Atomicorp WAF Research Notes
Selected CVE-related research notes documenting testing results, engineering observations, attack-pattern analysis, and WAF rule interactions.
These notes are not a CVE coverage matrix, completeness claim, certification list, or list of all vulnerabilities mitigated by Atomicorp products.
A published CVE research note documents a positive research finding for that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Last updated: 2026-07-29
| CVE | Name | Product | CVSS | Severity | Rules Observed |
|---|---|---|---|---|---|
| CVE-2009-0545 | ZeroShell <= 1.0beta11 Remote Code Execution | zeroshell | 10.0 | HIGH | 347009 |
| CVE-2010-5286 | Joomla! Component Jstore - 'Controller' Local File Inclusion | com_jstore | 10.0 | critical | 347009 |
| CVE-2011-0518 | LotusCMS 3.0 - Remote Code Execution | core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled | 10.0 | critical | 393655 |
| CVE-2013-5755 | Yealink VoIP Phone SIP-T38G - Remote Command Execution | sip-t38g | 10.0 | HIGH | 344370, 390726, 392647 |
| CVE-2014-8877 | WordPress Plugin CM Download Manager 2.0.0 - Code Injection | cm download manager | 10.0 | HIGH | 390726, 392301, 392647 |
| CVE-2017-5638 | Apache Struts 2 - Remote Command Execution | struts | 10.0 | critical | 390719 |
| CVE-2019-11510 | Pulse Connect Secure SSL VPN Arbitrary File Read | connect_secure | 10.0 | critical | 347009 |
| CVE-2019-16932 | Visualizer <3.3.1 - Blind Server-Side Request Forgery | visualizer | 10.0 | CRITICAL | 344362 |
| CVE-2019-7256 | eMerge E3 1.00-06 - Remote Code Execution | linear_emerge_essential_firmware | 10.0 | critical | 347009 |
| CVE-2021-44228 | Apache Log4j2 Remote Code Injection | log4j | 10.0 | critical | 345115 |
| CVE-2022-22536 | SAP Memory Pipes (MPI) Desynchronization | content_server | 10.0 | CRITICAL | 392301 |
| CVE-2024-10081 | CodeChecker <= 6.24.1 - Authentication Bypass | CodeChecker | 10.0 | critical | 392301 |
| CVE-2024-21650 | XWiki < 4.10.20 - Remote code execution | xwiki | 10.0 | critical | 340130 |
| CVE-2024-22476 | Intel Neural Compressor <2.5.0 - SQL Injection | - | 10.0 | CRITICAL | 341245 |
| CVE-2024-2389 | Progress Kemp Flowmon - Command Injection | - | 10.0 | critical | 344363 |
| CVE-2024-4040 | CrushFTP VFS - Sandbox Escape LFR | crushftp | 10.0 | critical | 392301 |
| CVE-2024-50603 | Aviatrix Controller - Remote Code Execution | controller | 10.0 | critical | 344360 |
| CVE-2025-20281 | Cisco ISE - Remote Code Execution | identity_services_engine | 10.0 | critical | 392301 |
| CVE-2025-2473 | Company Visitor Management System 1.0 - SQL Injection | - | 10.0 | critical | 340145 |
| CVE-2025-31324 | SAP NetWeaver Visual Composer Metadata Uploader - Deserialization | - | 10.0 | critical | 330791 |
| CVE-2025-34030 | sar2html <=3.2.2 Plot Parameter - Remote Code Execution | sar2html | 10.0 | critical | 340014 |
| CVE-2025-34035 | EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 Root Remote Code Execution | esr300 firmware | 10.0 | CRITICAL | 341245 |
| CVE-2025-34040 | Zhiyuan OA - arbitrary file upload leading | - | 10.0 | CRITICAL | 330791, 340007 |
| CVE-2025-45854 | JEHC-BPM - Remote Code Execute | jehc-bpm | 10.0 | CRITICAL | 390724 |
| CVE-2025-48828 | vBulletin replaceAdTemplate - Remote Code Execution | vbulletin | 10.0 | critical | 344370 |
| CVE-2025-49132 | Pterodactyl Panel - Remote Code Execution | panel | 10.0 | critical | 340007 |
| CVE-2025-53833 | LaRecipe < 2.8.1 Remote Code Execution via SSTI | larecipe | 10.0 | critical | 340087 |
| CVE-2025-55182 | React Server Components - Remote Code Execution | - | 10.0 | critical | 393655 |
| CVE-2025-59528 | Flowise - Remote Code Execution | flowise | 10.0 | CRITICAL | 380026 |
| CVE-2025-7160 | Zoo Management System 1.0 - SQL Injection | - | 10.0 | critical | 340145 |
| CVE-2025-9744 | Loan Management System 1.0 - SQL Injection | - | 10.0 | critical | 340156 |
| CVE-2026-22557 | UniFi Network Application - Path Traversal | unifi_network_application | 10.0 | CRITICAL | 340007 |
| CVE-2026-48907 | Joomla! JCE extension < 2.9.99.5 unauthenticated RCE | jce | 10.0 | CRITICAL | 333360, 383871 |
| CVE-2026-8054 | dotCMS Core Publish Audit API - Unauthenticated SQL Injection | dotcms | 10.0 | CRITICAL | 340145 |
| CVE-2019-10758 | mongo-express Remote Code Execution | mongo-express | 9.9 | critical | 380026 |
| CVE-2019-4013 | IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload | bigfix platform | 9.9 | CRITICAL | 392301 |
| CVE-2021-21345 | XStream < 1.4.16 - Remote Code Execution | xstream | 9.9 | critical | 344363 |
| CVE-2021-21881 | Lantronix PremierWave 2050 8.9.0.0R4 - Remote Command Injection | premierwave_2050_firmware | 9.9 | critical | 340014 |
| CVE-2021-33690 | SAP NetWeaver Development Infrastructure - Server Side Request Forgery | netweaver_development_infrastructure | 9.9 | critical | 340162 |
| CVE-2022-45808 | LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLi | learnpress | 9.9 | critical | 380122 |
| CVE-2023-6825 | WordPress File Manager <= 7.2.1 - Directory Traversal | file-manager | 9.9 | CRITICAL | 377360 |
| CVE-2024-27956 | WordPress Automatic Plugin <= 3.92.0 - SQL Injection | ValvePress Automatic | 9.9 | critical | 390614 |
| CVE-2024-51482 | ZoneMinder v1.37.* <= 1.37.64 - SQL Injection | zoneminder | 9.9 | CRITICAL | 380122 |
| CVE-2024-9463 | PaloAlto Networks Expedition - Remote Code Execution | expedition | 9.9 | critical | 344363 |
| CVE-2009-1151 | PhpMyAdmin Scripts - Remote Code Execution | phpmyadmin | 9.8 | CRITICAL | 344360 |
| CVE-2010-2861 | Adobe ColdFusion 8.0/8.0.1/9.0/9.0.1 LFI | coldfusion | 9.8 | CRITICAL | 390614 |
| CVE-2010-4239 | Tiki Wiki CMS Groupware 5.2 - Local File Inclusion | tikiwiki_cms/groupware | 9.8 | CRITICAL | 340007 |
| CVE-2012-1259 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 9.8 | CRITICAL | 341266, 390727, 392301, 392648 |
| CVE-2013-2681 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 9.8 | CRITICAL | 392301 |
| CVE-2013-4864 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 9.8 | CRITICAL | 390726, 392647 |
| CVE-2013-7137 | Burden 1.8 - Authentication Bypass | burden | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2013-7285 | XStream <1.4.6/1.4.10 - Remote Code Execution | xstream | 9.8 | critical | 344363 |
| CVE-2014-1203 | Eyou E-Mail <3.6 - Remote Code Execution | eyou | 9.8 | critical | 344360 |
| CVE-2014-3206 | Seagate BlackArmor NAS - Command Injection | blackarmor_nas_220_firmware | 9.8 | critical | 340014 |
| CVE-2014-6271 | ShellShock - Remote Code Execution | bash | 9.8 | critical | 330701 |
| CVE-2014-6287 | HTTP File Server <2.3c - Remote Command Execution | http_file_server | 9.8 | critical | 390614 |
| CVE-2014-8673 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 9.8 | CRITICAL | 340155, 390726, 392647 |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 9.8 | CRITICAL | 344360, 390720, 390726, 392647 |
| CVE-2014-9614 | Netsweeper 4.0.5 - Default Weak Account | netsweeper | 9.8 | critical | 392301 |
| CVE-2015-1635 | Microsoft Windows 'HTTP.sys' - Remote Code Execution | windows_7 | 9.8 | CRITICAL | 363434 |
| CVE-2015-3933 | GeniXCMS 0.0.3 - 'register.php' SQL Injection | genixcms | 9.8 | CRITICAL | 390720, 390726, 392647 |
| CVE-2015-4455 | WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload | aviary_image_editor_add-on_for_gravity_forms | 9.8 | critical | 340007 |
| CVE-2015-4664 | Xceedium Xsuite - Multiple Vulnerabilities | privileged access manager | 9.8 | CRITICAL | 344360, 347198, 390726, 392647 |
| CVE-2015-4667 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 9.8 | CRITICAL | 344360, 347198, 390726, 392647 |
| CVE-2015-6970 | Bosch Security Systems Dinion NBN-498 - Web Interface XML Injection | nbn-498 dinion2x day/night ip cameras firmware | 9.8 | CRITICAL | 390726, 392301, 392647 |
| CVE-2015-9323 | 404 to 301 <= 2.0.2 - Authenticated Blind SQL Injection | 404_to_301 | 9.8 | critical | 380122 |
| CVE-2016-10108 | Western Digital MyCloud NAS - Command Injection | mycloud_nas | 9.8 | critical | 344364 |
| CVE-2016-10134 | Zabbix - SQL Injection | zabbix | 9.8 | critical | 340159 |
| CVE-2016-15042 | WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Upload | frontend_file_manager | 9.8 | critical | 382238 |
| CVE-2016-15043 | WP Mobile Detector <= 3.5 - Unrestricted File Upload | - | 9.8 | critical | 340162 |
| CVE-2016-1555 | NETGEAR WNAP320 Access Point Firmware - Remote Command Injection | wnap320_firmware | 9.8 | critical | 340014 |
| CVE-2016-3088 | Apache ActiveMQ Fileserver - Arbitrary File Write | activemq | 9.8 | critical | 392301 |
| CVE-2016-4337 | Ktools Photostore 4.7.5 - Blind SQL Injection | photostore | 9.8 | CRITICAL | 390726, 392647 |
| CVE-2016-5674 | NUUO NVR camera debugging_center_utils_.php - Command Execution | readynas_surveillance | 9.8 | CRITICAL | 344363 |
| CVE-2016-6600 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2016-6602 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2016-6603 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2016-9682 | Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection | sonicwall secure remote access server | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2017-11165 | DataTaker DT80 dEX 1.50.012 - Information Disclosure | dt80_dex_firmware | 9.8 | critical | 390716 |
