| CVE-2026-61505 | 6.9 | 37.5 | rejetto | hfs | CWE-22 | Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter |
| CVE-2026-4769 | 9.3 | 37.2 | WAGO | 0765-110x/0100-0000 | CWE-912 | Unauthenticated Access to Internal Diagnostic Interface |
| CVE-2026-62184 | 8.7 | 37.0 | openwrt | luci-app-banip | CWE-116 | luci-app-banip Log Monitor IP Extraction Bypass |
| CVE-2026-15544 | 7.4 | 36.5 | Shibby | Tomato | CWE-119 | Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow |
| CVE-2026-13221 | 9.1 | 36.0 | SHAY | perl | CWE-190 | Perl versions through 5.43.9 produce silently incorrect regular expression ma… |
| CVE-2026-51540 | 9.8 | 35.1 | n/a | n/a | CWE-191 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe m… |
| CVE-2026-51541 | 9.1 | 35.1 | n/a | n/a | CWE-125 | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message … |
| CVE-2026-52533 | 9.8 | 34.5 | n/a | n/a | CWE-269 | An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escal… |
| CVE-2026-12257 | 9.3 | 34.2 | Mura Software | CMS | CWE-94 | Remote code execution in Mura Software’s CMS |
| CVE-2026-39042 | 7.5 | 34.1 | n/a | n/a | CWE-190 | An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4… |
| CVE-2026-57743 | 8.1 | 33.5 | stmcan | RT-Theme 18 | Extensions | CWE-98 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulne… |
| CVE-2026-15542 | 6.9 | 33.5 | will-moss | Isaiah | CWE-287 | will-moss Isaiah Websocket Connection Authentication main.go improper authent… |
| CVE-2026-49876 | 6.5 | 33.4 | Apache Software Foundation | Apache Gravitino | CWE-918 | Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-si… |
| CVE-2026-15557 | 5.5 | 32.9 | waooAI | waoowaoo | CWE-287 | waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight impr… |
| CVE-2026-15545 | 7.4 | 32.8 | Shibby | Tomato | CWE-119 | Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write |
| CVE-2026-15685 | 7.5 | 32.2 | Ollama | Ollama | CWE-129 | Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vuln… |
| CVE-2026-56877 | 6.3 | 32.3 | Skillable | SCORM Lab Launch Integration | CWE-472 | The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026… |
| CVE-2026-57856 | 8.7 | 32.1 | Cockpit HQ | Cockpit CMS | CWE-22 | Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API |
| CVE-2026-51538 | 9.1 | 32.0 | n/a | n/a | CWE-284 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access … |
| CVE-2026-58228 | 5.1 | 31.3 | phoenixframework | phoenix_live_view | CWE-79 | Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link> |
| CVE-2026-61462 | 9.2 | 31.2 | zereight | mcp-gitlab | CWE-73 | mcp-gitlab Path Traversal via job_id Parameter |
| CVE-2026-57724 | 9.8 | 30.6 | Themeum | Kirki | CWE-502 | WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability |
| CVE-2026-57738 | 9.8 | 30.6 | axiomthemes | 777 | CWE-502 | WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability |
| CVE-2026-57401 | 9.9 | 30.2 | Brainstorm Force | SureDash | CWE-22 | WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability |
| CVE-2026-62327 | 9.3 | 30.2 | decolua | 9Router | CWE-306 | 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats |
| CVE-2026-62328 | 8.7 | 30.2 | decolua | 9Router | CWE-359 | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints |
| CVE-2026-57389 | 8.6 | 30.3 | Adrian Tobey | Groundhogg | CWE-22 | WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability |
| CVE-2026-57709 | 8.6 | 30.3 | WP Swings | Membership For WooCommerce | CWE-22 | WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletio… |
| CVE-2026-57788 | 7.5 | 30.1 | Edge-Themes | Aalto | CWE-98 | WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability |
| CVE-2026-57789 | 7.5 | 30.1 | jwsthemes | Aqua | CWE-98 | WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability |
| CVE-2026-57790 | 7.5 | 30.1 | ThemeMove | Billey | CWE-98 | WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability |
| CVE-2026-57791 | 7.5 | 30.1 | ThemeMove | Brook | CWE-98 | WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability |
| CVE-2026-57792 | 7.5 | 30.1 | Mikado-Themes | Dør | CWE-98 | WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability |
| CVE-2026-57793 | 7.5 | 30.1 | Elated-Themes | Flow | CWE-98 | WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability |
| CVE-2026-57794 | 7.5 | 30.1 | uxper | Golo Framework | CWE-98 | WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability |
| CVE-2026-57795 | 7.5 | 30.1 | themelexus | Kitchor | CWE-98 | WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability |
| CVE-2026-57796 | 7.5 | 30.1 | VLThemes | Leedo | CWE-98 | WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability |
| CVE-2026-57798 | 7.5 | 30.1 | SaurabhSharma | NewsPlus Shortcodes | CWE-98 | WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerab… |
| CVE-2026-57799 | 7.5 | 30.1 | uxper | Nuss | CWE-98 | WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability |
| CVE-2026-57800 | 7.5 | 30.1 | Edge-Themes | Overworld | CWE-98 | WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2026-57801 | 7.5 | 30.1 | Select-Themes | SetSail | CWE-98 | WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability |
