| CVE-2025-11977 | 6.6 | 40.6 | happyforms | Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms | CWE-98 | HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion |
| CVE-2026-15291 | 7.5 | 38.7 | themeatelier | ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form | CWE-862 | Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to U… |
| CVE-2026-21045 | 8.3 | 38.3 | Samsung Mobile | Samsung Mobile Devices | — | Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so pr… |
| CVE-2026-12761 | 9.8 | 38.2 | cyberlord92 | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) | CWE-287 | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= … |
| CVE-2026-59792 | 9.8 | 38.1 | JetBrains | IntelliJ IDEA | CWE-23 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path tr… |
| CVE-2026-57158 | 5.1 | 38.0 | FreeRDP | FreeRDP | CWE-125 | FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for … |
| CVE-2026-55852 | 8.6 | 37.9 | frappe | frappe | CWE-22 | Frappe: TarSlip RCE in Package Import |
| CVE-2026-42219 | 6.9 | 37.9 | frappe | frappe | CWE-22 | Frappe: Path Traversal via /backups Route |
| CVE-2026-44383 | 8.7 | 37.2 | Hydro-Québec | Le Circuit Electrique charging station backend | CWE-613 | Hydro-Québec Le Circuit Electrique charging station backend Insufficient Sess… |
| CVE-2026-28564 | 9.8 | 36.7 | Apache Software Foundation | Apache IoTDB | CWE-294 | Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials |
| CVE-2026-14480 | 8.7 | 36.6 | OpenPLC | OpenPLC | CWE-73 | OpenPLC v3 External Control of File Name or Path |
| CVE-2026-54469 | 8.8 | 36.0 | Dell | Unisphere for PowerMax | CWE-502 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Dese… |
| CVE-2026-57212 | 7.1 | 36.1 | rabbitmq | rabbitmq-server | CWE-770 | RabbitMQ management HTTP API accepts request bodies larger than configured ma… |
| CVE-2026-38059 | 8.7 | 35.9 | ST Engineering iDirect | Evolution iQ‑Series terminals | CWE-306 | ST Engineering iDirect iQ-Series Terminals Missing authentication for critica… |
| CVE-2026-53448 | 7.2 | 35.9 | coturn | coturn | CWE-89 | Coturn: SQL Injection in HTTPS Admin Panel Delete Operations |
| CVE-2026-57211 | 10.0 | 35.7 | rabbitmq | rabbitmq-server | CWE-36 | RabbitMQ: UNC SSRF affecting the management UI on Windows |
| CVE-2026-39244 | 7.5 | 35.5 | n/a | n/a | CWE-400 | adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP fi… |
| CVE-2026-40008 | 9.8 | 35.3 | Apache Software Foundation | Apache IoTDB | CWE-470 | Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC |
| CVE-2026-57850 | 8.7 | 35.0 | RustDesk | RustDesk | CWE-862 | RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Messag… |
| CVE-2026-57584 | 8.7 | 35.0 | phalcon | cphalcon | CWE-1333 | Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router rout… |
| CVE-2026-40006 | 7.5 | 34.9 | Apache Software Foundation | Apache IoTDB | CWE-306 | Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in… |
| CVE-2026-57156 | 8.6 | 34.8 | FreeRDP | FreeRDP | CWE-122 | FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Poi… |
| CVE-2026-52761 | 5.3 | 34.5 | owasp-modsecurity | ModSecurity | CWE-467 | ModSecurity: Transformation utf8toUnicode produces wrong output on i386 archi… |
| CVE-2026-40005 | 9.1 | 34.3 | Apache Software Foundation | Apache IoTDB | CWE-22 | Apache IoTDB: Path Traversal in Pipe File Transfer Receiver |
| CVE-2026-57221 | 5.3 | 34.2 | rabbitmq | rabbitmq-server | CWE-862 | RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, l… |
| CVE-2026-5801 | 9.8 | 33.6 | Semtek Informatics Software Consulting Trade Ltd. Co. | SEM-PMP | CWE-89 | SQLi in Semtek Informatics' SEM-PMP |
| CVE-2026-42952 | 8.7 | 33.6 | Hydro-Québec | Le Circuit Electrique charging station backend | CWE-307 | Hydro-Québec Le Circuit Electrique charging station backend Improper Restrict… |
| CVE-2026-47199 | 2.3 | 33.3 | frappe | frappe | CWE-89 | Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE |
| CVE-2026-55884 | 9.2 | 33.0 | tilt-dev | tilt | CWE-306 | Tilt: Missing authentication on the network-exposed Tilt HUD server |
| CVE-2026-59161 | 8.7 | 33.0 | qax-os | excelize | CWE-400 | Excelize: Streaming GetRows row-bound bypass causes attacker-controlled alloc… |
| CVE-2026-8609 | 7.5 | 32.9 | Grafana | Grafana OSS | CWE-400 | Pre-authentication denial of service via the OAuth login route |
| CVE-2026-15290 | 7.5 | 32.4 | ultimatemember | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | CWE-89 | Ultimate Member – User Profile, Registration, Login, Member Directory, Conten… |
| CVE-2026-61444 | 9.4 | 32.4 | MervinPraison | PraisonAI | CWE-94 | PraisonAI before 4.6.78 Code Injection via f-string |
| CVE-2026-61492 | 6.1 | 32.2 | JetBrains | YouTrack | CWE-79 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in di… |
| CVE-2026-59162 | 6.9 | 32.2 | qax-os | excelize | CWE-248 | Excelize: Negative shared-string index causes panic in GetCellValue and GetRows |
| CVE-2026-59193 | 6.9 | 32.2 | getgrav | grav | CWE-409 | Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip() |
| CVE-2026-33382 | 7.5 | 32.0 | Grafana | Grafana OSS | CWE-400 | Denial of service via unbounded request body size |
| CVE-2026-54063 | 7.5 | 31.9 | qax-os | excelize | CWE-770 | Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/… |
| CVE-2026-55500 | 9.9 | 31.9 | decolua | 9router | CWE-200 | 9router: Exposure of Sensitive Information and Unprotected Database Import/Ex… |