| CVE-2017-11444 | Subrion CMS <4.1.5.10 - SQL Injection | subrion_cms | 9.8 | CRITICAL | 341245 |
| CVE-2017-12611 | Apache Struts2 S2-053 - Remote Code Execution | struts | 9.8 | critical | 347009 |
| CVE-2017-12635 | Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation | couchdb | 9.8 | critical | 392301 |
| CVE-2017-14094 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 9.8 | CRITICAL | 330791 |
| CVE-2017-14097 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 9.8 | CRITICAL | 330791 |
| CVE-2017-14135 | OpenDreambox 2.0.0 - Remote Code Execution | opendreambox | 9.8 | critical | 344364 |
| CVE-2017-14942 | Intelbras WRN 150 - Authentication Bypass | wrn150 | 9.8 | critical | 390716 |
| CVE-2017-16935 | Ametys CMS 4.0.2 - Password Reset | ametys | 9.8 | CRITICAL | 390724 |
| CVE-2017-17731 | DedeCMS 5.7 - SQL Injection | dedecms | 9.8 | critical | 344370 |
| CVE-2017-17970 | Muviko 1.1 - SQL Injection | muviko | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2017-17976 | PerfexCRM 1.9.7 - Arbitrary File Upload | perfex crm | 9.8 | CRITICAL | 392301 |
| CVE-2017-17999 | RISE 1.9 - 'search' SQL Injection | rise ultimate project manager | 9.8 | CRITICAL | 380122, 390724 |
| CVE-2017-18001 | Trustwave SWG 11.8.0.27 - SSH Unauthorized Access | secure web gateway | 9.8 | CRITICAL | 330791 |
| CVE-2017-18580 | WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution | shortcodes-ultimate | 9.8 | CRITICAL | 377360 |
| CVE-2017-5689 | Intel Active Management Technology - System Privileges | proliant ml10 gen9 server firmware | 9.8 | CRITICAL | 390726, 392647 |
| CVE-2017-8917 | Joomla! <3.7.1 - SQL Injection | joomla! | 9.8 | critical | 340159 |
| CVE-2017-9791 | Apache Struts2 S2-053 - Remote Code Execution | struts | 9.8 | critical | 337207 |
| CVE-2017-9841 | PHPUnit - Remote Code Execution | phpunit | 9.8 | critical | 393782 |
| CVE-2018-0127 | Cisco RV132W/RV134W Router - Information Disclosure | rv132w_firmware | 9.8 | critical | 312863 |
| CVE-2018-1000861 | Jenkins - Remote Command Injection | jenkins | 9.8 | critical | 390722 |
| CVE-2018-10562 | Dasan GPON Devices - Remote Code Execution | gpon_router_firmware | 9.8 | critical | 392301 |
| CVE-2018-11511 | ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection | asustor-data-master | 9.8 | critical | 380122 |
| CVE-2018-11535 | Sitemakin SLAC 1.0 - 'my_item_search' SQL Injection | slac | 9.8 | CRITICAL | 340155 |
| CVE-2018-11686 | FlexPaper/FlowPaper 2.3.6 - Remote Code Execution | flowpaper | 9.8 | critical | 340029 |
| CVE-2018-12031 | Eaton Intelligent Power Manager 1.6 - Directory Traversal | intelligent_power_manager | 9.8 | critical | 340007, 347009 |
| CVE-2018-12596 | Ektron CMS 9.20 SP2 - Improper Access Restrictions | ektron cms | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2018-1273 | Spring Data Commons - Remote Code Execution | spring_data_commons | 9.8 | critical | 344360 |
| CVE-2018-13379 | Fortinet FortiOS - Credentials Disclosure | fortios | 9.8 | critical | 340007 |
| CVE-2018-14064 | VelotiSmart Wifi - Directory Traversal | velotismart_wifi_firmware | 9.8 | critical | 347009 |
| CVE-2018-14728 | Responsive filemanager 9.13.1 Server-Side Request Forgery | responsive_filemanager | 9.8 | critical | 392301 |
| CVE-2018-15534 | Geutebrueck re_porter 7.8.974.20 - Credential Disclosure | re porter 16 firmware | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2018-16159 | WordPress Gift Voucher <4.1.8 - Blind SQL Injection | gift_vouchers | 9.8 | critical | 380122 |
| CVE-2018-16167 | LogonTracer <=1.2.0 - Remote Command Injection | logontracer | 9.8 | critical | 340014 |
| CVE-2018-16283 | WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion | wechat_brodcast | 9.8 | critical | 347009 |
| CVE-2018-16763 | FUEL CMS 1.4.1 - Remote Code Execution | fuel_cms | 9.8 | critical | 347009 |
| CVE-2018-16836 | Rubedo CMS <=3.4.0 - Directory Traversal | rubedo | 9.8 | critical | 347009 |
| CVE-2018-17153 | Western Digital MyCloud NAS - Authentication Bypass | my_cloud_wdbctl0020hwt_firmware | 9.8 | critical | 344363 |
| CVE-2018-17173 | LG Supersign EZ CMS - Remote Code Execution | supersign_cms | 9.8 | critical | 340014 |
| CVE-2018-17246 | Kibana - Local File Inclusion | kibana | 9.8 | critical | 347009 |
| CVE-2018-17254 | Joomla! JCK Editor SQL Injection | jck_editor | 9.8 | critical | 340016 |
| CVE-2018-17431 | Comodo Unified Threat Management Web Console - Remote Code Execution | unified_threat_management_firewall | 9.8 | critical | 390722 |
| CVE-2018-18923 | Ticketly 1.0 - 'kind_id' SQL Injection | ticketly | 9.8 | CRITICAL | 380122 |
| CVE-2018-18925 | Gogs (Go Git Service) 0.11.66 - Remote Code Execution | gogs | 9.8 | critical | 344360 |
| CVE-2018-19276 | OpenMRS Platform < 2.24.0 - Insecure Object Deserialization | openmrs | 9.8 | CRITICAL | 344366 |
| CVE-2018-20985 | WordPress Payeezy Pay <=2.97 - Local File Inclusion | wp_payeezy_pay | 9.8 | critical | 392301 |
| CVE-2018-3810 | Oturia WordPress Smart Google Code Inserter <3.5 - Authentication Bypass | smart_google_code_inserter | 9.8 | critical | 380026 |
| CVE-2018-6605 | Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection | zh_baidumap | 9.8 | critical | 340016 |
| CVE-2018-7251 | Anchor CMS 0.12.3 - Error Log Exposure | anchor | 9.8 | critical | 390716 |
| CVE-2018-7282 | TITool PrintMonitor - Blind SQL Injection | printmonitor | 9.8 | critical | 344370 |
| CVE-2018-7314 | Joomla! Component PrayerCenter 3.0.2 - SQL Injection | prayercenter | 9.8 | critical | 340157 |
| CVE-2018-7538 | Tuleap 9.17.99.189 - Blind SQL Injection | tuleap | 9.8 | CRITICAL | 380122 |
| CVE-2018-7841 | Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection | u.motion builder | 9.8 | CRITICAL | 344364 |
| CVE-2018-9160 | SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response | sickrage | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2019-10068 | Kentico CMS Insecure Deserialization Remote Code Execution | kentico | 9.8 | critical | 341256 |
| CVE-2019-10232 | Teclib GLPI <= 9.3.3 - Unauthenticated SQL Injection | gestionnaire_libre_de_parc_informatique | 9.8 | critical | 340155 |
| CVE-2019-10647 | ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE) | zzzphp | 9.8 | critical | 340162 |
| CVE-2019-11581 | Atlassian Jira Server-Side Template Injection | jira | 9.8 | critical | 311299 |
| CVE-2019-12314 | Deltek Maconomy 2.2.5 - Local File Inclusion | maconomy | 9.8 | critical | 347009 |
| CVE-2019-12725 | Zeroshell 3.9.0 - Remote Command Execution | zeroshell | 9.8 | critical | 347009 |
| CVE-2019-12985 | Citrix SD-WAN Center - Remote Command Injection | netscaler_sd-wan | 9.8 | critical | 340014 |
| CVE-2019-12986 | Citrix SD-WAN Center - Remote Command Injection | netscaler_sd-wan | 9.8 | critical | 340014 |
| CVE-2019-12987 | Citrix SD-WAN Center - Remote Command Injection | netscaler_sd-wan | 9.8 | critical | 340014 |
| CVE-2019-12988 | Citrix SD-WAN Center - Remote Command Injection | netscaler_sd-wan | 9.8 | critical | 393655 |
| CVE-2019-12989 | Citrix SD-WAN and NetScaler SD-WAN - SQL Injection | netscaler_sd-wan | 9.8 | CRITICAL | 340016 |
| CVE-2019-13372 | D-Link Central WiFi Manager CWM(100) - Remote Code Execution | central_wifimanager | 9.8 | critical | 344370 |
| CVE-2019-15107 | Webmin <= 1.920 - Unauthenticated Remote Command Execution | webmin | 9.8 | critical | 344360 |
| CVE-2019-16072 | Enigma NMS < 65.0.0 - Authenticated OS Command Injection | enigma_network_management_solution | 9.8 | CRITICAL | 344364 |
| CVE-2019-16278 | nostromo 1.9.6 - Remote Code Execution | nostromo_nhttpd | 9.8 | critical | 392301 |
| CVE-2019-16662 | rConfig 3.9.2 - Remote Code Execution | rconfig | 9.8 | critical | 347009 |
| CVE-2019-16693 | phpIPAM 1.4 - SQL-Injection | phpipam | 9.8 | CRITICAL | 340016 |
| CVE-2019-16759 | vBulletin 5.0.0-5.5.4 - Remote Command Execution | vbulletin | 9.8 | CRITICAL | 341245 |
| CVE-2019-16920 | D-Link Routers - Remote Code Execution | dir-655_firmware | 9.8 | critical | 344360 |
| CVE-2019-17270 | Yachtcontrol Webapplication 1.0 - Remote Command Injection | yachtcontrol | 9.8 | critical | 347009 |
| CVE-2019-17564 | Apache Dubbo 2.5.x-2.7.4 - Insecure Deserialization | dubbo | 9.8 | critical | 390626 |
| CVE-2019-1935 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 9.8 | CRITICAL | 350147, 390724, 390727, 392301, 392648 |
| CVE-2019-1937 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 9.8 | CRITICAL | 350147, 390724, 390727, 392301, 392648 |
| CVE-2019-19740 | Octeth Oempro 4.8 - 'CampaignID' SQL Injection | oempro | 9.8 | CRITICAL | 392301 |
| CVE-2019-19781 | Citrix ADC and Gateway - Directory Traversal | application_delivery_controller_firmware | 9.8 | critical | 390716 |
| CVE-2019-20504 | Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Remote Code Execution | kace_systems_management | 9.8 | CRITICAL | 340014 |
| CVE-2019-25141 | Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update | easy_wp_smtp | 9.8 | CRITICAL | 390726 |