| CVE-2026-57802 | 7.5 | 30.1 | Select-Themes | Struktur | CWE-98 | WordPress Struktur theme < 2.7 - Local File Inclusion vulnerability |
| CVE-2026-57803 | 7.5 | 30.1 | Select-Themes | Struktur Core | CWE-98 | WordPress Struktur Core plugin < 2.7 - Local File Inclusion vulnerability |
| CVE-2026-57804 | 7.5 | 30.1 | CodexThemes | TheGem Theme Elements (for Elementor) | CWE-98 | WordPress TheGem Theme Elements (for Elementor) plugin < 5.12.1.1 - Local Fil… |
| CVE-2026-61463 | 8.7 | 29.9 | go-shiori | shiori | CWE-269 | Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account |
| CVE-2026-59245 | 8.1 | 29.1 | Apache Software Foundation | Apache Airflow FAB provider | CWE-269 | Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the… |
| CVE-2026-58487 | 5.1 | 28.9 | hedgedoc | hedgedoc | CWE-79 | HedgeDoc: Stored HTML injection via email local-part |
| CVE-2026-57433 | 9.8 | 28.8 | HAARG | Storable | CWE-190 | Storable versions before 3.41 for Perl have a signed integer overflow when de… |
| CVE-2026-57719 | 10.0 | 27.8 | CodeRevolution | Aimogen Pro | CWE-434 | WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability |
| CVE-2026-58411 | 7.0 | 27.7 | ChurchCRM | CRM | CWE-79 | ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request pa… |
| CVE-2026-15596 | 2.1 | 27.8 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System subject.php cross site scrip… |
| CVE-2026-55771 | 8.8 | 27.5 | cedar-policy | cedar-java | CWE-94 | CedarJava has policy injection, type confusion, and incorrect equality compar… |
| CVE-2026-57371 | 8.8 | 27.4 | denishua | WPJAM Basic | CWE-502 | WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability |
| CVE-2026-51539 | 7.5 | 27.3 | n/a | n/a | CWE-400 | A Denial of Service (DoS) vulnerability exists in the receive loop of libmodb… |
| CVE-2026-61503 | 6.9 | 27.3 | rejetto | hfs | CWE-204 | Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences |
| CVE-2026-15597 | 5.5 | 25.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection |
| CVE-2026-57815 | 7.5 | 25.4 | WPMU DEV - Your All-in-One WordPress Platform | Forminator | CWE-22 | WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability |
| CVE-2026-57710 | 9.9 | 24.7 | quantumcloud | WoowBot Pro Max | CWE-434 | WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability |
| CVE-2026-57697 | 7.5 | 24.7 | Metagauss | ProfileGrid | CWE-288 | WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability |
| CVE-2026-15541 | 6.9 | 24.4 | will-moss | Isaiah | CWE-862 | will-moss Isaiah Master Websocket server.go Server.Handle authorization |
| CVE-2026-22102 | 9.3 | 24.1 | EVbee | DC-80 | CWE-20 | Arbitrary file overwrite through certificate update functionality |
| CVE-2026-62240 | 8.3 | 24.2 | crewAIInc | crewAI | CWE-918 | CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools |
| CVE-2026-15598 | 5.3 | 24.0 | antv | layout | CWE-94 | antv layout object.js setNestedValue prototype pollution |
| CVE-2026-22096 | 9.3 | 23.9 | EVbee | DC-80 | CWE-306 | Missing authentication for webserver endpoints |
| CVE-2026-57811 | 10.0 | 23.8 | Realtyna | Realtyna Organic IDX plugin | CWE-94 | WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution… |
| CVE-2026-15530 | 5.5 | 23.8 | n/a | WuzhiCMS | CWE-200 | WuzhiCMS Attachment API index.php listimage information disclosure |
| CVE-2026-57713 | 8.8 | 23.4 | Marcus (aka @msykes) | Events Manager | CWE-502 | WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability |
| CVE-2026-61501 | 5.3 | 23.5 | rejetto | hfs | CWE-79 | Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer |
| CVE-2026-57744 | 9.8 | 23.0 | stmcan | RT-Theme 18 | Extensions | CWE-502 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulne… |
| CVE-2026-57770 | 9.8 | 23.0 | ThemeGoods | Grand Photography | CWE-502 | WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability |
| CVE-2026-59518 | 9.8 | 23.0 | wpWax | Directorist | CWE-502 | WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability |
| CVE-2026-61458 | 8.7 | 23.0 | pglombardo | PasswordPusher | CWE-307 | PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint |
| CVE-2026-57830 | 8.8 | 22.9 | joomshaper.com | Helix Ultimate extension for Joomla | CWE-862 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion i… |
| CVE-2026-57805 | 7.5 | 22.6 | Select-Themes | Tonda | CWE-98 | WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability |
| CVE-2026-15594 | 2.9 | 22.4 | waooAI | waoowaoo | CWE-266 | waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authoriza… |
| CVE-2026-62199 | 8.7 | 22.0 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering |
| CVE-2026-62200 | 8.7 | 22.0 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport |
| CVE-2026-58488 | 6.9 | 22.1 | hedgedoc | hedgedoc | CWE-290 | HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing |
| CVE-2026-55773 | 8.8 | 22.0 | cedar-policy | cedar-java | CWE-94 | CedarJava has a policy injection vulnerability |