| CVE-2026-21048 | 8.3 | 31.9 | Samsung Mobile | Samsung Mobile Devices | — | Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so pri… |
| CVE-2026-12535 | 9.8 | 31.8 | Drupal | Formatter Field | CWE-915 | Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048 |
| CVE-2026-29519 | 6.2 | 31.8 | lucee | Lucee | CWE-79 | Lucee CFML Server Reflected XSS via URL Path Parsing |
| CVE-2026-55687 | 7.5 | 31.6 | espressif | esp-idf | CWE-121 | ESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker Parsing |
| CVE-2026-54149 | 8.8 | 31.6 | 1Panel-dev | MaxKB | CWE-78 | MaxKB MCP tool import validation bypass allows post-authentication remote cod… |
| CVE-2026-55882 | 8.3 | 31.6 | tilt-dev | tilt | CWE-200 | Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server |
| CVE-2026-51119 | 9.1 | 31.3 | n/a | n/a | CWE-269 | An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privi… |
| CVE-2026-57215 | 7.0 | 31.4 | rabbitmq | rabbitmq-server | CWE-863 | RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-… |
| CVE-2026-55469 | 6.5 | 30.9 | grokability | snipe-it | CWE-22 | Snipe-IT: Path traversal vulnerability via CSV import `image` field |
| CVE-2026-15331 | 5.3 | 30.9 | zhayujie | CowAgent | CWE-22 | zhayujie CowAgent Skill Installation service.py _add_package path traversal |
| CVE-2026-59793 | 8.8 | 30.8 | JetBrains | TeamCity | CWE-73 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via … |
| CVE-2026-55638 | 8.6 | 30.3 | decolua | 9router | CWE-862 | 9router: Unauthenticated LLM proxy access via /codex rewrite authorization by… |
| CVE-2026-56261 | 9.2 | 30.3 | Crawl4AI | Crawl4AI | CWE-918 | Crawl4AI - Server-Side Request Forgery via Webhook URLs |
| CVE-2026-48127 | 5.3 | 30.0 | frappe | frappe | CWE-862 | Frappe: Arbitrary Attachment Injection via add_attachments and upload_file |
| CVE-2026-57157 | 6.5 | 29.8 | FreeRDP | FreeRDP | CWE-125 | Out-of-bounds read in the camera device enumerator server (rdpecam) via unter… |
| CVE-2026-15326 | 2.0 | 29.5 | halo-dev | halo | CWE-22 | halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path… |
| CVE-2026-56765 | 9.3 | 28.9 | Vikunja | Vikunja | CWE-639 | Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Discl… |
| CVE-2026-56305 | 8.7 | 28.8 | Capgo | Capgo | CWE-620 | Capgo - Authentication Bypass in Password Change via Missing Current Password… |
| CVE-2026-58499 | 8.2 | 28.7 | EverMind-AI | EverOS | CWE-22 | Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id |
| CVE-2026-55229 | 7.5 | 28.6 | gotenberg | gotenberg | CWE-918 | Gotenberg: SSRF via LibreOffice document processing |
| CVE-2026-58503 | 6.9 | 28.6 | frappe | frappe | CWE-203 | Frappe: Unauthenticated User Enumeration via reset_password |
| CVE-2026-61461 | 8.7 | 28.2 | langgenius | dify | CWE-89 | Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text |
| CVE-2026-57217 | 7.0 | 28.2 | rabbitmq | rabbitmq-server | CWE-863 | RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass |
| CVE-2026-15330 | 5.5 | 28.3 | zhayujie | CowAgent | CWE-918 | zhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side req… |
| CVE-2026-57218 | 4.9 | 28.2 | rabbitmq | rabbitmq-server | CWE-863 | RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can le… |
| CVE-2026-15300 | 9.1 | 28.0 | ninjew | GEO my WP | CWE-89 | GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / '… |
| CVE-2026-15293 | 8.0 | 27.8 | joeyoungblood | WP Business Intelligence Lite | CWE-862 | WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing … |
| CVE-2026-55405 | 7.6 | 27.9 | langchain4j | langchain4j | CWE-89 | LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and la… |
| CVE-2026-57575 | 6.9 | 27.8 | misskey-dev | misskey | CWE-918 | Misskey: SSRF bypass in URL Preview |
| CVE-2026-55466 | 6.2 | 27.7 | grokability | snipe-it | CWE-79 | Snipe-IT: Stored XSS via inline-served attachment |
| CVE-2026-15289 | 5.9 | 27.7 | wpdevart | Booking calendar, Appointment Booking System | CWE-89 | Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time… |
| CVE-2026-55213 | 7.5 | 27.4 | h2o | h2o | CWE-789 | h2o: musl libc stack overflow (QPACK) |
| CVE-2026-55233 | 7.5 | 27.3 | openresty | openresty | CWE-787 | OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream |
| CVE-2026-11990 | 5.3 | 27.2 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-862 | KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass a… |
| CVE-2026-15288 | 7.5 | 27.0 | brainstormforce | SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator | CWE-20 | SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticat… |
| CVE-2026-57574 | 7.4 | 27.0 | misskey-dev | misskey | CWE-294 | Misskey: TOTP tokens can be reused |
| CVE-2026-57475 | 6.9 | 27.0 | Deloitte | AI Assist for Customer | CWE-306 | Deloitte AI Assist for Customer unauthenticated configuration write |
| CVE-2026-55827 | 8.8 | 26.9 | FreeRDP | FreeRDP | CWE-131 | FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode |
| CVE-2026-41482 | 7.1 | 26.7 | frappe | frappe | CWE-22 | Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Gener… |
| CVE-2026-39903 | 7.1 | 26.2 | SimpleMachines | SMF | CWE-863 | Simple Machines Forum Authorization Bypass via AttachmentApprove.php |
| CVE-2026-40007 | 7.5 | 25.8 | Apache Software Foundation | Apache IoTDB | CWE-400 | Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's … |