| CVE-2019-25213 | WordPress Advanced Access Manager - Path Traversal | - | 9.8 | critical | 344360 |
| CVE-2019-2729 | Oracle WebLogic Server Administration Console - Remote Code Execution | communications_diameter_signaling_router | 9.8 | critical | 393655 |
| CVE-2019-3396 | Atlassian Confluence Server - Path Traversal | confluence | 9.8 | critical | 392301 |
| CVE-2019-5434 | Revive Adserver 4.2 - Remote Code Execution | revive_adserver | 9.8 | critical | 344362 |
| CVE-2019-7139 | Magento - SQL Injection | magento | 9.8 | CRITICAL | 340016, 380026 |
| CVE-2019-9194 | elFinder <= 2.1.47 - Command Injection | elfinder | 9.8 | critical | 390700 |
| CVE-2019-9618 | WordPress GraceMedia Media Player 1.0 - Local File Inclusion | gracemedia_media_player | 9.8 | critical | 347009 |
| CVE-2019-9762 | PHPSHE 1.7 - SQL Injection | phpshe | 9.8 | critical | 340016 |
| CVE-2020-10148 | SolarWinds Orion API - Auth Bypass | orion_platform | 9.8 | critical | 390709 |
| CVE-2020-10189 | ManageEngine Desktop Central Java Deserialization | manageengine_desktop_central | 9.8 | critical | 347019 |
| CVE-2020-10220 | rConfig 3.9 - SQL Injection | rconfig | 9.8 | critical | 340016 |
| CVE-2020-10257 | ThemeREX Addons - Remote Code Execution | themerex | 9.8 | CRITICAL | 377360 |
| CVE-2020-10546 | rConfig 3.9.4 - SQL Injection | rconfig | 9.8 | critical | 380123 |
| CVE-2020-10547 | rConfig 3.9.4 - SQL Injection | rconfig | 9.8 | critical | 380123 |
| CVE-2020-10548 | rConfig 3.9.4 - SQL Injection | rconfig | 9.8 | critical | 380123 |
| CVE-2020-10549 | rConfig <=3.9.4 - SQL Injection | rconfig | 9.8 | critical | 380123 |
| CVE-2020-10987 | Tenda AC15 AC1900 version 15.03.05.19 - Command Injection | ac15_firmware | 9.8 | CRITICAL | 340014 |
| CVE-2020-11455 | LimeSurvey 4.1.11 - Local File Inclusion | limesurvey | 9.8 | critical | 347009 |
| CVE-2020-11530 | WordPress Chop Slider 3 - Blind SQL Injection | chop_slider | 9.8 | critical | 380122 |
| CVE-2020-11546 | SuperWebmailer 7.21.0.01526 - Remote Code Execution | superwebmailer | 9.8 | critical | 393655 |
| CVE-2020-11984 | Apache HTTP Server - Remote Code Execution | http_server | 9.8 | critical | 390626 |
| CVE-2020-12641 | Roundcube Webmail - Command Injection | webmail | 9.8 | critical | 340014 |
| CVE-2020-12720 | vBulletin SQL Injection | vbulletin | 9.8 | critical | 340155 |
| CVE-2020-13117 | Wavlink Multiple AP - Remote Command Injection | wn575a4 | 9.8 | critical | 340014 |
| CVE-2020-13167 | Netsweeper <=6.4.3 - Python Code Injection | netsweeper | 9.8 | critical | 340095 |
| CVE-2020-13640 | wpDiscuz <= 5.3.5 - SQL Injection | wpdiscuz | 9.8 | critical | 340155 |
| CVE-2020-13942 | Apache Unomi <1.5.2 - Remote Code Execution | unomi | 9.8 | CRITICAL | 340095 |
| CVE-2020-14750 | Oracle WebLogic Server - Remote Command Execution | fusion_middleware | 9.8 | critical | 340014 |
| CVE-2020-15415 | DrayTek Vigor - Command Injection | vigor | 9.8 | critical | 390700 |
| CVE-2020-15568 | TerraMaster TOS <.1.29 - Remote Code Execution | tos | 9.8 | critical | 347009 |
| CVE-2020-15920 | Mida eFramework <=2.9.0 - Remote Command Execution | eframework | 9.8 | critical | 347009 |
| CVE-2020-17456 | SEOWON INTECH SLC-130 & SLR-120S - Unauthenticated Remote Code Execution | slc-130 | 9.8 | critical | 340014 |
| CVE-2020-17463 | Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated) | fuel cms | 9.8 | CRITICAL | 380122, 390727, 392301, 392648 |
| CVE-2020-17496 | vBulletin 5.5.4 - 5.6.2- Remote Command Execution | vbulletin | 9.8 | critical | 344360 |
| CVE-2020-17506 | Artica Web Proxy 4.30 - Authentication Bypass/SQL Injection | web_proxy | 9.8 | critical | 340017 |
| CVE-2020-17530 | Apache Struts 2.0.0-2.5.25 - Remote Code Execution | struts | 9.8 | critical | 347009 |
| CVE-2020-18662 | Gnuboard5 5.3.2.8 - SQL Injection | gnuboard | 9.8 | CRITICAL | 380122 |
| CVE-2020-19625 | Gridx 1.3 - Remote Code Execution | gridx | 9.8 | CRITICAL | 341250 |
| CVE-2020-20300 | WeiPHP 5.0 - SQL Injection | weiphp | 9.8 | critical | 340159 |
| CVE-2020-21224 | Inspur ClusterEngine 4.0 - Remote Code Execution | clusterengine | 9.8 | critical | 344360 |
| CVE-2020-22208 | 74cms - ajax_street.php 'x' SQL Injection | 74cms | 9.8 | critical | 340016 |
| CVE-2020-22209 | 74cms - ajax_common.php SQL Injection | 74cms | 9.8 | critical | 341250, 390703 |
| CVE-2020-22210 | 74cms - ajax_officebuilding.php SQL Injection | 74cms | 9.8 | critical | 340145 |
| CVE-2020-22211 | 74cms - ajax_street.php 'key' SQL Injection | 74cms | 9.8 | critical | 340016 |
| CVE-2020-24193 | Daily Tracker System 1.0 - Authentication Bypass | daily tracker system | 9.8 | CRITICAL | 340145 |
| CVE-2020-24391 | Mongo-Express - Remote Code Execution | mongo-express | 9.8 | critical | 380026 |
| CVE-2020-25213 | WordPress File Manager Plugin - Remote Code Execution | file_manager | 9.8 | critical | 393781 |
| CVE-2020-25223 | Sophos UTM Preauth - Remote Code Execution | unified_threat_management | 9.8 | CRITICAL | 340014 |
| CVE-2020-25494 | SCO Openserver 5.0.7 - 'outputform' Command Injection | openserver | 9.8 | CRITICAL | 344364 |
| CVE-2020-25506 | D-Link DNS-320 - Unauthenticated Remote Code Execution | dns-320_firmware | 9.8 | critical | 392301 |
| CVE-2020-26919 | NETGEAR ProSAFE Plus - Unauthenticated Remote Code Execution | jgs516pe_firmware | 9.8 | critical | 392301 |
| CVE-2020-27481 | Good Layers LMS Plugin <= 2.1.4 - SQL Injection | good_learning_management_system | 9.8 | critical | 380122 |
| CVE-2020-27615 | WordPress Loginizer < 1.6.4 – Unauthenticated SQL Injection via log Parameter | loginizer | 9.8 | CRITICAL | 380122 |
| CVE-2020-28188 | TerraMaster TOS - Unauthenticated Remote Command Execution | tos | 9.8 | critical | 340014 |
| CVE-2020-28429 | geojson2kml - Command Injection | geojson2kml | 9.8 | CRITICAL | 344361 |
| CVE-2020-29047 | WP Hotel Booking < 1.10.4 - PHP Object Injection | wp_hotel_booking | 9.8 | CRITICAL | 330889 |
| CVE-2020-29214 | Alumni Management System 1.0 - SQL Injection | alumni_management_system | 9.8 | critical | 340156 |
| CVE-2020-29227 | Car Rental Management System 1.0 - Local File Inclusion | car_rental_management_system | 9.8 | critical | 347009 |
| CVE-2020-29279 | 74CMS - Remote File Inclusion | 74cms | 9.8 | critical | 340128 |
| CVE-2020-29390 | Zeroshell 3.9.3 - Command Injection | zeroshell | 9.8 | critical | 347009 |
| CVE-2020-35131 | Cockpit CMS 0.6.1 - Remote Code Execution | cockpit | 9.8 | CRITICAL | 340095 |
| CVE-2020-35476 | OpenTSDB <=2.4.0 - Remote Code Execution | opentsdb | 9.8 | critical | 340014 |
| CVE-2020-35545 | Spotweb 1.4.9 - 'search' SQL Injection | spotweb | 9.8 | CRITICAL | 380122 |
| CVE-2020-35713 | Belkin Linksys RE6500 <1.0.012.001 - Remote Command Execution | re6500_firmware | 9.8 | critical | 392301 |
| CVE-2020-35729 | Klog Server <=2.41 - Unauthenticated Command Injection | klog_server | 9.8 | critical | 392301 |
| CVE-2020-5307 | PHPGurukul Dairy Farm Shop Management System 1.0 - SQL Injection | dairy_farm_shop_management_system | 9.8 | critical | 340145 |
| CVE-2020-5722 | Grandstream UCM6200 - SQL Injection | - | 9.8 | critical | 340145 |
| CVE-2020-5902 | F5 BIG-IP TMUI - Remote Code Execution | big-ip_access_policy_manager | 9.8 | critical | 347009, 390709, 392301 |
| CVE-2020-7209 | LinuxKI Toolset <= 6.01 - Remote Command Execution | linuxki | 9.8 | critical | 347009 |
| CVE-2020-7980 | Satellian Intellian Aptus Web <= 1.24 - Remote Command Execution | aptus_web | 9.8 | CRITICAL | 344360 |
| CVE-2020-8515 | DrayTek - Remote Code Execution | vigor2960_firmware | 9.8 | CRITICAL | 392301 |
| CVE-2020-8656 | EyesOfNetwork - Hardcoded API Key & SQL Injection | eyesofnetwork | 9.8 | critical | 340016, 380122 |
| CVE-2020-8771 | WordPress Time Capsule < 1.21.16 - Authentication Bypass | wp_time_capsule | 9.8 | critical | 392301 |
| CVE-2020-9054 | Zyxel NAS Firmware 5.21- Remote Code Execution | nas326_firmware | 9.8 | critical | 347009 |
| CVE-2020-9480 | Apache Spark - Authentication Bypass | spark | 9.8 | CRITICAL | 340162 |
| CVE-2021-1472 | Cisco Small Business RV Series - OS Command Injection | rv160_firmware | 9.8 | critical | 340014 |
| CVE-2021-1498 | Cisco HyperFlex HX Data Platform - Remote Command Execution | hyperflex_hx_data_platform | 9.8 | critical | 340014 |
| CVE-2021-20038 | SonicWall SMA100 Stack - Buffer Overflow/Remote Code Execution | sma_200_firmware | 9.8 | critical | 340193 |
| CVE-2021-20158 | Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Change | tew-827dru_firmware | 9.8 | critical | 392301 |
| CVE-2021-20617 | Acmailer - Improper Access Control to OS Command Injection | acmailer,acmailer_db | 9.8 | critical | 340014 |
| CVE-2021-21307 | Lucee Admin - Remote Code Execution | lucee_server | 9.8 | critical | 340149 |
| CVE-2021-22005 | VMware vCenter Server - Arbitrary File Upload | cloud_foundation | 9.8 | CRITICAL | 330791 |
| CVE-2021-22175 | GitLab CI Lint API - Server-Side Request Forgery | gitlab | 9.8 | CRITICAL | 344362 |
| CVE-2021-22502 | Micro Focus Operations Bridge Reporter - Remote Code Execution | operation_bridge_reporter | 9.8 | CRITICAL | 344364 |