| CVE-2026-57774 | 5.3 | 21.8 | vowelweb | VW Food Corner | CWE-862 | WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability |
| CVE-2026-57776 | 5.3 | 21.8 | vowelweb | VW Wedding | CWE-862 | WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability |
| CVE-2026-59521 | 7.2 | 21.6 | ShapedPlugin LLC | Real Testimonials | CWE-502 | WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerabi… |
| CVE-2026-40553 | 5.1 | 21.5 | GNU | gawk | CWE-121 | Stack-based buffer overflow in gawk |
| CVE-2026-57727 | 7.5 | 21.2 | Themeum | Kirki | CWE-862 | WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability |
| CVE-2026-62190 | 8.7 | 21.0 | OpenClaw | OpenClaw | CWE-706 | OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper |
| CVE-2026-62185 | 8.6 | 20.9 | argoproj | argo-helm | CWE-1188 | Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE |
| CVE-2026-57702 | 9.3 | 20.8 | Melograno Venture Studio | Amelia | CWE-89 | WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability |
| CVE-2026-57707 | 9.3 | 20.8 | quantumcloud | Simple Business Directory Pro | CWE-89 | WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vuln… |
| CVE-2026-57714 | 9.3 | 20.8 | LatePoint | LatePoint | CWE-89 | WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability |
| CVE-2026-57726 | 9.3 | 20.8 | Themeum | Kirki | CWE-89 | WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability |
| CVE-2026-57739 | 9.3 | 20.8 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-89 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulner… |
| CVE-2026-57855 | 8.7 | 20.8 | Cockpit HQ | Cockpit CMS | CWE-284 | Cockpit CMS Missing Authorization in Bucket File Storage API |
| CVE-2026-62242 | 7.7 | 20.8 | codecentric | spring-boot-admin | CWE-918 | Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration |
| CVE-2026-57386 | 8.8 | 20.2 | Kodezen LLC | aBlocks | CWE-266 | WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability |
| CVE-2026-57410 | 8.8 | 20.2 | MailerPress Team | MailerPress | CWE-266 | WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability |
| CVE-2026-57729 | 7.5 | 20.3 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-15595 | 2.1 | 20.3 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System forsubject.php cross site sc… |
| CVE-2026-58500 | 8.2 | 20.0 | appium | appium-mcp | CWE-79 | MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGener… |
| CVE-2026-11964 | 9.1 | 19.9 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signa… |
| CVE-2026-15516 | 2.9 | 19.8 | n/a | MacCMS Pro | CWE-285 | MacCMS Pro Installation Index.php step5 authorization |
| CVE-2026-55772 | 8.8 | 19.6 | cedar-policy | cedar-java | CWE-843 | CedarJava has a type confusion vulnerability |
| CVE-2026-4765 | 5.1 | 19.6 | RD Station Conversas | Tallos Chat | CWE-79 | Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas |
| CVE-2026-57773 | 7.6 | 19.3 | Zorem | Advanced Shipment Tracking for WooCommerce | CWE-89 | WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Inje… |
| CVE-2026-57393 | 6.5 | 19.2 | EDGARROJAS | WooCommerce PDF Invoice Builder | CWE-497 | WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Ex… |
| CVE-2026-15537 | 5.5 | 18.2 | SourceCodester | Online Book Store System | CWE-74 | SourceCodester Online Book Store System login.php sql injection |
| CVE-2026-12582 | 8.6 | 18.1 | Unknown | Library Management System | — | Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id |
| CVE-2026-57813 | 9.8 | 17.9 | properfraction | MailOptin | CWE-266 | WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability |
| CVE-2026-15680 | 7.5 | 17.8 | Lorex | 2K Indoor Wi-Fi Security Camera | CWE-134 | Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Co… |
| CVE-2026-15574 | 7.5 | 17.7 | Red Hat | Red Hat OpenShift AI (RHOAI) | CWE-538 | Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header an… |
| CVE-2026-15529 | 5.3 | 17.6 | yzhao062 | pyod | CWE-20 | yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization |
| CVE-2026-15538 | 5.3 | 17.3 | primefaces | primereact | CWE-94 | primefaces primereact API ObjectUtils.mutateFieldData prototype pollution |
| CVE-2026-15517 | 5.5 | 17.1 | Jinher | OA | CWE-74 | Jinher OA PlanGiveOut.aspx sql injection |
| CVE-2026-15607 | 2.1 | 17.1 | tanstack | db | CWE-94 | tanstack db Alias Path select.ts select prototype pollution |
| CVE-2026-22098 | 9.2 | 16.9 | EVbee | DC-80 | CWE-532 | Sensitive information is written to logs |
| CVE-2026-57385 | 8.5 | 16.9 | appsbd | Vitepos | CWE-89 | WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability |
| CVE-2026-57771 | 8.5 | 16.9 | Milan Petrovic | GD Rating System | CWE-89 | WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability |
| CVE-2026-57772 | 8.5 | 16.9 | WP Inventory | WP Inventory Manager | CWE-89 | WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability |
| CVE-2026-57787 | 8.5 | 16.9 | CreativeWS | CWS SVGicons | CWE-89 | WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability |
| CVE-2026-62194 | 8.7 | 16.7 | OpenClaw | OpenClaw | CWE-732 | OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install |
| CVE-2026-15553 | 6.9 | 16.7 | Ragic | Enterprise Cloud Database | CWE-434 | Ragic|Enterprise Cloud Database - Arbitrary File Upload |
| CVE-2026-14846 | 4.5 | 16.7 | PrestaShop | The firmware | CWE-1236 | Incorrect neutralisation in the PrestaShop firmware |
| CVE-2026-57364 | 6.5 | 16.3 | WPDeveloper | Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More | CWE-1284 | WordPress Better Payment – Instant Payments, Donations, Fundraising with Subs… |
| CVE-2026-57395 | 6.5 | 16.3 | Themefic | Tourfic | CWE-862 | WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability |
| CVE-2026-57418 | 6.5 | 16.3 | BoldGrid | Client Invoicing by Sprout Invoices | CWE-862 | WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Acce… |
| CVE-2026-15518 | 2.0 | 16.4 | AREA 17 | Twill CMS | CWE-284 | AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile un… |
| CVE-2026-15533 | 2.0 | 16.4 | n/a | DedeCMS | CWE-74 | DedeCMS Column Management search.php code injection |
| CVE-2026-15535 | 2.1 | 16.2 | AkariAsai | self-rag | CWE-20 | AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserializa… |
| CVE-2026-62189 | 7.6 | 16.2 | OpenClaw | OpenClaw | CWE-59 | OpenClaw < 2026.6.9 Symlink Following via Mirror Sync |
| CVE-2026-14165 | 7.5 | 16.2 | Dassault Systèmes | Tuleap Enterprise Edition | CWE-639 | Authorization Bypass Through User-Controlled Key vulnerability affecting Tule… |
| CVE-2026-15584 | 7.5 | 16.1 | Red Hat | Pen Drive Powered by Red Hat Lightspeed | CWE-250 | Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot deb… |
| CVE-2026-57698 | 6.5 | 15.9 | VillaTheme | Abandoned Cart Recovery for WooCommerce | CWE-288 | WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken A… |
| CVE-2026-59515 | 9.3 | 15.7 | Sergey | AIWU | CWE-89 | WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability |
| CVE-2026-57377 | 6.5 | 15.6 | WPXPO | WowAddons | CWE-862 | WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability |
| CVE-2026-57390 | 6.5 | 15.6 | EDGARROJAS | Extra Product Options Builder for WooCommerce | CWE-862 | WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - B… |
| CVE-2026-57392 | 6.5 | 15.6 | Themefic | Tourfic | CWE-862 | WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability |
| CVE-2026-57404 | 6.5 | 15.6 | magepeopleteam | Booking and Rental Manager | CWE-862 | WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control … |
| CVE-2026-57408 | 6.5 | 15.6 | peachpayments | Peach Payments Gateway | CWE-862 | WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vuln… |
| CVE-2026-57412 | 6.5 | 15.6 | Codemenschen | Gift Vouchers | CWE-862 | WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability |
| CVE-2026-57424 | 6.5 | 15.6 | knitpay | Razorpay Payment Links for WooCommerce | CWE-862 | WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Acc… |
| CVE-2026-12385 | 4.3 | 15.7 | nextendweb | Smart Slider 3 | CWE-200 | Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contribu… |
| CVE-2026-15540 | 2.1 | 15.6 | SourceCodester | Online Book Store System | CWE-73 | SourceCodester Online Book Store System Administrative index.php php file inc… |
| CVE-2026-49969 | 5.3 | 15.4 | plank | laravel-mediable | CWE-918 | Laravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling |
| CVE-2026-6850 | 6.5 | 15.4 | Mattermost | Mattermost | CWE-1333 | Crafted message attachment causes client-side denial of service via markdown … |
| CVE-2026-57797 | 4.3 | 15.3 | ThemeMove | EduMall | CWE-862 | WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability |
| CVE-2026-15618 | 2.1 | 15.3 | mosaxiv | clawlet | CWE-693 | mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection me… |
| CVE-2026-62143 | 8.3 | 15.2 | misp | misp-modules | CWE-918 | Server-Side Request Forgery protection bypass in misp-modules html_to_markdow… |
| CVE-2026-57378 | 7.5 | 15.1 | Phil Kurth | Advanced Forms | CWE-862 | WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability |
| CVE-2026-57705 | 7.5 | 15.1 | Nexcess | Event Tickets | CWE-862 | WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability |
| CVE-2026-15519 | 1.3 | 15.1 | usestrix | strix | CWE-829 | usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted c… |
| CVE-2026-57694 | 6.5 | 15.0 | Themeum | Tutor LMS | CWE-639 | WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDO… |
| CVE-2026-58486 | 8.3 | 14.6 | hedgedoc | hedgedoc | CWE-400 | HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter |
| CVE-2026-57400 | 6.5 | 14.7 | WP Swings | Event Tickets Manager for WooCommerce | CWE-862 | WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Acce… |
| CVE-2026-57406 | 6.5 | 14.7 | Roxnor | FundEngine | CWE-862 | WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability |
| CVE-2026-62192 | 7.2 | 14.4 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass |
| CVE-2026-62195 | 8.7 | 14.0 | OpenClaw | OpenClaw | CWE-732 | OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback |
| CVE-2026-62196 | 8.7 | 14.0 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs |
| CVE-2026-15539 | 2.0 | 13.6 | SourceCodester | Online Book Store System | CWE-284 | SourceCodester Online Book Store System Book Image Upload Feature index.php b… |
| CVE-2026-14934 | 9.4 | 13.6 | Google Cloud | BigQuery | CWE-862 | Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dat… |
| CVE-2026-61955 | 7.6 | 13.5 | Hannan | گرویتی فرم فارسی | CWE-89 | WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability |
| CVE-2026-57405 | 7.1 | 13.5 | themehunk | Open Shop | CWE-862 | WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability |
| CVE-2026-57740 | 7.1 | 13.5 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-862 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Contro… |
| CVE-2026-57768 | 8.2 | 12.9 | favethemes | Houzez Login Register | CWE-266 | WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulner… |
| CVE-2026-58408 | 6.5 | 12.4 | ChurchCRM | CRM | CWE-862 | ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privilege… |
| CVE-2026-58102 | 9.1 | 12.0 | JONASBN | Crypt::OpenSSL::X509 | CWE-125 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bound… |
| CVE-2026-15525 | 2.1 | 12.1 | kLOsk | adloop | CWE-918 | kLOsk adloop write.py _validate_urls server-side request forgery |
| CVE-2026-62187 | 8.6 | 11.9 | openclaw | feishu | CWE-863 | OpenClaw < 2026.6.9 Feishu tools Authorization Bypass |
| CVE-2026-62188 | 8.6 | 11.9 | openclaw | feishu | CWE-863 | OpenClaw < 2026.6.9 Feishu Authorization Bypass |
| CVE-2026-40467 | 5.1 | 11.9 | GNU | gawk | CWE-416 | Use after free in gawk |
| CVE-2026-40469 | 5.1 | 11.9 | GNU | gawk | CWE-190 | Heap buffer overflow in gawk |
| CVE-2026-57419 | 6.5 | 11.8 | Fahad Mahmood | Stock Locations for WooCommerce | CWE-862 | WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Con… |
| CVE-2026-57432 | 8.4 | 11.6 | SHAY | perl | CWE-125 | Perl versions through 5.43.10 have an integer overflow in S_measure_struct le… |
| CVE-2026-9708 | 4.9 | 11.5 | Mattermost | Mattermost | CWE-639 | Incoming webhook user attribution via unvalidated webhook owner |
| CVE-2026-15532 | 1.9 | 11.5 | SourceCodester | Online Book Store System | CWE-79 | SourceCodester Online Book Store System User Management cross site scripting |
| CVE-2026-62147 | 6.5 | 11.3 | Red Hat | Red Hat OpenShift distributed tracing 3 | CWE-863 | Tempo-operator: tempo operator: query rbac bypass |
| CVE-2026-22097 | 9.3 | 11.2 | EVbee | DC-80 | CWE-347 | Missing firmware validation allows remote code execution |
| CVE-2026-57778 | 5.3 | 11.2 | wpdevart | Booking calendar, Appointment Booking System | CWE-862 | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Bro… |
| CVE-2026-57779 | 5.3 | 11.2 | themebeez | Fascinate | CWE-862 | WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability |
| CVE-2026-57781 | 5.3 | 11.2 | Sovlix | MeetingHub | CWE-862 | WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability |
| CVE-2026-57782 | 5.3 | 11.2 | PressTigers | Universal Clocks | CWE-862 | WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability |
| CVE-2026-62191 | 7.1 | 11.1 | OpenClaw | OpenClaw | CWE-862 | OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations |
| CVE-2026-57810 | 8.5 | 10.8 | Saad Iqbal | APIExperts Square for WooCommerce | CWE-89 | WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection v… |
| CVE-2026-15552 | 5.3 | 10.8 | Ragic | Enterprise Cloud Database | CWE-79 | Ragic|Enterprise Cloud Database - Stored Cross-Site Scripting |
| CVE-2026-58101 | 7.5 | 10.7 | JONASBN | Crypt::OpenSSL::X509 | CWE-476 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service v… |
| CVE-2026-49971 | 5.3 | 10.6 | plank | laravel-mediable | CWE-79 | Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload |
| CVE-2026-11963 | 8.1 | 10.3 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Memb… |
| CVE-2026-40468 | 2.1 | 10.3 | GNU | gawk | CWE-190 | Heap buffer overflow in gawk |
| CVE-2025-45869 | 7.3 | 10.1 | n/a | n/a | CWE-918 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server… |
| CVE-2026-15523 | 2.1 | 10.2 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System dashboard.php sql injection |
| CVE-2026-15536 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patviewprescription.php sql injection |
| CVE-2026-15558 | 2.1 | 10.2 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System deletemp.php sql injection |
| CVE-2026-15559 | 2.1 | 10.2 | CodeAstro | Simple Online Leave Management System | CWE-74 | CodeAstro Simple Online Leave Management System POST accept.php sql injection |
| CVE-2026-62197 | 6.3 | 10.0 | OpenClaw | OpenClaw | CWE-918 | OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery |
| CVE-2026-61975 | 5.3 | 9.8 | Crocoblock | JetReviews | CWE-497 | WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-61976 | 5.3 | 9.8 | Crocoblock | JetBlocks For Elementor | CWE-497 | WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure v… |