| CVE-2026-40454 | 7.5 | 25.8 | Apache Software Foundation | Apache IoTDB C++ client | CWE-20 | Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializ… |
| CVE-2026-55474 | 7.1 | 25.8 | grokability | snipe-it | CWE-23 | Snipe-IT: Directory traversal in displaySig |
| CVE-2026-44918 | 5.5 | 25.7 | OpenStack | Ironic | CWE-862 | OpenStack Ironic through before 37.0.1 allows creation or modification of nod… |
| CVE-2026-22660 | 8.6 | 25.7 | flaskbb | flaskbb | CWE-697 | FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint |
| CVE-2026-15319 | 5.5 | 25.1 | Sipeed | PicoClaw | CWE-266 | Sipeed PicoClaw Launcher access_control.go IPAllowlist access control |
| CVE-2026-55665 | 8.5 | 25.0 | gristlabs | grist-core | CWE-79 | DOM-based XSS in Grist via unsanitized links, enabling privilege escalation |
| CVE-2026-11913 | 9.8 | 24.8 | Drupal | Mother May I | CWE-79 | Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045 |
| CVE-2026-55501 | 7.3 | 24.8 | decolua | 9router | CWE-307 | 9router: Login brute-force protection bypass via spoofed X-Forwarded-For header |
| CVE-2026-49213 | 8.1 | 24.7 | baptisteArno | typebot.io | CWE-918 | TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP … |
| CVE-2026-12918 | 4.9 | 24.7 | getwpfunnels | Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | CWE-89 | Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recip… |
| CVE-2026-15378 | 9.3 | 24.3 | Red Hat | Red Hat OpenShift AI (RHOAI) | CWE-918 | Guardrails-detectors: guardrails-detectors: ssrf and local file read via user… |
| CVE-2026-56675 | 8.3 | 24.3 | decolua | 9router | CWE-287 | 9router: Reverse proxy locality collapse allows unauthenticated access to 9ro… |
| CVE-2026-15298 | 7.2 | 24.1 | pechenki | TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot | CWE-79 | TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegr… |
| CVE-2026-11321 | 7.1 | 24.1 | pluginsGLPI | datainjection | CWE-89 | GLPI DataInjection Plugin Authenticated SQL Injection via CSV Import |
| CVE-2026-9726 | 9.8 | 24.1 | Drupal | Drupal AlternativeCommerce (Basket) | CWE-915 | Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code ex… |
| CVE-2026-56279 | 8.7 | 24.0 | Capgo | Capgo | CWE-862 | Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint |
| CVE-2026-55780 | 2.4 | 23.5 | M2Team | NanaZip | CWE-248 | NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-fil… |
| CVE-2026-55809 | 8.1 | 23.3 | Drupal | Flag attendance field | CWE-915 | Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049 |
| CVE-2026-49394 | 7.1 | 23.3 | frappe | frappe | CWE-862 | Frappe: Auth. bypass via update_page |
| CVE-2026-59155 | 6.9 | 23.0 | nezhahq | nezha | CWE-200 | Nezha Monitoring: DDNS and Notification credential exposure via unredacted li… |
| CVE-2026-14461 | 5.1 | 23.0 | BitWizard | mtr | CWE-125 | Out-of-bound read in mtr |
| CVE-2026-58492 | 9.2 | 22.8 | getgrav | grav | CWE-89 | grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized … |
| CVE-2026-54423 | 8.2 | 22.8 | OpenStack | Ironic | CWE-424 | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy … |
| CVE-2026-54468 | 6.5 | 22.8 | Dell | Unisphere for PowerMax | CWE-22 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path… |
| CVE-2026-53653 | 8.7 | 22.7 | getgrav | grav | CWE-770 | Grav: Unauthenticated denial of service via unbounded image derivative dimens… |
| CVE-2026-15089 | 9.1 | 22.3 | Drupal | Commerce guest registration | CWE-287 | Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079 |
| CVE-2026-55789 | 8.5 | 22.4 | logto-io | logto | CWE-91 | Logto: SAML IdP injects user-controlled profile attributes raw into signed as… |
| CVE-2026-55843 | 7.0 | 22.4 | grokability | snipe-it | CWE-269 | Snipe-IT: Improper Privilege Management |
| CVE-2026-15284 | 6.4 | 22.3 | kingaddons | King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder | CWE-79 | King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cro… |
| CVE-2026-59151 | 9.6 | 22.1 | prowler-cloud | prowler | CWE-287 | Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover |
| CVE-2026-9838 | 6.1 | 22.1 | room34 | ICS Calendar | CWE-79 | ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Pa… |
| CVE-2026-53363 | 9.8 | 22.1 | Linux | Linux | — | xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() |
| CVE-2026-56335 | 7.1 | 22.1 | Capgo | Capgo | CWE-284 | Capgo - Channel Configuration Mutation via Write-Scoped API Keys |
| CVE-2026-14475 | 4.9 | 22.0 | wplegalpages | Cookie Banner for GDPR / CCPA – WPLP Cookie Consent | CWE-89 | Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL I… |
| CVE-2026-41878 | 7.1 | 21.8 | R-SOFT SERWIS | DMS | CWE-639 | Insecure Direct Object Reference in R-SOFT DMS |
| CVE-2026-57474 | 6.9 | 21.7 | Deloitte | AI Assist for Customer | CWE-200 | Deloitte AI Assist for Customer information disclosure |
| CVE-2026-55879 | 9.3 | 21.5 | openreplay | openreplay | CWE-79 | OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover |
| CVE-2026-58493 | 5.1 | 21.3 | getgrav | grav | CWE-74 | grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration V… |
| CVE-2026-9857 | 4.3 | 21.3 | saskaita123 | Invoice123 | CWE-862 | Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Se… |
| CVE-2026-40452 | 7.5 | 21.2 | Apache Software Foundation | Apache IoTDB | CWE-284 | Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-val… |
| CVE-2026-55670 | 2.3 | 21.1 | zitadel | zitadel | CWE-284 | ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers |
| CVE-2026-55460 | 7.1 | 21.0 | grokability | snipe-it | CWE-863 | Snipe-IT: Authorization bypass on bulk editing users |
| CVE-2026-22659 | 7.2 | 20.9 | flaskbb | flaskbb | CWE-863 | FlaskBB Authorization Bypass via Topic ID Manipulation |
| CVE-2026-15287 | 6.5 | 20.7 | rtcamp | rtMedia for WordPress, BuddyPress and bbPress | CWE-89 | rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subs… |
| CVE-2026-55187 | 5.8 | 20.7 | axllent | mailpit | CWE-918 | Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mec… |
| CVE-2026-61460 | 8.7 | 20.5 | krayin | laravel-crm | CWE-639 | Krayin CRM Insecure Direct Object Reference via Controllers |
| CVE-2026-11992 | 4.3 | 20.5 | easyappointments | Easy Appointments | CWE-862 | Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author… |
| CVE-2026-61432 | 6.9 | 20.2 | MervinPraison | PraisonAI | CWE-22 | PraisonAI FastContext before 1.6.78 Path Traversal |
| CVE-2026-47422 | 5.3 | 20.2 | frappe | frappe | CWE-862 | Frappe: Unrestricted API access to save_report |
| CVE-2026-55462 | 4.3 | 20.3 | grokability | snipe-it | CWE-863 | Snipe-IT: Authorization bypass on print inventory page |
| CVE-2026-55672 | 7.4 | 20.0 | zitadel | zitadel | CWE-287 | ZITADEL: Missing client_id binding in OIDC authorization code exchange and re… |
| CVE-2026-15086 | 5.9 | 20.1 | Drupal | Raw Formatter [Meta Tag Formatter] | — | Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026… |
| CVE-2026-55659 | 7.7 | 19.9 | gristlabs | grist-core | CWE-79 | Grist: XSS through unsafe value interpolation in server-rendered pages |
| CVE-2026-56312 | 6.9 | 19.9 | Capgo | Capgo | CWE-287 | Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint |
| CVE-2026-59796 | 8.1 | 19.6 | JetBrains | TeamCity | CWE-862 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due … |
| CVE-2026-57961 | 5.1 | 19.2 | phpMyFAQ | phpMyFAQ | CWE-22 | phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Fu… |
| CVE-2026-57167 | 5.1 | 19.1 | Chocobozzz | PeerTube | CWE-80 | PeerTube: Improper Neutralization of Script-Related HTML Tags in a Web Page (… |
| CVE-2026-55515 | 5.0 | 19.1 | grokability | snipe-it | CWE-639 | Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped… |
| CVE-2026-11392 | 6.1 | 19.0 | thimpress | WP Hotel Booking | CWE-79 | WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date… |
| CVE-2026-12400 | 4.3 | 19.0 | priyanshuchaudhary | FlowForms – Conversational Form Builder | CWE-639 | FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Refe… |
| CVE-2026-15286 | 4.3 | 19.0 | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | CWE-863 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - In… |
| CVE-2026-40009 | 6.5 | 18.5 | Apache Software Foundation | Apache IoTDB | CWE-269 | Apache IoTDB: Authenticated users can escalate to full tree-path access by re… |
| CVE-2026-2397 | 9.8 | 18.5 | Adam Retail Automation Ltd. | MobilMen 20T | CWE-89 | SQLi in AdamPOS' MobilMen 20T |
| CVE-2026-59795 | 6.1 | 18.4 | JetBrains | TeamCity | CWE-79 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent re… |
| CVE-2026-15285 | 6.4 | 18.0 | posimyththemes | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | CWE-79 | The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored… |
| CVE-2026-15070 | 8.8 | 17.7 | wordpresschef | Salon Booking System – Free Version | CWE-352 | Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code … |
| CVE-2026-55377 | 8.1 | 17.7 | logto-io | logto | CWE-287 | Logto: Account Center MFA management step-up bypass via WebAuthn registration… |
| CVE-2026-61431 | 6.8 | 17.7 | MervinPraison | PraisonAI | CWE-22 | PraisonAI before 4.6.78 Path Traversal via ContextGatherer |
| CVE-2026-56309 | 5.3 | 17.7 | Capgo | Capgo | CWE-770 | Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint |
| CVE-2026-15081 | 7.4 | 17.5 | Drupal | Location Selector | CWE-89 | Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072 |
| CVE-2026-13039 | 5.3 | 17.5 | arraytics | Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) | CWE-862 | Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment By… |
| CVE-2026-15297 | 6.1 | 17.4 | neeraj_slit | Brevo – Email, SMS, Web Push, Chat, and more. | CWE-79 | Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendi… |
| CVE-2026-15373 | 2.1 | 17.4 | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software userAddAction.do improper authorization |
| CVE-2026-15374 | 2.1 | 17.4 | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software Group roleAddAction.do improper authorization |
| CVE-2026-15376 | 2.1 | 17.4 | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software statisticReportAction.do improper authorization |
| CVE-2026-15143 | 9.3 | 17.2 | Red Hat | Red Hat OpenShift AI (RHOAI) | CWE-918 | Guardrails-detectors: guardrails-detectors: ssrf and local file read via user… |
| CVE-2026-3907 | 6.4 | 17.2 | prasunsen | Hostel | CWE-79 | Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting vi… |
| CVE-2026-15296 | 6.4 | 17.2 | cservit | affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display | CWE-79 | affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated … |
| CVE-2026-15377 | 2.1 | 17.3 | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software sendlogfile improper authorization |
| CVE-2026-54714 | 6.1 | 17.0 | logto-io | logto | CWE-79 | Logto: XSS via unescaped RelayState in SAML auto-submit form |