| CVE-2021-24212 | WooCommerce Help Scout - Arbitrary File Upload | help_scout | 9.8 | critical | 382238 |
| CVE-2021-24215 | Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation | controlled_admin_access | 9.8 | CRITICAL | 377360 |
| CVE-2021-24284 | WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File Upload | kaswara | 9.8 | critical | 382238 |
| CVE-2021-24285 | WordPress Car Seller - Auto Classifieds Script - SQL Injection | cars-seller-auto-classifieds-script | 9.8 | critical | 340016 |
| CVE-2021-24442 | Wordpress Polls Widget < 1.5.3 - SQL Injection | poll,_survey,_questionnaire_and_voting_system | 9.8 | critical | 380122 |
| CVE-2021-24472 | Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery | kentharadio | 9.8 | critical | 340162 |
| CVE-2021-24499 | WordPress Workreap - Remote Code Execution | workreap | 9.8 | critical | 382238 |
| CVE-2021-24527 | Profile Builder < 3.4.9 - Improper Authentication | profile-builder | 9.8 | critical | 340130 |
| CVE-2021-24666 | WordPress Podlove Podcast Publisher <3.5.6 - SQL Injection | podlove_podcast_publisher | 9.8 | critical | 340016 |
| CVE-2021-24731 | Pie Register < 3.7.1.6 - SQL Injection | pie_register | 9.8 | critical | 380122 |
| CVE-2021-24762 | WordPress Perfect Survey <1.5.2 - SQL Injection | perfect_survey | 9.8 | critical | 380122 |
| CVE-2021-24827 | WordPress Asgaros Forum <1.15.13 - SQL Injection | asgaros_forum | 9.8 | critical | 380122 |
| CVE-2021-24849 | WCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL Injection | frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible | 9.8 | CRITICAL | 380122 |
| CVE-2021-24915 | Contest Gallery < 13.1.0.6 - SQL injection | contest_gallery | 9.8 | critical | 340017 |
| CVE-2021-24931 | WordPress Secure Copy Content Protection and Content Locking <2.8.2 - SQL Injection | secure_copy_content_protection_and_content_locking | 9.8 | critical | 380122 |
| CVE-2021-24943 | Registrations for the Events Calendar < 2.7.6 - SQL Injection | registrations_for_the_events_calendar | 9.8 | critical | 380122 |
| CVE-2021-24946 | WordPress Modern Events Calendar <6.1.5 - Blind SQL Injection | modern_events_calendar_lite | 9.8 | critical | 380122 |
| CVE-2021-25003 | WordPress WPCargo Track & Trace <6.9.0 - Remote Code Execution | wpcargo_track_&_trace | 9.8 | critical | 331324 |
| CVE-2021-25114 | WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injection | paid_memberships_pro | 9.8 | critical | 380122 |
| CVE-2021-25281 | SaltStack Salt <3002.5 - Auth Bypass | salt | 9.8 | CRITICAL | 340007 |
| CVE-2021-27132 | Sercomm VD625 Smart Modems - CRLF Injection | agcombo_vd625_firmware | 9.8 | critical | 330708 |
| CVE-2021-27314 | Doctor Appointment System 1.0 - SQL Injection | doctor_appointment_system | 9.8 | critical | 380122 |
| CVE-2021-28799 | QNAP HBS 3 - Broken Access Control | hybrid_backup_sync | 9.8 | CRITICAL | 344360 |
| CVE-2021-30118 | Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Execution | vsa | 9.8 | critical | 392301 |
| CVE-2021-3018 | IPeakCMS 3.5 - SQL Injection | ipeakcms | 9.8 | CRITICAL | 380122 |
| CVE-2021-3110 | PrestaShop 1.7.7.0 - SQL Injection | prestashop | 9.8 | critical | 380122 |
| CVE-2021-3129 | Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution | ignition | 9.8 | CRITICAL | 340007, 340162, 344365 |
| CVE-2021-31316 | CentOS Web Panel - SQL Injection | webpanel | 9.8 | CRITICAL | 340016 |
| CVE-2021-31324 | CentOS Web Panel - OS Command Injection | webpanel | 9.8 | CRITICAL | 340016 |
| CVE-2021-31755 | Tenda Router AC11 - Remote Command Injection | ac11_firmware | 9.8 | critical | 340014 |
| CVE-2021-31805 | Apache Struts2 S2-062 - Remote Code Execution | struts | 9.8 | critical | 330791 |
| CVE-2021-31856 | Layer5 Meshery 0.5.2 - SQL Injection | meshery | 9.8 | critical | 341245, 344366 |
| CVE-2021-32305 | Websvn <2.6.1 - Remote Code Execution | websvn | 9.8 | critical | 340014 |
| CVE-2021-3239 | E-Learning System 1.0 - SQL Injection | e-learning system | 9.8 | CRITICAL | 340016 |
| CVE-2021-3278 | Local Service Search Engine Management System 1.0 - SQLi Authentication Bypass | local services search engine management system | 9.8 | CRITICAL | 340156 |
| CVE-2021-33357 | RaspAP <=2.6.5 - Remote Command Injection | raspap | 9.8 | critical | 344363 |
| CVE-2021-34187 | Chamilo model.ajax.php - SQL Injection | chamilo | 9.8 | critical | 340016 |
| CVE-2021-34621 | WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weakness | profilepress | 9.8 | CRITICAL | 377360 |
| CVE-2021-34624 | WordPress ProfilePress 3.0-3.1.3 - Arbitrary File Upload | profilepress | 9.8 | critical | 382238 |
| CVE-2021-35395 | RealTek Jungle SDK - Arbitrary Command Injection | realtek_jungle_sdk | 9.8 | critical | 340014 |
| CVE-2021-36260 | Hikvision IP camera/NVR - Remote Command Execution | ds-2cd2026g2-iu/sl_firmware | 9.8 | critical | 393655 |
| CVE-2021-36380 | Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection | sureline | 9.8 | critical | 392301 |
| CVE-2021-37291 | KevinLAB BEMS 1.0 - SQL Injection | 4st_l-bems | 9.8 | critical | 340156 |
| CVE-2021-37538 | PrestaShop SmartBlog <4.0.6 - SQL Injection | smartblog | 9.8 | critical | 340016 |
| CVE-2021-40617 | openSIS Community Edition 8.0 - SQL Injection | opensis | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2021-40870 | Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Execution | controller | 9.8 | critical | 340007 |
| CVE-2021-40960 | Galera WebTemplate 1.0 Directory Traversal | galera_webtemplate | 9.8 | critical | 347009 |
| CVE-2021-41649 | PuneethReddyHC Online Shopping System homeaction.php SQL Injection | online-shopping-system-advanced | 9.8 | critical | 392301 |
| CVE-2021-41749 | CraftCMS SEOmatic - Server-Side Template Injection | seomatic | 9.8 | critical | 390719 |
| CVE-2021-42013 | Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution | http_server | 9.8 | critical | 347009 |
| CVE-2021-42237 | Sitecore Experience Platform Pre-Auth RCE | experience_platform | 9.8 | critical | 344362 |
| CVE-2021-42325 | Froxlor 0.10.29.1 - SQL Injection (Authenticated) | froxlor | 9.8 | CRITICAL | 350147, 390724 |
| CVE-2021-42667 | Online Event Booking and Reservation System 2.3.0 - SQL Injection | online_event_booking_and_reservation_system | 9.8 | critical | 340016 |
| CVE-2021-43140 | Simple Subscription Website 1.0 - SQLi Authentication Bypass | simple subscription website | 9.8 | CRITICAL | 340145 |
| CVE-2021-43421 | Studio-42 elFinder <2.1.60 - Arbitrary File Upload | elfinder | 9.8 | critical | 393781 |
| CVE-2021-43510 | Sourcecodester Simple Client Management System 1.0 - SQL Injection | simple_client_management_system | 9.8 | critical | 340145 |
| CVE-2021-4449 | ZoomSounds Plugin - Unauthenticated Arbitrary File Upload | zoomsounds | 9.8 | CRITICAL | 392301 |
| CVE-2021-44567 | RosarioSIS 7.6 - SQL Injection | rosariosis | 9.8 | CRITICAL | 392301 |
| CVE-2021-45382 | D-Link - Remote Command Execution | dir-820l_firmware | 9.8 | critical | 392301 |
| CVE-2021-45428 | Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Upload | tlr-2005ksh | 9.8 | CRITICAL | 392301 |
| CVE-2021-45467 | Control Web Panel (CWP) - File Inclusion | webpanel | 9.8 | CRITICAL | 390614 |
| CVE-2022-0169 | Photo Gallery by 10Web < 1.6.0 - SQL Injection | photo_gallery | 9.8 | critical | 340016 |
| CVE-2022-0332 | Moodle 3.11.4 - SQL Injection | moodle | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2022-0349 | WordPress NotificationX <2.3.9 - SQL Injection | notificationx | 9.8 | critical | 380122 |
| CVE-2022-0412 | WordPress TI WooCommerce Wishlist <1.40.1 - SQL Injection | ti_woocommerce_wishlist | 9.8 | critical | 380122 |
| CVE-2022-0434 | WordPress Page Views Count <2.4.15 - SQL Injection | page_view_count | 9.8 | critical | 340016 |
| CVE-2022-0479 | Popup Builder Plugin - SQL Injection and Cross-Site Scripting | popup_builder | 9.8 | CRITICAL | 340016, 377360 |
| CVE-2022-0592 | MapSVG < 6.2.20 - Unauthenticated SQLi | mapsvg | 9.8 | critical | 380122 |
| CVE-2022-0658 | CommonsBooking < 2.6.8 - SQL Injection | commonsbooking | 9.8 | critical | 380122 |
| CVE-2022-0679 | WordPress Narnoo Distributor <=2.5.1 - Local File Inclusion | narnoo_distributor | 9.8 | critical | 344360 |
| CVE-2022-0693 | WordPress Master Elements <=8.0 - SQL Injection | master_elements | 9.8 | critical | 380122 |
| CVE-2022-0747 | Infographic Maker iList < 4.3.8 - SQL Injection | infographic_maker | 9.8 | critical | 380122 |
| CVE-2022-0760 | WordPress Simple Link Directory <7.7.2 - SQL injection | simple_link_directory | 9.8 | critical | 380122 |
| CVE-2022-0769 | Users Ultra <= 3.1.0 - SQL Injection | users_ultra | 9.8 | critical | 380122 |
| CVE-2022-0773 | Documentor <= 1.5.3 - Unauthenticated SQL Injection | documentor | 9.8 | critical | 380122 |
| CVE-2022-0781 | WordPress Nirweb Support <2.8.2 - SQL Injection | nirweb_support | 9.8 | critical | 340016 |
| CVE-2022-0784 | WordPress Title Experiments Free <9.0.1 - SQL Injection | title_experiments_free | 9.8 | critical | 380122 |
| CVE-2022-0785 | WordPress Daily Prayer Time <2022.03.01 - SQL Injection | daily_prayer_time | 9.8 | critical | 380122 |