| CVE-2026-61977 | 5.3 | 9.8 | Crocoblock | JetSearch | CWE-497 | WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-57375 | 6.5 | 9.4 | FluxBuilder | MStore API | CWE-862 | WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability |
| CVE-2026-61952 | 4.9 | 9.3 | Jose Vega | WooCommerce Bulk Edit Products – WP Sheet Editor | CWE-862 | WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 -… |
| CVE-2026-62186 | 7.2 | 9.2 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override |
| CVE-2026-61971 | 2.7 | 9.2 | Cozmoslabs | User Profile Picture | CWE-639 | WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object Refer… |
| CVE-2026-57812 | 6.5 | 9.0 | NSquared | Simply Schedule Appointments | CWE-862 | WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Con… |
| CVE-2026-22099 | 8.7 | 8.7 | EVbee | DC-80 | CWE-287 | Missing authentication for Bluetooth communication |
| CVE-2026-57372 | 7.2 | 8.8 | denishua | WPJAM Basic | CWE-918 | WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vuln… |
| CVE-2026-57407 | 7.2 | 8.8 | WP Swings | PDF Generator for WordPress | CWE-918 | WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request F… |
| CVE-2026-62193 | 6.9 | 8.3 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install |
| CVE-2026-12274 | 6.5 | 8.3 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR |
| CVE-2026-57829 | 8.7 | 8.1 | joomshaper.com | Helix Ultimate extension for Joomla | CWE-79 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultim… |
| CVE-2026-61502 | 5.1 | 8.1 | rejetto | hfs | CWE-352 | Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests |
| CVE-2026-57368 | 7.1 | 7.8 | NooTheme | Jobmonster | CWE-79 | WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vu… |
| CVE-2026-57421 | 7.1 | 7.8 | CRM Perks | CRM Perks Forms | CWE-79 | WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-57733 | 7.1 | 7.8 | tagDiv | tagDiv Cloud Library | CWE-79 | WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) v… |
| CVE-2026-57695 | 7.1 | 7.7 | Dan Rossiter | Document Gallery | CWE-79 | WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-14906 | 5.3 | 7.5 | Mozilla | Firefox for iOS | CWE-434 | Malicious webpage titles could allow overwriting of bundled PDF resources whe… |
| CVE-2026-61983 | 5.3 | 7.4 | andy_moyle | Church Admin | CWE-862 | WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability |
| CVE-2026-61985 | 5.3 | 7.4 | magepeopleteam | Car Rental Manager | CWE-862 | WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerab… |
| CVE-2026-57363 | 7.1 | 7.3 | QuantumCloud | ChatBot | CWE-79 | WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57369 | 7.1 | 7.3 | themifyme | Themify Builder | CWE-79 | WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-57376 | 7.1 | 7.3 | Element Invader | ElementInvader Addons for Elementor | CWE-79 | WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Sc… |
| CVE-2026-57379 | 7.1 | 7.3 | WPPOOL | FormyChat | CWE-79 | WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57380 | 7.1 | 7.3 | hupe13 | Extensions for Leaflet Map | CWE-79 | WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XS… |
| CVE-2026-57381 | 7.1 | 7.3 | Property Hive | PropertyHive | CWE-79 | WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57382 | 7.1 | 7.3 | Mitchell Bennis | Simple File List | CWE-79 | WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (… |
| CVE-2026-57383 | 7.1 | 7.3 | eyecix | JobSearch | CWE-79 | WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57387 | 7.1 | 7.3 | picu | picu | CWE-79 | WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57388 | 7.1 | 7.3 | Themefic | Hydra Booking | CWE-79 | WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57394 | 7.1 | 7.3 | Tribulant Software | Newsletters | CWE-79 | WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57396 | 7.1 | 7.2 | Flintop | Free Gifts for WooCommerce | CWE-79 | WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting … |
| CVE-2026-57398 | 7.1 | 7.3 | WebCodingPlace | Real Estate Manager Pro | CWE-79 | WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XS… |
| CVE-2026-57399 | 7.1 | 7.3 | Proxy & VPN Blocker | Proxy & VPN Blocker | CWE-79 | WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vu… |
| CVE-2026-57403 | 7.1 | 7.3 | Milan Petrovic | GD Security Headers | CWE-79 | WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57409 | 7.1 | 7.2 | RealMag777 | Active Products Tables for WooCommerce | CWE-79 | WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site… |
| CVE-2026-57411 | 7.1 | 7.2 | Aman | CF7 Views – Complete Entry Management for Contact Form 7 | CWE-79 | WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= … |
| CVE-2026-57415 | 7.1 | 7.3 | Codemenschen | Gift Vouchers | CWE-79 | WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57416 | 7.1 | 7.3 | SiteGround | SiteGround Email Marketing | CWE-79 | WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (… |
| CVE-2026-57417 | 7.1 | 7.3 | RexTheme | Cart Lift | CWE-79 | WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57422 | 7.1 | 7.3 | VillaTheme | Bopo – WooCommerce Product Bundle Builder | CWE-79 | WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflect… |