| CVE-2026-57213 | 5.7 | 16.8 | rabbitmq | rabbitmq-server | CWE-79 | RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_ta… |
| CVE-2026-55671 | 2.3 | 16.8 | zitadel | zitadel | CWE-918 | ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing H… |
| CVE-2026-6212 | 8.8 | 16.8 | Teracity Software Technologies Inc. | TeraMIS | CWE-639 | IDOR in Teracity's TeraMIS |
| CVE-2026-41877 | 5.1 | 16.8 | R-SOFT SERWIS | DMS | CWE-79 | Stored XSS in R-SOFT DMS |
| CVE-2026-2398 | 8.8 | 16.7 | Adam Retail Automation Ltd. | MobilMen 20T | CWE-639 | IDOR in AdamPOS' MobilMen 20T |
| CVE-2026-61455 | 7.1 | 16.5 | getgrav | grav | CWE-409 | Grav before 2.0.1 Decompression Bomb via ZipArchiver |
| CVE-2026-13244 | 8.1 | 16.4 | Drupal | Tealium iQ Tag Management | CWE-915 | Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026… |
| CVE-2026-55810 | 8.1 | 16.4 | Drupal | Plotly.js Graphing | CWE-915 | Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050 |
| CVE-2026-57476 | 6.3 | 16.3 | Deloitte | AI Assist for Customer | CWE-306 | Deloitte AI Assist for Customer unauthenticated RAG corpus read and write |
| CVE-2026-13010 | 6.5 | 16.2 | beardev | JoomSport – for Sports: Team & League, Football, Hockey & more | CWE-89 | JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' S… |
| CVE-2026-15317 | 2.1 | 16.2 | Sipeed | PicoClaw | CWE-918 | Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-sid… |
| CVE-2026-55641 | 8.2 | 16.2 | decolua | 9router | CWE-290 | 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open… |
| CVE-2026-55881 | 7.1 | 16.1 | openreplay | openreplay | CWE-639 | OpenReplay: Cross-tenant session replay disclosure via missing session owners… |
| CVE-2026-61450 | 7.1 | 16.2 | getgrav | grav | CWE-94 | Grav before 2.0.2 Config Exfiltration via offsetGet Filter |
| CVE-2026-53449 | 6.0 | 16.0 | coturn | coturn | CWE-73 | Coturn: Arbitrary File Write via CLI psd Command |
| CVE-2026-15087 | 5.9 | 15.8 | Drupal | Clean RESTful | CWE-287 | Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078 |
| CVE-2026-11818 | 5.4 | 15.8 | arraytics | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System | CWE-862 | WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbit… |
| CVE-2026-15292 | 6.4 | 15.7 | tibouille | Sudoku Shortcode | CWE-79 | Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting… |
| CVE-2026-6802 | 5.3 | 15.8 | fahadmahmood | Easy Upload Files During Checkout | CWE-639 | Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthe… |
| CVE-2026-55664 | 4.3 | 15.7 | gristlabs | grist-core | CWE-200 | Grist: Insufficient access control in the /forms endpoint exposes table metadata |
| CVE-2026-15104 | 6.5 | 15.5 | wpdevteam | BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot | CWE-89 | BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter |
| CVE-2026-15329 | 2.1 | 15.5 | zhayujie | CowAgent | CWE-200 | zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate infor… |
| CVE-2026-56690 | 8.5 | 15.4 | Dell | PowerFlex Manager | CWE-89 | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neut… |
| CVE-2026-8595 | 5.4 | 15.3 | Grafana | Grafana OSS | CWE-79 | Stored XSS in the table panel (TableNG) |
| CVE-2026-61441 | 7.1 | 15.3 | MervinPraison | PraisonAI | CWE-862 | PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies |
| CVE-2026-12123 | 6.4 | 15.1 | plugins360 | All-in-One Video Gallery | CWE-918 | All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side R… |
| CVE-2026-56329 | 5.3 | 14.9 | Capgo | Capgo | CWE-436 | Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore… |
| CVE-2026-55481 | 6.2 | 14.8 | grokability | snipe-it | CWE-79 | Snipe-IT: CSS Injection via `header_color` Setting |
| CVE-2026-55452 | 4.8 | 14.5 | grokability | snipe-it | CWE-1236 | Snipe-IT: CSV formula injection in Activity Report export |
| CVE-2026-15320 | 2.1 | 14.6 | Sipeed | PicoClaw | CWE-862 | Sipeed PicoClaw pico.go rt.ReloadConfig authorization |
| CVE-2026-55461 | 6.1 | 14.3 | grokability | snipe-it | CWE-601 | Snipe-IT: Open Redirect After User Edit |
| CVE-2026-56668 | 8.1 | 14.1 | zitadel | zitadel | CWE-862 | ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange |
| CVE-2026-56373 | 6.3 | 14.1 | ImageMagick | ImageMagick | CWE-416 | ImageMagick - Use-After-Free Write in PDB Decoder |
| CVE-2026-38057 | 7.0 | 13.5 | ST Engineering iDirect | Evolution iQ‑Series terminals | CWE-352 | ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery |
| CVE-2026-58661 | 5.3 | 13.5 | n8n | n8n | CWE-770 | n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint |
| CVE-2026-54329 | 7.7 | 13.5 | grokability | snipe-it | CWE-862 | Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API |
| CVE-2026-56667 | 7.3 | 13.3 | zitadel | zitadel | CWE-79 | ZITADEL: Stored XSS via Default URI Redirect in Login V2 |
| CVE-2026-15026 | 4.3 | 13.1 | carazo | Import and export users and customers | CWE-862 | Import and export users and customers <= 2.4.0 - Missing Authorization to Aut… |
| CVE-2026-55883 | 8.3 | 13.0 | tilt-dev | tilt | CWE-345 | Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream |
| CVE-2026-12685 | 7.5 | 13.1 | Unknown | escortwp | — | EscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor |
| CVE-2026-1946 | 4.3 | 13.0 | nandhiniwp | GW AI Website Builder | CWE-862 | GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subs… |
| CVE-2026-15375 | 2.1 | 13.0 | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization |
| CVE-2026-56689 | 7.7 | 12.8 | Dell | PowerFlex Manager | CWE-89 | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neut… |
| CVE-2026-57214 | 7.1 | 12.7 | rabbitmq | rabbitmq-server | CWE-79 | RabbitMQ: Stored XSS in RabbitMQ management UI |
| CVE-2026-60086 | 6.9 | 12.8 | MervinPraison | PraisonAI | CWE-693 | PraisonAI before 4.6.78 Prompt Injection Defense Bypass |
| CVE-2026-15321 | 1.9 | 12.7 | n/a | MyEMS | CWE-79 | MyEMS Admin Backend svg.py on_post cross site scripting |
| CVE-2026-55516 | 7.7 | 12.5 | grokability | snipe-it | CWE-639 | Snipe-IT: Cross-company asset maintenance re-parenting via API update |
| CVE-2026-11914 | 5.9 | 12.4 | Drupal | Composer | CWE-20 | Composer - Critical - Unsupported - SA-CONTRIB-2026-046 |
| CVE-2026-59190 | 8.7 | 12.2 | getgrav | grav | CWE-639 | Grav Admin Plugin — IDOR Privilege Escalation via saveUser() |
| CVE-2026-55803 | 5.9 | 12.2 | Drupal | Drupal core | CWE-915 | Drupal core - Critical - PHP object injection - SA-CORE-2026-005 |
| CVE-2026-55804 | 5.9 | 12.2 | Drupal | Drupal core | CWE-915 | Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006 |
| CVE-2026-57994 | 6.9 | 12.0 | phpMyFAQ | phpMyFAQ | CWE-200 | phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endp… |
| CVE-2026-15318 | 2.1 | 12.0 | Sipeed | PicoClaw | CWE-285 | Sipeed PicoClaw MQTT Channel mqtt.go authorization |
| CVE-2026-15079 | 5.4 | 11.3 | Drupal | Login Disable | CWE-307 | Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070 |
| CVE-2026-15332 | 2.1 | 11.4 | zhayujie | CowAgent | CWE-862 | zhayujie CowAgent Message Endpoint channel.py authorization |
| CVE-2026-59794 | 5.4 | 11.2 | JetBrains | TeamCity | CWE-79 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page wa… |
| CVE-2026-12108 | 4.4 | 11.2 | looswebstudio | Highlighting Code Block | CWE-79 | Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cros… |
| CVE-2026-59154 | 4.3 | 11.3 | wekan | wekan | CWE-863 | Wekan: Checklist direct DDP updates can write checklist data into private boards |
| CVE-2026-57230 | 5.4 | 11.0 | openreplay | openreplay | CWE-89 | OpenReplay: Authenticated ClickHouse SQL injection via session search |
| CVE-2026-55806 | 5.9 | 10.9 | Drupal | Drupal core | CWE-601 | Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-202… |
| CVE-2026-13233 | 3.3 | 10.7 | Drupal | OpenAI Provider | CWE-918 | OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONT… |
| CVE-2026-56664 | 4.2 | 10.6 | zitadel | zitadel | CWE-613 | ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider |
| CVE-2026-15028 | 3.9 | 10.6 | Red Hat | Red Hat Hardened Images | CWE-805 | Libarchive: heap overflow oob read while parsing a tar archive contains a pax… |
| CVE-2026-12924 | 6.4 | 10.1 | arraytics | Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) | CWE-79 | Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting … |
| CVE-2026-13710 | 6.4 | 10.1 | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | CWE-79 | Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Si… |
| CVE-2026-55476 | 5.3 | 10.2 | grokability | snipe-it | CWE-862 | Snipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_adm… |
| CVE-2026-41879 | 8.2 | 10.0 | R-SOFT SERWIS | DMS | CWE-328 | Weak password hashing in R-SOFT DMS |
| CVE-2026-55370 | 6.4 | 10.0 | logto-io | logto | CWE-294 | Logto: TOTP code can be replayed within the RFC 6238 validity window (one-tim… |
| CVE-2026-55472 | 4.3 | 9.8 | grokability | snipe-it | CWE-863 | Snipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary V… |
| CVE-2026-12955 | 4.3 | 9.6 | wplegalpages | Cookie Banner for GDPR / CCPA – WPLP Cookie Consent | CWE-862 | Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticat… |
| CVE-2026-55880 | 7.1 | 9.5 | openreplay | openreplay | CWE-639 | OpenReplay: Cross-user IDOR in notes and dashboard widgets |
| CVE-2026-59180 | 3.1 | 9.5 | caronc | apprise | CWE-200 | Apprise forwards configured auth headers across cross-origin HTTP redirects |
| CVE-2026-15299 | 6.4 | 9.3 | wealcoder | Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates | CWE-79 | Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored… |
| CVE-2026-11915 | 5.9 | 9.2 | Drupal | Brute force attack protection | CWE-307 | Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047 |
| CVE-2026-55475 | 5.7 | 9.2 | grokability | snipe-it | CWE-863 | Snipe-IT: Import created_by can be overwritten |
| CVE-2026-54470 | 5.3 | 9.0 | Dell | Unisphere for PowerMax | CWE-611 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Impr… |
| CVE-2026-55479 | 5.3 | 8.9 | grokability | snipe-it | CWE-863 | Snipe-IT: Incorrect permission for legacy license checkin API |
| CVE-2026-15295 | 4.4 | 9.0 | dcooney | Ajax Load More – Infinite Scroll, Load More, & Lazy Load | CWE-692 | Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Sc… |
| CVE-2026-56666 | 4.8 | 8.9 | zitadel | zitadel | CWE-287 | ZITADEL: Auto-linking by email: IdP-side email verification is not checked |
| CVE-2026-13247 | 6.4 | 8.7 | logichunt | Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase | CWE-79 | Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-55890 | 4.8 | 8.7 | getgrav | grav | CWE-79 | Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTra… |
| CVE-2026-15283 | 4.4 | 8.6 | wpvividplugins | WPvivid Backup for MainWP | CWE-79 | WPvivid Backup for MainWP <= 0.9.33 - Authenticated (Admin+) Stored Cross-Sit… |