| CVE-2022-0786 | WordPress KiviCare <2.3.9 - SQL Injection | kivicare | 9.8 | critical | 380122 |
| CVE-2022-0787 | Limit Login Attempts (Spam Protection) < 5.1 - SQL Injection | limit_login_attempts | 9.8 | critical | 380122 |
| CVE-2022-0788 | WordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL Injection | wp_fundraising_donation_and_crowdfunding_platform | 9.8 | CRITICAL | 390727 |
| CVE-2022-0814 | Ubigeo de Peru < 3.6.4 - SQL Injection | ubigeo_de_peru_para_woocommerce | 9.8 | critical | 340016 |
| CVE-2022-0817 | WordPress BadgeOS <=3.7.0 - SQL Injection | badgeos | 9.8 | critical | 340016 |
| CVE-2022-0826 | WordPress WP Video Gallery <=1.7.1 - SQL Injection | wp-video-gallery-free | 9.8 | critical | 380122 |
| CVE-2022-0827 | WordPress Best Books <=2.6.3 - SQL Injection | bestbooks | 9.8 | critical | 380122 |
| CVE-2022-0846 | SpeakOut Email Petitions < 2.14.15.1 - SQL Injection | speakout!_email_petitions | 9.8 | critical | 380122 |
| CVE-2022-0867 | WordPress ARPrice <3.6.1 - SQL Injection | pricing_table | 9.8 | critical | 380122 |
| CVE-2022-0948 | WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection | order_listener_for_woocommerce | 9.8 | CRITICAL | 380122 |
| CVE-2022-0949 | WordPress Stop Bad Bots <6.930 - SQL Injection | block_and_stop_bad_bots | 9.8 | critical | 380122 |
| CVE-2022-1013 | WordPress Personal Dictionary <1.3.4 - Blind SQL Injection | personal_dictionary | 9.8 | critical | 380122 |
| CVE-2022-1057 | WordPress Pricing Deals for WooCommerce <=2.0.2.02 - SQL Injection | pricing_deals_for_woocommerce | 9.8 | critical | 380122 |
| CVE-2022-1388 | F5 BIG-IP iControl - REST Auth Bypass RCE | big-ip_access_policy_manager | 9.8 | critical | 392767 |
| CVE-2022-1390 | WordPress Admin Word Count Column 2.2 - Local File Inclusion | admin_word_count_column | 9.8 | critical | 347009 |
| CVE-2022-1391 | WordPress Cab fare calculator < 1.0.4 - Local File Inclusion | cab_fare_calculator | 9.8 | critical | 347009 |
| CVE-2022-1453 | RSVPMaker <= 9.2.5 - SQL Injection | - | 9.8 | critical | 380122 |
| CVE-2022-1574 | WordPress HTML2WP <=1.0.0 - Arbitrary File Upload | html2wp | 9.8 | critical | 382238 |
| CVE-2022-1609 | The School Management < 9.9.7 - Remote Code Execution | school_management | 9.8 | critical | 340095 |
| CVE-2022-1950 | Youzify < 1.2.0 - Unauthenticated SQLi | youzify | 9.8 | critical | 380122 |
| CVE-2022-22897 | PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injection | ap_pagebuilder | 9.8 | critical | 340156, 341145, 380122 |
| CVE-2022-22954 | VMware Workspace ONE Access - Server-Side Template Injection | identity_manager | 9.8 | critical | 344360 |
| CVE-2022-23898 | MCMS 5.2.5 - SQL Injection | mcms | 9.8 | critical | 340159 |
| CVE-2022-24112 | Apache APISIX - Remote Code Execution | apisix | 9.8 | CRITICAL | 344364 |
| CVE-2022-24223 | Atom CMS v2.0 - SQL Injection | atomcms | 9.8 | CRITICAL | 380122 |
| CVE-2022-24260 | VoipMonitor - Pre-Auth SQL Injection | voipmonitor | 9.8 | critical | 340016 |
| CVE-2022-24627 | AudioCodes Device Manager Express - SQL Injection | device_manager_express | 9.8 | CRITICAL | 340145 |
| CVE-2022-2467 | Garage Management System 1.0 - SQL Injection | garage_management_system | 9.8 | critical | 380122 |
| CVE-2022-24816 | GeoServer <1.2.2 - Remote Code Execution | jai-ext | 9.8 | critical | 344360 |
| CVE-2022-2486 | Wavlink WN535K2/WN535K3 - OS Command Injection | wl-wn535k2 | 9.8 | critical | 340014 |
| CVE-2022-2488 | Wavlink WN535K2/WN535K3 - OS Command Injection | wl-wn535k2_firmware | 9.8 | critical | 340014 |
| CVE-2022-25082 | TOTOLink - Unauthenticated Command Injection | a950rg_firmware | 9.8 | critical | 344361 |
| CVE-2022-25125 | MCMS 5.2.4 - SQL Injection | mcms | 9.8 | critical | 340159 |
| CVE-2022-25488 | Atom CMS v2.0 - SQL Injection | atomcms | 9.8 | critical | 340016 |
| CVE-2022-26134 | Confluence - Remote Code Execution | confluence_data_center | 9.8 | critical | 337211, 340087 |
| CVE-2022-26585 | Mingsoft MCMS v5.2.7 - SQL Injection | mcms | 9.8 | critical | 340156 |
| CVE-2022-27927 | Microfinance Management System 1.0 - 'customer_number' SQLi | microfinance management system | 9.8 | CRITICAL | 340016 |
| CVE-2022-27984 | Cuppa CMS v1.0 - SQL injection | cuppacms | 9.8 | critical | 380122 |
| CVE-2022-27985 | Cuppa CMS v1.0 - SQL injection | cuppacms | 9.8 | critical | 340017 |
| CVE-2022-28032 | Atom CMS v2.0 - SQL Injection | atomcms | 9.8 | critical | 380122 |
| CVE-2022-28033 | Atom.CMS 2.0 - SQL Injection | atomcms | 9.8 | CRITICAL | 380122 |
| CVE-2022-28219 | Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Execution | manageengine_adaudit_plus | 9.8 | CRITICAL | 344370 |
| CVE-2022-2840 | Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi | zephyr project manager | 9.8 | CRITICAL | 380122 |
| CVE-2022-29006 | Directory Management System 1.0 - SQL Injection | directory_management_system | 9.8 | critical | 340145 |
| CVE-2022-29007 | Dairy Farm Shop Management System 1.0 - SQL Injection | dairy_farm_shop_management_system | 9.8 | critical | 340145 |
| CVE-2022-29013 | Razer Sila Gaming Router - Remote Code Execution | sila | 9.8 | critical | 392301 |
| CVE-2022-29078 | Node.js Embedded JavaScript 3.1.6 - Template Injection | ejs | 9.8 | critical | 340014 |
| CVE-2022-29303 | SolarView Compact 6.00 - OS Command Injection | sv-cpt-mc310_firmware | 9.8 | CRITICAL | 344360 |
| CVE-2022-29383 | NETGEAR ProSafe SSL VPN firmware - SQL Injection | ssl312_firmware | 9.8 | critical | 340156 |
| CVE-2022-30525 | Zyxel Firewall - OS Command Injection | usg_flex_100w_firmware | 9.8 | CRITICAL | 344363 |
| CVE-2022-31137 | Roxy-WI < 6.1.1.0 - Remote Code Execution | roxy-wi | 9.8 | critical | 344360 |
| CVE-2022-31499 | Nortek Linear eMerge E3-Series <0.32-08f - Remote Command Injection | emerge_e3_firmware | 9.8 | critical | 344364 |
| CVE-2022-31976 | Online Fire Reporting System v1.0 - SQL injection | online_fire_reporting_system | 9.8 | critical | 380122 |
| CVE-2022-31977 | Online Fire Reporting System v1.0 - SQL injection | online_fire_reporting_system | 9.8 | critical | 380122 |
| CVE-2022-31978 | Online Fire Reporting System v1.0 - SQL injection | online_fire_reporting_system | 9.8 | critical | 380122 |
| CVE-2022-32094 | Hospital Management System 1.0 - SQL Injection | hospital_management_system | 9.8 | critical | 340145 |
| CVE-2022-3236 | Sophos Firewall <= 19.0 MR1 - Remote Code Execution | firewall | 9.8 | critical | 344361 |
| CVE-2022-32409 | Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion | i3geo | 9.8 | critical | 347009 |
| CVE-2022-33965 | WordPress Visitor Statistics <=5.7 - SQL Injection | wp_visitor_statistics | 9.8 | critical | 380122 |
| CVE-2022-34045 | WAVLINK WN530HG4 - Improper Access Control | wl-wn530hg4_firmware | 9.8 | critical | 390716 |
| CVE-2022-34128 | GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE) | positions | 9.8 | CRITICAL | 392301 |
| CVE-2022-3481 | NotificationX Dropshipping < 4.4 - SQL Injection | woocommerce dropshipping | 9.8 | CRITICAL | 380122 |
| CVE-2022-35405 | Zoho ManageEngine - Remote Code Execution | manageengine_access_manager_plus | 9.8 | critical | 392301 |
| CVE-2022-35914 | GLPI <=10.0.2 - Remote Command Execution | glpi | 9.8 | critical | 344360 |
| CVE-2022-36446 | Webmin <1.997 - Authenticated Remote Code Execution | webmin | 9.8 | critical | 392301 |
| CVE-2022-36553 | Hytec Inter HWL-2511-SS - Remote Command Execution | hwl-2511-ss_firmware | 9.8 | critical | 347009 |
| CVE-2022-36642 | Omnia MPX 1.5.0+r1 - Local File Inclusion | omnia_mpx_node_firmware | 9.8 | critical | 340007, 347009 |
| CVE-2022-37042 | Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution | collaboration | 9.8 | critical | 390626 |
| CVE-2022-38580 | X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF) | skipper | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2022-38627 | Nortek Linear eMerge E3-Series - SQL Injection | emerge_e3_firmware | 9.8 | critical | 340016 |
| CVE-2022-38637 | Hospital Management System 1.0 - SQL Injection | hospital_management_system | 9.8 | critical | 340145 |
| CVE-2022-40032 | Simple Task Managing System v1.0 - SQL Injection (Unauthenticated) | simple task managing system | 9.8 | CRITICAL | 340016, 380122 |
| CVE-2022-40347 | Intern Record System v1.0 - SQL Injection (Unauthenticated) | intern record system | 9.8 | CRITICAL | 340016 |
| CVE-2022-4050 | WordPress JoomSport <5.2.8 - SQL Injection | joomsport | 9.8 | critical | 380122 |
| CVE-2022-4059 | Cryptocurrency Widgets Pack < 2.0 - SQL Injection | cryptocurrency_widgets_pack | 9.8 | critical | 380122 |
| CVE-2022-4060 | WordPress User Post Gallery <=2.19 - Remote Code Execution | user_post_gallery | 9.8 | critical | 347009 |
| CVE-2022-40881 | SolarView 6.00 - Remote Command Execution | solarview_compact | 9.8 | critical | 344360 |
| CVE-2022-4117 | WordPress IWS Geo Form Fields <=1.0 - SQL Injection | iws-geo-form-fields | 9.8 | critical | 380122 |
| CVE-2022-41840 | Welcart eCommerce <=2.7.7 - Local File Inclusion | welcart_e-commerce | 9.8 | critical | 347009 |