| CVE-2026-57423 | 7.1 | 7.2 | Kofi Mokome | Message Filter for Contact Form 7 | CWE-79 | WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cro… |
| CVE-2026-57668 | 7.1 | 7.2 | Basix | NEX-Forms | CWE-79 | WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57706 | 7.1 | 7.2 | Dokan, Inc. | Dokan | CWE-79 | WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57708 | 7.1 | 7.2 | CRM Perks | Contact Form Entries | CWE-79 | WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) v… |
| CVE-2026-57712 | 7.1 | 7.2 | WPZOOM | WPZOOM Portfolio | CWE-79 | WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57715 | 7.1 | 7.2 | WPManageNinja | Fluent CRM | CWE-79 | WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57718 | 7.1 | 7.2 | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-79 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-57725 | 7.1 | 7.2 | Themeum | Kirki | CWE-79 | WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57728 | 7.1 | 7.2 | UX-themes | Flatsome | CWE-79 | WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-57732 | 7.1 | 7.2 | tagDiv | tagDiv Opt-In Builder | CWE-79 | WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) … |
| CVE-2026-57734 | 7.1 | 7.2 | tagDiv | tagDiv Composer | CWE-79 | WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (X… |
| CVE-2026-57741 | 7.1 | 7.2 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-79 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting… |
| CVE-2026-57745 | 7.1 | 7.2 | stmcan | RT-Theme 18 | Extensions | CWE-79 | WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scrip… |
| CVE-2026-10106 | 6.5 | 7.2 | Mattermost | Mattermost | CWE-863 | Unauthorized users can trigger interactive post actions in private channels v… |
| CVE-2026-58410 | 7.1 | 7.2 | ChurchCRM | CRM | CWE-639 | ChurchCRM: Improper object-level authorization allows low-privileged users to… |
| CVE-2026-9571 | 6.5 | 7.2 | Mattermost | Mattermost | CWE-305 | Deactivated user accounts can continue to obtain valid OAuth access tokens vi… |
| CVE-2026-61504 | 5.1 | 7.0 | rejetto | hfs | CWE-79 | Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing |
| CVE-2026-12275 | 7.1 | 6.8 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private C… |
| CVE-2026-10085 | 5.4 | 6.7 | Mattermost | Mattermost | CWE-862 | Ordinary group/direct message member can enable group_constrained and remove … |
| CVE-2026-12271 | 5.4 | 6.7 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR |
| CVE-2026-12396 | 5.4 | 6.7 | Unknown | WP Job Portal | — | WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rej… |
| CVE-2026-61958 | 5.4 | 6.7 | Saad Iqbal | License Manager for WooCommerce | CWE-862 | WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Conten… |
| CVE-2026-61968 | 5.4 | 6.7 | Saad Iqbal | myCred | CWE-862 | WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability |
| CVE-2026-12273 | 4.3 | 6.7 | Unknown | Tutor LMS | — | Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation |
| CVE-2026-12536 | 6.4 | 6.6 | themefusion | Avada (Fusion) Builder | CWE-79 | Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-57786 | 8.8 | 6.1 | purethemes | WorkScout-Core | CWE-352 | WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF)… |
| CVE-2026-57391 | 6.5 | 6.0 | Tangible | Loops & Logic | CWE-79 | WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57413 | 6.4 | 6.0 | bdthemes | Instant Image Generator | CWE-918 | WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forge… |
| CVE-2026-9824 | 4.3 | 5.9 | Mattermost | Mattermost | CWE-862 | Remote cluster metadata enumeration via /share-channel autocomplete |
| CVE-2026-12397 | 4.3 | 5.9 | Unknown | WP Job Portal | — | WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR |
| CVE-2026-22093 | 9.5 | 5.7 | EVbee | EVbee Service | CWE-295 | Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app |
| CVE-2026-62198 | 5.3 | 5.7 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search |
| CVE-2026-48363 | 8.2 | 5.5 | Adobe | ColdFusion | CWE-427 | ColdFusion | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-48364 | 8.2 | 5.5 | Adobe | ColdFusion | CWE-427 | ColdFusion | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-57365 | 6.5 | 5.3 | Hitesh Chandwani | reCAPTCHA (v2 & v3) for Asgaros Forum | CWE-79 | WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site … |
| CVE-2026-57402 | 6.5 | 5.3 | wpdesk | Flexible Refund and Return Order for WooCommerce | CWE-79 | WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 -… |
| CVE-2026-57414 | 6.5 | 5.3 | QuantumCloud | ChatBot for eCommerce – WoowBot | CWE-79 | WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Script… |
| CVE-2026-57420 | 6.5 | 5.3 | Netrr | Author Box WP Lens | CWE-79 | WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57693 | 6.5 | 5.3 | Spacetime | Ad Inserter | CWE-79 | WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57711 | 6.5 | 5.3 | PSM Plugins | SupportCandy | CWE-79 | WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57780 | 6.5 | 5.3 | Plugin Envision | Envision Page Builder | CWE-79 | WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) v… |