| CVE-2026-1667 | 7.2 | 8.5 | cifi | GEO Plugin by Squirrly SEO | CWE-862 | SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creatio… |
| CVE-2026-12276 | 5.3 | 8.0 | Unknown | LA-Studio Element Kit for Elementor | — | LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration |
| CVE-2026-10770 | 6.1 | 8.0 | Drupal | Anti-Spam by CleanTalk | CWE-79 | Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONT… |
| CVE-2026-13231 | 6.1 | 8.0 | Drupal | Advanced Content Feedback (aka admin_feedback) | CWE-79 | Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-… |
| CVE-2026-13234 | 6.1 | 8.0 | Drupal | AI (Artificial Intelligence) | CWE-79 | AI (Artificial Intelligence) - Moderately critical - Information Disclosure /… |
| CVE-2026-60091 | 6.9 | 7.9 | MervinPraison | PraisonAI | CWE-918 | PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url |
| CVE-2026-15083 | 4.2 | 7.8 | Drupal | ECA: Event - Condition - Action | CWE-915 | ECA: Event - Condition - Action - Less critical - Information disclosure - SA… |
| CVE-2025-30008 | 5.1 | 7.6 | hestiacp | hestiacp | CWE-79 | HestiaCP < 1.9.5 Stored XSS via DNS Record Management Interface |
| CVE-2026-55478 | 5.3 | 7.3 | grokability | snipe-it | CWE-639 | Snipe-IT: Missing object-level authorization in Kits API |
| CVE-2026-55885 | 6.8 | 7.1 | getgrav | grav | CWE-312 | Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Sec… |
| CVE-2026-53450 | 7.4 | 7.0 | coturn | coturn | CWE-918 | Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection |
| CVE-2026-55464 | 4.8 | 7.0 | grokability | snipe-it | CWE-79 | Snipe-IT: Stored XSS via Markdown custom field |
| CVE-2026-21055 | 8.5 | 7.0 | Samsung Mobile | Bixby | — | Improper export of android application components in Bixby prior to version 4… |
| CVE-2026-5069 | 5.4 | 6.9 | wpmanageninja | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | CWE-863 | Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+… |
| CVE-2026-56354 | 5.1 | 6.6 | n8n | n8n | CWE-79 | n8n - Cross-Site Scripting and Open Redirect in Form Node |
| CVE-2026-56366 | 4.8 | 6.7 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in META Reader APP1JPEG Error Path |
| CVE-2026-13237 | 4.8 | 6.5 | Drupal | AI Agents | CWE-863 | AI Agents - Moderately critical - Information disclosure, Access bypass - SA-… |
| CVE-2026-56665 | 4.2 | 6.4 | zitadel | zitadel | CWE-613 | ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider |
| CVE-2026-13242 | 6.5 | 6.2 | Drupal | Geolocation Field | CWE-89 | Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062 |
| CVE-2026-10769 | 5.4 | 6.2 | Drupal | Commerce Core | CWE-79 | Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041 |
| CVE-2026-15082 | 5.4 | 6.2 | Drupal | Siteimprove Analytics | CWE-79 | Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTR… |
| CVE-2026-15084 | 5.4 | 6.2 | Drupal | UI Patterns (SDC in Drupal UI) | CWE-79 | UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting -… |
| CVE-2026-15085 | 5.4 | 6.2 | Drupal | AI SEO/GEO Analyzer | CWE-79 | AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB… |
| CVE-2026-54919 | 7.4 | 6.0 | yhirose | cpp-httplib | CWE-295 | cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts… |
| CVE-2026-15146 | 5.9 | 6.1 | GNU wget | Wget | — | CVE-2026-15146 |
| CVE-2026-58225 | 2.1 | 5.9 | elixir-ecto | postgrex | CWE-89 | SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect … |
| CVE-2026-11908 | 5.4 | 5.9 | Drupal | Tagify | CWE-79 | Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043 |
| CVE-2026-13232 | 3.1 | 5.9 | Drupal | Advanced Content Feedback (aka admin_feedback) | CWE-863 | Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access… |
| CVE-2026-55808 | 5.4 | 5.8 | Drupal | Drupal core | CWE-79 | Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009 |
| CVE-2026-11909 | 3.3 | 5.7 | Drupal | Examples for Developers | CWE-862 | Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-20… |
| CVE-2026-13235 | 3.3 | 5.7 | Drupal | AI (Artificial Intelligence) | CWE-862 | AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTR… |
| CVE-2026-13239 | 6.5 | 5.6 | Drupal | WissKI | CWE-862 | WissKI - Critical - Access bypass - SA-CONTRIB-2026-059 |
| CVE-2026-13240 | 6.5 | 5.6 | Drupal | Paragraphs | CWE-862 | Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060 |
| CVE-2026-13241 | 6.5 | 5.6 | Drupal | Paragraphs | CWE-862 | Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061 |
| CVE-2026-6440 | 4.3 | 5.5 | sovlix | GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference | CWE-352 | GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Rese… |
| CVE-2026-15301 | 6.4 | 5.3 | digiblogger | BuddyHolis TableSearch | CWE-79 | BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-S… |
| CVE-2026-56676 | 7.4 | 5.1 | decolua | 9router | CWE-367 | 9router: Image prefetch DNS rebinding allows SSRF to internal services |
| CVE-2026-58588 | 6.1 | 4.9 | Drupal | Drupal Canvas | CWE-79 | Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066 |
| CVE-2026-56254 | 8.3 | 4.8 | capacitor-updater | capacitor-updater | CWE-320 | capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution |
| CVE-2026-58587 | 6.1 | 4.6 | Drupal | Drupal Canvas | CWE-79 | Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065 |
| CVE-2026-3251 | 6.4 | 4.5 | Webremium Istanbul Web Design | Mezunum Satiyorum | CWE-79 | XSS in Webremium's Mezunum Satiyorum |