| CVE-2022-4328 | WooCommerce Checkout Field Manager < 18.0 - Arbitrary File Upload | woocommerce_checkout_field_manager | 9.8 | critical | 382238 |
| CVE-2022-44290 | WebTareas 2.4p5 - SQL Injection | webtareas | 9.8 | critical | 380122 |
| CVE-2022-44291 | WebTareas 2.4p5 - SQL Injection | webtareas | 9.8 | critical | 380122 |
| CVE-2022-4447 | WordPress Fontsy <=1.8.6 - SQL Injection | fontsy | 9.8 | critical | 340016 |
| CVE-2022-44588 | Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injection | - | 9.8 | critical | 380122 |
| CVE-2022-44877 | Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE) | webpanel | 9.8 | CRITICAL | 393655 |
| CVE-2022-45699 | APsystems ECU-R Firmware - Command Injection | ecu-r_firmware | 9.8 | CRITICAL | 344364 |
| CVE-2022-45805 | WordPress Paytm Payment Gateway <=2.7.3 - SQL Injection | payment_gateway | 9.8 | critical | 380122 |
| CVE-2022-46071 | Helmet Store Showroom v1.0 - SQL Injection | helmet_store_showroom_site | 9.8 | critical | 340145 |
| CVE-2022-47615 | LearnPress Plugin < 4.2.0 - Local File Inclusion | learnpress | 9.8 | critical | 347009 |
| CVE-2022-47945 | Thinkphp Lang - Local File Inclusion | thinkphp | 9.8 | critical | 340007 |
| CVE-2022-47986 | IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution | linux_kernel | 9.8 | CRITICAL | 344364 |
| CVE-2022-48323 | Sunflower Simple and Personal 1.0.1.43315 - Remote Code Execution | sunflower | 9.8 | critical | 392301 |
| CVE-2023-0037 | WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injection | map_builder_for_google_maps | 9.8 | critical | 380122 |
| CVE-2023-0297 | PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE) | pyload | 9.8 | critical | 340095 |
| CVE-2023-0562 | Bank Locker Management System v1.0 - SQL Injection | bank_locker_management_system | 9.8 | critical | 340156 |
| CVE-2023-0600 | WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL Injection | wp_visitor_statistics | 9.8 | CRITICAL | 380122 |
| CVE-2023-0938 | Music Gallery Site v1.0 - SQL Injection on music_list.php | music gallery site | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2023-1020 | Steveas WP Live Chat Shoutbox <= 1.4.2 - SQL Injection | wp_live_chat_shoutbox | 9.8 | critical | 340016 |
| CVE-2023-1389 | TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection | archer-ax21 | 9.8 | critical | 393655 |
| CVE-2023-1454 | Jeecg-boot 3.5.0 qurestSql - SQL Injection | jeecg-boot | 9.8 | CRITICAL | 340159 |
| CVE-2023-1719 | Bitrix Component - Cross-Site Scripting | bitrix24 | 9.8 | critical | 347198 |
| CVE-2023-1730 | SupportCandy < 3.1.5 - Unauthenticated SQL Injection | supportcandy | 9.8 | critical | 380122 |
| CVE-2023-2130 | Purchase Order Management v1.0 - SQL Injection | purchase_order_management_system | 9.8 | critical | 380122 |
| CVE-2023-22463 | KubePi JwtSigKey - Admin Authentication Bypass | kubepi | 9.8 | critical | 392301 |
| CVE-2023-22527 | Atlassian Confluence - Remote Code Execution | confluence_data_center | 9.8 | critical | 340095 |
| CVE-2023-23333 | SolarView Compact 6.00 - OS Command Injection | solarview_compact_firmware | 9.8 | critical | 390614 |
| CVE-2023-23488 | WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection | paid_memberships_pro | 9.8 | critical | 380122 |
| CVE-2023-23489 | WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injection | easy_digital_downloads | 9.8 | critical | 380122 |
| CVE-2023-24000 | WordPress GamiPress <= 2.5.7 - SQL Injection | GamiPress gamipress | 9.8 | critical | 380122 |
| CVE-2023-2479 | Appium Desktop Server - Remote Code Execution | appium-desktop | 9.8 | critical | 342259 |
| CVE-2023-25135 | vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution | vbulletin | 9.8 | critical | 390614 |
| CVE-2023-25280 | D-Link DIR820LA1_FW105B03 'ping_addr' - OS Command Injection | dir820la1_firmware | 9.8 | CRITICAL | 340014 |
| CVE-2023-25717 | Ruckus Wireless Admin - Remote Code Execution | ruckus_wireless_admin | 9.8 | critical | 393655 |
| CVE-2023-26802 | DCBI-Netlog-LAB v1.0 - Command Injection | dcbi-netlog-lab_firmware | 9.8 | critical | 344361 |
| CVE-2023-27034 | Jms Blog - SQL Injection | jms_blog | 9.8 | CRITICAL | 380122 |
| CVE-2023-27350 | PaperCut - Unauthenticated Remote Code Execution | papercut_mf | 9.8 | CRITICAL | 390727 |
| CVE-2023-27637 | PrestaShop tshirtecommerce Module - SQL Injection | custom_product_designer | 9.8 | critical | 380122 |
| CVE-2023-27638 | tshirtecommerce PrestaShop Module - SQL Injection | prestashop | 9.8 | CRITICAL | 380122 |
| CVE-2023-27847 | PrestaShop xipblog - SQL Injection | xipblog | 9.8 | CRITICAL | 340016, 340156, 341145, 380122 |
| CVE-2023-28343 | Altenergy Power Control Software C1.2.5 - Remote Command Injection | energy_communication_unit_firmware | 9.8 | critical | 344364 |
| CVE-2023-29300 | Adobe ColdFusion - Pre-Auth Remote Code Execution | coldfusion | 9.8 | critical | 350147 |
| CVE-2023-29827 | Embedded JavaScript(EJS) 3.1.6 - Template Injection | ejs | 9.8 | critical | 340014 |
| CVE-2023-30013 | TOTOLink - Unauthenticated Command Injection | x5000r_firmware | 9.8 | critical | 392301 |
| CVE-2023-30150 | PrestaShop leocustomajax 1.0 & 1.0.0 - SQL Injection | leocustomajax | 9.8 | CRITICAL | 380122 |
| CVE-2023-30192 | PrestaShop 'possearchproducts' <= 1.7 - SQL Injection | possearchproducts | 9.8 | CRITICAL | 380122 |
| CVE-2023-30194 | Prestashop posstaticfooter <= 1.0.0 - SQL Injection | poststaticfooter | 9.8 | CRITICAL | 341245 |
| CVE-2023-30258 | MagnusBilling - Remote Code Execution | magnusbilling | 9.8 | critical | 344363, 344364 |
| CVE-2023-3077 | MStore API < 3.9.8 - SQL Injection | mstore_api | 9.8 | CRITICAL | 380122 |
| CVE-2023-30869 | Easy Digital Downloads - Privilege Escalation | easy_digital_downloads | 9.8 | CRITICAL | 377360 |
| CVE-2023-31465 | TimeKeeper by FSMLabs - Remote Code Execution | timekeeper | 9.8 | critical | 393655 |
| CVE-2023-3197 | WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection | mstore api | 9.8 | CRITICAL | 380122 |
| CVE-2023-32563 | Ivanti Avalanche - Remote Code Execution | avalanche | 9.8 | critical | 340007 |
| CVE-2023-33338 | Old Age Home Management System v1.0 - SQL Injection | old_age_home_management_system | 9.8 | critical | 340145 |
| CVE-2023-33362 | Piwigo 13.6.0 - SQL Injection | piwigo | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2023-3368 | Chamilo LMS <= v1.11.20 Unauthenticated Command Injection | chamilo | 9.8 | critical | 393655 |
| CVE-2023-3380 | WAVLINK WN579X3 - Remote Command Execution | wn579x3_firmware | 9.8 | CRITICAL | 340014 |
| CVE-2023-33831 | FUXA - Unauthenticated Remote Code Execution | fuxa | 9.8 | CRITICAL | 345240 |
| CVE-2023-34048 | VMware vCenter Server - Out-of-Bounds Write | vcenter_server | 9.8 | critical | 392301 |
| CVE-2023-34124 | SonicWall GMS and Analytics Web Services - Shell Injection | analytics | 9.8 | critical | 380123 |
| CVE-2023-34362 | MOVEit Transfer - Remote Code Execution | moveit_cloud | 9.8 | critical | 340016 |
| CVE-2023-3452 | WordPress Canto Plugin <= 3.0.4 - File Inclusion | canto | 9.8 | CRITICAL | 340077 |
| CVE-2023-34659 | JeecgBoot 3.5.0 - SQL Injection | jeecg_boot | 9.8 | CRITICAL | 330791 |
| CVE-2023-34751 | bloofoxCMS v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 | critical | 380122 |
| CVE-2023-34752 | bloofoxCMS v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 | critical | 380122 |
| CVE-2023-34753 | bloofoxCMS v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 | critical | 380122 |
| CVE-2023-34754 | Bloofox v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 | critical | 380122 |
| CVE-2023-34755 | bloofoxCMS v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 | critical | 380122 |
| CVE-2023-34756 | Bloofox v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 | critical | 380122 |
| CVE-2023-34960 | Chamilo Command Injection | chamilo | 9.8 | critical | 344360 |
| CVE-2023-34990 | FortiWLM - Directory Traversal | fortiwlm | 9.8 | CRITICAL | 340007 |
| CVE-2023-34993 | Fortinet FortiWLM Unauthenticated Command Injection Vulnerability | fortiwlm | 9.8 | critical | 344363 |
| CVE-2023-3643 | CAREL Boss Mini <= 1.4.0 - Local File Inclusion | boss-mini | 9.8 | critical | 344360 |
| CVE-2023-36845 | Juniper J-Web - Remote Code Execution | junos | 9.8 | critical | 344360 |
| CVE-2023-3710 | Honeywell PM43 Printers - Command Injection | pm43_firmware | 9.8 | critical | 344361 |
| CVE-2023-37629 | Online Piggery Management System v1.0 - Unauthenticated File Upload | simple_online_piggery_management_system | 9.8 | critical | 330791 |
| CVE-2023-37679 | NextGen Mirth Connect - Remote Code Execution | mirth_connect | 9.8 | critical | 344363 |
| CVE-2023-38203 | Adobe ColdFusion - Deserialization of Untrusted Data | coldfusion | 9.8 | critical | 350147 |
| CVE-2023-39143 | PaperCut < 22.1.3 - Path Traversal | papercut_mf | 9.8 | critical | 347019 |
| CVE-2023-39361 | Cacti 1.2.24 - SQL Injection | cacti | 9.8 | critical | 380122 |
| CVE-2023-39650 | PrestaShop Theme Volty CMS Blog - SQL Injection | theme volty cms blog | 9.8 | CRITICAL | 340156, 341145, 380122 |
| CVE-2023-39796 | WBCE 1.6.0 - SQL Injection | wbce_cms | 9.8 | CRITICAL | 380122 |