| CVE-2026-57783 | 6.5 | 5.3 | merkulove | Speaker | CWE-79 | WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-59523 | 6.5 | 5.1 | NSquared | Simply Schedule Appointments | CWE-862 | WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Co… |
| CVE-2026-6541 | 4.3 | 4.9 | Mattermost | Mattermost | CWE-639 | Unscoped updates to other playbooks' metric configuration |
| CVE-2026-9820 | 3.8 | 4.9 | Mattermost | Mattermost | CWE-862 | Mattermost schemes teams endpoint exposes private team invite IDs |
| CVE-2026-15605 | 2.3 | 4.8 | n/a | wandb | CWE-327 | wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.downloa… |
| CVE-2026-10551 | 6.1 | 4.6 | Unknown | Breeze Cache | — | Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library |
| CVE-2026-57691 | 5.8 | 4.5 | Eli | Anti-Malware Security and Brute-Force Firewall | CWE-79 | WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - … |
| CVE-2026-10103 | 4.3 | 4.2 | Mattermost | Mattermost | CWE-639 | Authenticated remote cluster can modify or delete posts it does not own in Ma… |
| CVE-2026-15684 | 7.3 | 4.0 | Glarysoft | Glary Utilities | CWE-59 | Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerabi… |
| CVE-2026-57814 | 7.1 | 4.0 | WPMU DEV - Your All-in-One WordPress Platform | Forminator | CWE-79 | WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57816 | 7.1 | 4.0 | FunnelKit | Funnel Builder by FunnelKit | CWE-79 | WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripti… |
| CVE-2026-59516 | 7.1 | 4.0 | Room 34 Creative Services, LLC | ICS Calendar | CWE-79 | WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-9597 | 5.4 | 3.9 | Mattermost | Mattermost | CWE-305 | Deactivated guest accounts can authenticate via magic-link token in Mattermos… |
| CVE-2026-15527 | 1.9 | 3.8 | better-auth | better-icons | CWE-22 | better-auth better-icons scan_project_icons/sync_icon path traversal |
| CVE-2026-12081 | 5.0 | 3.8 | Unknown | Database for Contact Form 7, WPforms, Elementor forms | — | Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticat… |
| CVE-2026-15521 | 1.9 | 3.6 | makafeli | n8n-workflow-builder | CWE-22 | makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal |
| CVE-2026-15522 | 1.9 | 3.6 | tugcantopaloglu | godot-mcp | CWE-22 | tugcantopaloglu godot-mcp run_project index.js validatePath path traversal |
| CVE-2026-15524 | 1.9 | 3.6 | alioshr | memory-bank-mcp | CWE-22 | alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal |
| CVE-2026-15526 | 1.9 | 3.6 | augmnt | augments-mcp-server | CWE-22 | augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProject… |
| CVE-2026-15520 | 1.9 | 3.5 | GNU | LibreDWG | CWE-119 | GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section he… |
| CVE-2026-15682 | 5.5 | 3.2 | AnyDesk | AnyDesk | CWE-59 | AnyDesk Support Information Link Following Denial-of-Service Vulnerability |
| CVE-2026-62239 | 5.3 | 2.9 | Dao-AILab | flash-attention | CWE-59 | FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py |
| CVE-2026-58489 | 6.8 | 2.7 | hedgedoc | hedgedoc | CWE-352 | HedgeDoc: CSRF in GitHub Gist export callback |
| CVE-2026-15531 | 1.9 | 2.3 | yashbhalgat | HashNeRF-pytorch | CWE-20 | yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deseriali… |
| CVE-2026-53365 | 5.5 | 2.2 | Linux | Linux | CWE-401 | vsock/virtio: fix zerocopy completion for multi-skb sends |
| CVE-2026-61970 | 4.9 | 2.1 | Themeisle | Auto Featured Image (Auto Post Thumbnail) | CWE-918 | WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server … |
| CVE-2026-7162 | 7.8 | 2.0 | WinFsp | WinFsp | CWE-190 | Successful exploitation of the integer overflow vulnerability could allow an … |
| CVE-2026-60103 | 6.8 | 1.9 | blender | blender | CWE-125 | Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block |
| CVE-2026-15515 | 6.4 | 1.9 | Tencent | PC Manager | CWE-426 | Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path |
| CVE-2026-53364 | 5.5 | 1.7 | Linux | Linux | CWE-401 | Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() |
| CVE-2026-15528 | 1.9 | 1.6 | lamaalrajih | kicad-mcp | CWE-693 | lamaalrajih kicad-mcp path_validator.py protection mechanism |
| CVE-2026-9492 | 8.5 | 1.4 | GIGABYTE | MBStorage | CWE-782 | GIGABYTE|Gigabyte Control Center - Improper Access Control |
| CVE-2026-61956 | 7.1 | 1.3 | hamsalam | ووسلام – همگام سازی ووکامرس و باسلام | CWE-352 | WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site R… |
| CVE-2026-15681 | 5.5 | 1.2 | AnyDesk | AnyDesk | CWE-59 | AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability |
| CVE-2026-15683 | 7.5 | 0.8 | Lorex | 2K Indoor Wi-Fi Security Camera | CWE-295 | Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certi… |
| CVE-2026-15551 | 5.5 | 0.2 | Samsung Open Source | rlottie | CWE-190 | Samsung rlottie: Numeric truncation in gray_hline() leads to heap-based buffe… |