| CVE-2026-54736 | 8.2 | 4.5 | phalcon | cphalcon | CWE-208 | Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (… |
| CVE-2026-56813 | 2.1 | 4.4 | elixir-plug | plug | CWE-141 | Cookie attribute injection in Plug.Conn.Cookies.encode/2 |
| CVE-2026-13236 | 4.2 | 4.3 | Drupal | AI Agents | CWE-862 | AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056 |
| CVE-2026-60089 | 6.9 | 3.9 | MervinPraison | PraisonAI | CWE-22 | PraisonAI before 1.6.78 Path Traversal via config.toml |
| CVE-2026-58589 | 5.4 | 3.9 | Drupal | FlowDrop | CWE-862 | FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067 |
| CVE-2026-58590 | 5.4 | 3.9 | Drupal | FlowDrop | CWE-862 | FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068 |
| CVE-2026-61456 | 5.1 | 3.9 | getgrav | grav | CWE-79 | Grav before 1.0.3 Stored XSS via SVG Upload API |
| CVE-2026-55807 | 3.1 | 3.9 | Drupal | Drupal core | CWE-918 | Drupal core - Moderately critical - Server-side request forgery - SA-CORE-202… |
| CVE-2026-13238 | 4.8 | 3.7 | Drupal | Commerce Realex / Global Payments | CWE-863 | Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-… |
| CVE-2026-58591 | 5.4 | 3.5 | Drupal | Colorbox | CWE-79 | Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069 |
| CVE-2026-59791 | 3.5 | 3.4 | JetBrains | YouTrack | CWE-1021 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram r… |
| CVE-2026-41154 | 7.8 | 3.2 | Imagination Technologies | Graphics DDK | CWE-787 | GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse |
| CVE-2026-21052 | 6.8 | 3.2 | Samsung Mobile | Samsung Mobile Devices | — | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows … |
| CVE-2026-61437 | 8.5 | 3.0 | MervinPraison | PraisonAI | CWE-693 | PraisonAI before 1.6.78 Remote Code Execution via tools.py |
| CVE-2026-53657 | 8.2 | 3.0 | lima-vm | lima | CWE-276 | Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM … |
| CVE-2026-21043 | 6.7 | 3.0 | Samsung Mobile | Samsung Mobile Devices | — | Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows lo… |
| CVE-2026-21049 | 8.4 | 2.8 | Samsung Mobile | Samsung Mobile Devices | — | Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 all… |
| CVE-2026-7639 | 7.8 | 2.4 | Imagination Technologies | Graphics DDK | CWE-459 | GPU DDK - Page UAF read in PMMETA_PROTECT heap memory |
| CVE-2026-34196 | 7.8 | 2.0 | Imagination Technologies | Graphics DDK | CWE-416 | GPU DDK - UAF read and/or write of arbitrary physical memory due to integer t… |
| CVE-2026-15080 | 4.3 | 2.0 | Drupal | Ray Enterprise Translation | CWE-352 | Ray Enterprise Translation - Moderately critical - Cross site request forgery… |
| CVE-2026-21042 | 8.4 | 1.9 | Samsung Mobile | Samsung Mobile Devices | — | Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows lo… |
| CVE-2026-21057 | 6.8 | 1.9 | Samsung Mobile | Samsung Pass | — | Improper input validation in Samsung Pass prior to version 5.2.10.3 allows lo… |
| CVE-2026-21054 | 6.9 | 1.8 | Samsung Mobile | InputSharing | — | Improper export of android application components in InputSharing prior to ve… |
| CVE-2026-55782 | 2.4 | 1.7 | M2Team | NanaZip | CWE-400 | NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via … |
| CVE-2026-55669 | 4.2 | 1.6 | zitadel | zitadel | CWE-346 | ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider |
| CVE-2026-55781 | 2.4 | 1.6 | M2Team | NanaZip | CWE-400 | NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalida… |
| CVE-2026-55783 | 2.4 | 1.6 | M2Team | NanaZip | CWE-476 | NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom ar… |
| CVE-2026-21053 | 5.1 | 1.5 | Samsung Mobile | Samsung Email | — | Improper input validation in Samsung Email prior to version 6.2.13.1 allows l… |
| CVE-2026-54000 | 7.0 | 1.4 | osquery | osquery | CWE-122 | osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processe… |
| CVE-2026-54001 | 7.0 | 1.4 | osquery | osquery | CWE-122 | osquery: Heap buffer overflow via `authenticode` table (Windows) |
| CVE-2026-45196 | 7.8 | 1.2 | Imagination Technologies | Graphics DDK | CWE-280 | GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized … |
| CVE-2026-21039 | 6.9 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in Settings prior to SMR Jul-2026 Release 1 allows lo… |
| CVE-2026-21041 | 6.9 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Releas… |
| CVE-2026-21050 | 5.1 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 all… |
| CVE-2026-21051 | 5.1 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release … |
| CVE-2026-21040 | 6.9 | 0.9 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows… |
| CVE-2026-21056 | 4.8 | 0.9 | Samsung Mobile | Samsung Health | — | Improper authorization in Samsung Health prior to version 7.00.0.107 allows l… |
| CVE-2026-21046 | 8.4 | 0.8 | Samsung Mobile | Samsung Mobile Devices | — | Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to… |
| CVE-2026-21044 | 5.8 | 0.8 | Samsung Mobile | Samsung Mobile Devices | — | Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 al… |
| CVE-2026-46388 | 4.4 | 0.7 | osquery | osquery | CWE-279 | osquery: Unprivileged users can temporarily read file carve contents |
| CVE-2026-45203 | 7.8 | 0.6 | Imagination Technologies | Graphics DDK | CWE-367 | GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial … |
| CVE-2026-13243 | 4.8 | 0.5 | Drupal | Salesforce Suite | CWE-352 | Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONT… |