| CVE-2023-40504 | LG Simple Editor <= v3.21.0 - Command Injection | simple_editor | 9.8 | CRITICAL | 340007 |
| CVE-2023-40748 | PHPJabbers Food Delivery Script - SQL Injection | food_delivery_script | 9.8 | critical | 340156 |
| CVE-2023-40749 | PHPJabbers Food Delivery Script v3.0 - SQL Injection | food_delivery_script | 9.8 | critical | 340017 |
| CVE-2023-41109 | SmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway - Command Injection | smartnode_sn200 | 9.8 | critical | 392301 |
| CVE-2023-41892 | CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution | craft_cms | 9.8 | critical | 344365 |
| CVE-2023-43208 | NextGen Healthcare Mirth Connect - Remote Code Execution | mirth_connect | 9.8 | critical | 344363 |
| CVE-2023-43373 | Hoteldruid v3.0.5 - SQL Injection | hoteldruid | 9.8 | CRITICAL | 380122 |
| CVE-2023-43374 | Hoteldruid v3.0.5 - SQL Injection | hoteldruid | 9.8 | CRITICAL | 380122 |
| CVE-2023-44353 | Adobe ColdFusion WDDX Deserialization Gadgets | coldfusion | 9.8 | critical | 350147 |
| CVE-2023-45852 | Viessmann Vitogate 300 - Remote Code Execution | vitogate_300_firmware | 9.8 | CRITICAL | 344360 |
| CVE-2023-46347 | PrestaShop Step by Step products Pack - SQL Injection | ndk_steppingpack | 9.8 | critical | 340016, 341245 |
| CVE-2023-46359 | cPH2 Charging Station v1.87.0 - OS Command Injection | cph2_echarge | 9.8 | critical | 393655 |
| CVE-2023-46574 | TOTOLINK A3700R - Command Injection | a3700r_firmware | 9.8 | critical | 392301 |
| CVE-2023-46747 | F5 BIG-IP - Unauthenticated RCE via AJP Smuggling | big-ip_access_policy_manager | 9.8 | critical | 390626, 392767 |
| CVE-2023-47246 | SysAid Server - Remote Code Execution | sysaid_on-premises | 9.8 | critical | 390626 |
| CVE-2023-48022 | Anyscale Ray - Remote Code Execution | ray | 9.8 | critical | 392301 |
| CVE-2023-48084 | Nagios XI < 5.11.3 - SQL Injection | nagios_xi | 9.8 | critical | 340130, 380122 |
| CVE-2023-4974 | Academy LMS 6.2 - SQL Injection | academy_lms | 9.8 | critical | 380122 |
| CVE-2023-50839 | JS Help Desk <= 2.8.1 - SQL Injection | JS Help Desk – Best Help Desk & Support Plugin | 9.8 | critical | 380122 |
| CVE-2023-50917 | MajorDoMo thumb.php - OS Command Injection | majordomo | 9.8 | critical | 344363 |
| CVE-2023-5203 | WP Sessions Time Monitoring Full Automatic <= 1.0.8 - SQL Injection | - | 9.8 | critical | 380122 |
| CVE-2023-5204 | WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injection | - | 9.8 | critical | 380122 |
| CVE-2023-5652 | WP Hotel Booking <= 2.0.7 - SQL Injection | wp hotel booking | 9.8 | CRITICAL | 380122 |
| CVE-2023-5991 | Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion | hotel_booking_lite | 9.8 | critical | 347009 |
| CVE-2023-6360 | WordPress My Calendar <3.4.22 - SQL Injection | my_calendar | 9.8 | CRITICAL | 380122 |
| CVE-2023-6623 | Essential Blocks < 4.4.3 - Local File Inclusion | essential_blocks | 9.8 | critical | 347009 |
| CVE-2023-6655 | Hongjing e-HR 2020 - SQL Injection | e-hr | 9.8 | CRITICAL | 341245 |
| CVE-2023-6750 | WordPress WP Clone <= 2.4.2 - Database Backup Exposure | clone | 9.8 | critical | 350590 |
| CVE-2023-6989 | Shield Security WP Plugin <= 18.5.9 - Local File Inclusion | shield_security | 9.8 | critical | 340748 |
| CVE-2023-7116 | WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection | datax-web | 9.8 | CRITICAL | 340014 |
| CVE-2024-0195 | SpiderFlow Crawler Platform - Remote Code Execution | spider-flow | 9.8 | CRITICAL | 340095 |
| CVE-2024-10571 | Chartify – WordPress Chart Plugin < 2.9.6 - Local File Inclusion | chartify | 9.8 | critical | 347006 |
| CVE-2024-1061 | WordPress HTML5 Video Player - SQL Injection | html5_video_player | 9.8 | critical | 380122 |
| CVE-2024-10763 | WordPress Campress Theme <= 1.35 - Unauthenticated Local File Inclusion | - | 9.8 | critical | 340077 |
| CVE-2024-10914 | D-Link NAS - Command Injection via Name Parameter | dns-320_firmware | 9.8 | critical | 344363 |
| CVE-2024-10915 | D-Link NAS - Command Injection via Group Parameter | dns-320_firmware | 9.8 | critical | 344363 |
| CVE-2024-12209 | WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion | wp-umbrella | 9.8 | CRITICAL | 347009 |
| CVE-2024-12987 | DrayTek Vigor - Command Injection | Vigor300B | 9.8 | critical | 347009, 393655 |
| CVE-2024-1512 | MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection | masterstudy_lms | 9.8 | critical | 380122 |
| CVE-2024-1698 | NotificationX <= 2.8.2 - SQL Injection | notificationx | 9.8 | CRITICAL | 380122 |
| CVE-2024-22729 | Netis MW5360 V1.0.1.3031 - Command Injection | mw5360_firmware | 9.8 | CRITICAL | 392301 |
| CVE-2024-23692 | Rejetto HTTP File Server - Template injection | - | 9.8 | critical | 390703 |
| CVE-2024-24112 | Exrick XMall - SQL Injection | xmall | 9.8 | critical | 340016 |
| CVE-2024-24328 | TotoLink Router setMacFilterRules - Command Injection | a3300r_firmware | 9.8 | critical | 392301 |
| CVE-2024-24329 | TotoLink Router setPortForwardRules - Command Injection | a3300r_firmware | 9.8 | critical | 392301 |
| CVE-2024-24495 | Daily Habit Tracker 1.0 - SQL Injection | daily habit tracker | 9.8 | CRITICAL | 390727, 392301, 392648 |
| CVE-2024-2667 | InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload | instawp_connect | 9.8 | critical | 340162 |
| CVE-2024-27954 | WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF | WP Automatic Automatic | 9.8 | critical | 347009 |
| CVE-2024-30163 | IPS Community Suite - Unauthenticated SQL Injection | ips_community_suite | 9.8 | critical | 380026 |
| CVE-2024-31848 | CData API Server < 23.4.8844 - Path Traversal | - | 9.8 | CRITICAL | 344365 |
| CVE-2024-31849 | CData Connect < 23.4.8846 - Path Traversal | - | 9.8 | CRITICAL | 344365 |
| CVE-2024-3552 | Web Directory Free < 1.7.0 - SQL Injection | web_directory_free | 9.8 | CRITICAL | 380122 |
| CVE-2024-3605 | WP Hotel Booking <= 2.1.0 - SQL Injection | wp hotel booking | 9.8 | CRITICAL | 380122 |
| CVE-2024-36412 | SuiteCRM - SQL Injection | suitecrm | 9.8 | critical | 380122 |
| CVE-2024-37393 | SecurEnvoy Two Factor Authentication - LDAP Injection | - | 9.8 | critical | 392301 |
| CVE-2024-37843 | Craft CMS <=v3.7.31 - SQL Injection | craft_cms | 9.8 | CRITICAL | 344378 |
| CVE-2024-38773 | FormLift for Infusionsoft Web Forms <= 7.5.17 - SQL Injection | formlift for infusionsoft web forms | 9.8 | CRITICAL | 380122 |
| CVE-2024-3922 | Dokan Pro <= 3.10.3 - SQL Injection | dokan | 9.8 | CRITICAL | 392301 |
| CVE-2024-39907 | 1Panel SQL Injection - Authenticated | 1panel | 9.8 | CRITICAL | 380026 |
| CVE-2024-39914 | FOG Project < 1.5.10.34 - Remote Command Execution | fogproject | 9.8 | critical | 344363 |
| CVE-2024-43360 | ZoneMinder - SQL Injection | zoneminder | 9.8 | critical | 380122 |
| CVE-2024-44000 | LiteSpeed Cache <= 6.4.1 - Sensitive Information Exposure | liteSpeed-cache | 9.8 | CRITICAL | 390716 |
| CVE-2024-4443 | Business Directory Plugin <= 6.4.2 - SQL Injection | business_directory | 9.8 | critical | 340156 |
| CVE-2024-45507 | Apache OFBiz - Remote Code Execution | ofbiz | 9.8 | critical | 340162 |
| CVE-2024-45622 | ASIS - SQL Injection Authentication Bypass | asis | 9.8 | CRITICAL | 340145 |
| CVE-2024-4577 | PHP CGI - Argument Injection | php | 9.8 | critical | 392301 |
| CVE-2024-4620 | ArForms < 6.6 - Remote Code Execution | arforms | 9.8 | CRITICAL | 382238 |
| CVE-2024-48307 | JeecgBoot v3.7.1 - SQL Injection | jeecg_boot | 9.8 | CRITICAL | 340159 |
| CVE-2024-50498 | WP Query Console <= 1.0 - Remote Code Execution | wp_query_console | 9.8 | CRITICAL | 340095 |
| CVE-2024-5057 | WordPress Easy Digital Downloads <= 3.2.12 - SQL Injection | easy_digital_downloads | 9.8 | CRITICAL | 380122 |
| CVE-2024-51211 | openSIS Classic v9.1 - SQL Injection | - | 9.8 | critical | 380122 |
| CVE-2024-51978 | Brother Printers – Authentication Bypass via Default Admin Password | - | 9.8 | critical | 390709 |
| CVE-2024-53584 | OpenPanel 0.3.4 - OS Command Injection | openpanel | 9.8 | CRITICAL | 344360 |
| CVE-2024-5522 | WordPress HTML5 Video Player < 2.5.27 - SQL Injection | html5_video_player | 9.8 | critical | 340016 |
| CVE-2024-5765 | WpStickyBar <= 2.1.0 - SQL Injection | wpstickybar | 9.8 | CRITICAL | 380122 |
| CVE-2024-5827 | Vanna - SQL injection | - | 9.8 | CRITICAL | 344360 |
| CVE-2024-6159 | Push Notification for Post and BuddyPress <= 1.93 - SQL Injection | push notification for post and buddypress | 9.8 | CRITICAL | 380122 |
| CVE-2024-6205 | PayPlus Payment Gateway < 6.6.9 - SQL Injection | payplus-payment-gateway | 9.8 | critical | 380122 |
| CVE-2024-6460 | WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusion | tradedoubler-affiliate-tracker | 9.8 | CRITICAL | 344360 |
| CVE-2024-6670 | WhatsUp Gold HasErrors SQL Injection - Authentication Bypass | whatsup_gold | 9.8 | CRITICAL | 340016 |
| CVE-2024-6671 | WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass | whatsup_gold | 9.8 | CRITICAL | 340016 |
| CVE-2024-6924 | TrueBooker <= 1.0.2 - SQL Injection | truebooker | 9.8 | CRITICAL | 380122 |
| CVE-2024-6926 | Viral Signup <= 2.1 - SQL Injection | viral-signup | 9.8 | CRITICAL | 380122 |
| CVE-2024-6928 | Opti Marketing <= 2.0.9 - SQL Injection | opti-marketing | 9.8 | CRITICAL | 380122 |
| CVE-2024-7332 | TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability | cp450_firmware | 9.8 | critical | 390716 |
| CVE-2024-7593 | Ivanti vTM - Authentication Bypass | virtual traffic manager | 9.8 | critical | 392301 |
| CVE-2024-7854 | Woo Inquiry <= 0.1 - SQL Injection | woo_inquiry | 9.8 | CRITICAL | 380122 |
| CVE-2024-7954 | SPIP Porte Plume Plugin - Remote Code Execution | spip | 9.8 | critical | 340023 |
| CVE-2024-8877 | Riello Netman 204 - SQL Injection | netman_204_firmware | 9.8 | critical | 340156 |
| CVE-2024-8911 | LatePoint <= 5.0.11 - SQL Injection | latepoint | 9.8 | CRITICAL | 380122 |
| CVE-2024-9047 | WordPress File Upload <= 4.24.11 - Arbitrary File Read | wordpress-file-upload | 9.8 | critical | 344360 |
| CVE-2024-9193 | WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update | - | 9.8 | critical | 340087, 347006 |
| CVE-2024-9234 | GutenKit <= 2.1.0 - Arbitrary File Upload | gutenkit | 9.8 | CRITICAL | 340162 |
| CVE-2025-1023 | ChurchCRM - SQL Injection | churchcrm | 9.8 | critical | 380122 |
| CVE-2025-11833 | Post SMTP <= 3.6.0 - Email Log Disclosure | post_smtp_mailer | 9.8 | CRITICAL | 377360 |
| CVE-2025-13486 | Advanced Custom Fields Extended < 0.9.2 - Remote Code Execution | - | 9.8 | CRITICAL | 377360 |
| CVE-2025-1562 | Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control | funnelkit automations | 9.8 | CRITICAL | 377360 |
| CVE-2025-1661 | HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion | - | 9.8 | critical | 340748 |
| CVE-2025-2294 | Kubio AI Page Builder <= 2.5.1 - Local File Inclusion | - | 9.8 | critical | 347009 |
| CVE-2025-24813 | Apache Tomcat Path Equivalence - Remote Code Execution | tomcat | 9.8 | critical | 392301 |
| CVE-2025-24893 | XWiki Platform - Remote Code Execution | xwiki | 9.8 | critical | 347009 |
| CVE-2025-25257 | Fortinet FortiWeb - SQL Injection | fortiweb | 9.8 | critical | 340156 |
| CVE-2025-2636 | InstaWP Connect < 0.1.0.86 - Local PHP File Inclusion | - | 9.8 | high | 340007 |
| CVE-2025-29085 | Vipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey Component | vipshop Saturn v.3.5.1 and before | 9.8 | critical | 340159 |
| CVE-2025-29306 | FoxCMS v.1.2.5 - Remote Code Execution | - | 9.8 | critical | 347009, 393655 |
| CVE-2025-3248 | Langflow AI - Unauthenticated Remote Code Execution | langflow | 9.8 | CRITICAL | 344360 |
| CVE-2025-32814 | NetMRI Unauthenticated SQL Injection via skipjackUsername | netmri | 9.8 | critical | 340016 |
| CVE-2025-32969 | XWiki REST API Query - SQL Injection | xwiki | 9.8 | critical | 380122 |
| CVE-2025-34085 | WordPress Simple File List <=4.2.2 - Remote Code Execution | - | 9.8 | critical | 382238 |
| CVE-2025-40552 | SolarWinds Web Help Desk - Authentication Bypass | web_help_desk | 9.8 | CRITICAL | 392301 |
| CVE-2025-4524 | WordPress Madara - Local File Inclusion | - | 9.8 | CRITICAL | 344360 |
| CVE-2025-45985 | Blink Router - Command Injection | - | 9.8 | critical | 344363 |
| CVE-2025-47812 | Wing FTP Server <= 7.4.3 - Remote Code Execution | wftpserver | 9.8 | critical | 390614 |
| CVE-2025-48157 | WordPress Formality Plugin <= 1.5.9 - Local File Inclusion | - | 9.8 | critical | 347009 |
| CVE-2025-52472 | XWiki - HQL Injection | xwiki | 9.8 | high | 340159 |
| CVE-2025-53770 | Microsoft SharePoint Server - Remote Code Execution (ToolShell) | - | 9.8 | critical | 350147 |
| CVE-2025-57819 | FreePBX - Remote Code Execution | freepbx | 9.8 | critical | 340157, 341245 |
| CVE-2025-6058 | WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload | wpbookit | 9.8 | CRITICAL | 382238 |
| CVE-2025-6403 | Code-Projects School Fees Payment System 1.0 - SQL Injection | - | 9.8 | critical | 340157, 380122 |
| CVE-2025-6970 | WordPress Events Manager <= 7.0.3 - SQL Injection | events_manager | 9.8 | critical | 380122 |
| CVE-2026-3296 | Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection | everest_forms | 9.8 | CRITICAL | 300007 |
| CVE-2026-35273 | Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE | peoplesoft_enterprise_peopletools | 9.8 | CRITICAL | 331032 |
| CVE-2026-39808 | Fortinet FortiSandbox - Command Injection | fortisandbox | 9.8 | critical | 344363 |
| CVE-2026-63030 | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution | WordPress | 9.8 | CRITICAL | 340156, 344370 |
| CVE-2026-8037 | Progress ADC LoadMaster - Command Injection | connection manager for objectscale | 9.8 | CRITICAL | 344360 |
| CVE-2026-9082 | Drupal Core - Anonymous SQL Injection via PostgreSQL Entity Query | drupal | 9.8 | CRITICAL | 340156 |
| CVE-2019-8982 | Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request Forgery | wavemarker_studio | 9.6 | critical | 347009 |
| CVE-2020-20982 | shadoweb wdja v1.5.1 - Cross-Site Scripting | wdja_cms | 9.6 | critical | 341266 |
| CVE-2021-32853 | Erxes <0.23.0 - Cross-Site Scripting | erxes | 9.6 | critical | 341266 |
| CVE-2023-1892 | Sidekiq < 7.0.8 - Cross-Site Scripting | sidekiq | 9.6 | CRITICAL | 347198 |
| CVE-2024-29824 | Ivanti EPM - Remote Code Execution | - | 9.6 | critical | 340155 |
| CVE-2026-6875 | ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE | servicenow | 9.5 | CRITICAL | 380026 |
| CVE-2019-16383 | MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection | moveit transfer | 9.4 | CRITICAL | 344366, 361149, 380122 |
| CVE-2022-26833 | Open Automation Software OAS Platform V16.00.0121 - Missing Authentication | oas_platform | 9.4 | CRITICAL | 390726 |
| CVE-2024-9264 | Grafana Post-Auth DuckDB - SQL Injection To File Read | grafana | 9.4 | CRITICAL | 344360 |
| CVE-2025-54782 | NestJS DevTools Integration - Remote Code Execution | devtools-integration | 9.4 | CRITICAL | 345240 |
| CVE-2026-28496 | FOSSBilling - Server-Side Template Injection | - | 9.4 | CRITICAL | 340155 |
| CVE-2026-46442 | Flowise < 3.1.2 - node-custom-function Unauthorized RCE | flowise | 9.4 | CRITICAL | 345240 |
| CVE-2013-1965 | Apache Struts2 S2-012 RCE | struts | 9.3 | critical | 344360 |
| CVE-2013-2251 | Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution | struts | 9.3 | critical | 393655 |
| CVE-2020-37123 | Pinger 1.0 - Remote Code Execution | pinger | 9.3 | CRITICAL | 344363 |
| CVE-2024-30498 | CRM Perks Forms <= 1.1.4 - SQL Injection | CRM Perks Forms | 9.3 | critical | 380122 |
| CVE-2024-32128 | WordPress Realtyna Organic IDX Plugin <= 4.14.4 - SQL Injection | Realtyna Organic IDX plugin | 9.3 | CRITICAL | 380122 |
| CVE-2024-32709 | WP-Recall <= 16.26.5 - SQL Injection | wp-recall | 9.3 | critical | 340016 |
| CVE-2025-25034 | SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection | - | 9.3 | critical | 344370 |
| CVE-2025-32778 | Web-Check < 2.0.1 Screenshot API - OS Command Injection | web-check | 9.3 | CRITICAL | 393655 |
| CVE-2025-48281 | MyStyle Custom Product Designer <= 3.21.1 - SQL Injection | mystyleplatform MyStyle Custom Product Designer mystyle-custom-product-designer | 9.3 | critical | 380122 |
| CVE-2026-27174 | MajorDoMo - Unauthenticated RCE | majordomo | 9.3 | CRITICAL | 347009 |
| CVE-2026-29014 | MetInfo CMS <= 8.1 - Remote Code Execution | metinfo | 9.3 | CRITICAL | 393655 |
| CVE-2026-41940 | cPanel & WHM - Authentication Bypass via Session-File CRLF Injection | cpanel | 9.3 | CRITICAL | 377364 |
| CVE-2026-4810 | Google ADK-Python - Unauthenticated Builder Endpoint | adk-python | 9.3 | CRITICAL | 390726 |
| CVE-2026-54836 | YMC Filter - SQL Injection | YMC Filter | 9.3 | CRITICAL | 380122 |
| CVE-2026-27760 | OpenCATS - Command Injection | opencats | 9.2 | CRITICAL | 344363 |
| CVE-2026-41179 | RClone RC - Command Injection | rclone | 9.2 | CRITICAL | 340014 |
| CVE-2026-42796 | Arelle < 2.39.10 - Remote Code Execution | arelle | 9.2 | CRITICAL | 340162 |
| CVE-2026-58455 | Dockwatch <= 0.6.567 - OS Command Injection | dockwatch | 9.2 | CRITICAL | 344361 |
| CVE-2017-14611 | Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery | cockpit | 9.1 | CRITICAL | 390727, 392301, 392648 |
| CVE-2018-14916 | Loytec LGATE-902 <6.4.2 - Local File Inclusion | lgate-902 | 9.1 | critical | 347009 |
| CVE-2018-16716 | NCBI ToolBox - Directory Traversal | ncbi_toolbox | 9.1 | critical | 347009 |
| CVE-2018-19365 | Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal | streaming_engine | 9.1 | critical | 347009 |
| CVE-2018-9302 | Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery | cockpit | 9.1 | CRITICAL | 390727, 392301, 392648 |
| CVE-2019-13462 | Lansweeper Unauthenticated SQL Injection | lansweeper | 9.1 | critical | 340155 |
| CVE-2019-9880 | WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosure | wpgraphql | 9.1 | CRITICAL | 344361 |
| CVE-2020-24589 | WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection | api_manager | 9.1 | critical | 380018 |
| CVE-2020-36333 | ThemeGrill Demo Importer < 1.6.2 - Database Reset | themegrill-demo-importer | 9.1 | critical | 375357 |
| CVE-2021-21479 | SCIMono <0.0.19 - Remote Code Execution | scimono | 9.1 | critical | 340087 |
| CVE-2021-27828 | In4Suit ERP 3.2.74.1370 - 'txtLoginId' SQL injection | in4suite erp | 9.1 | CRITICAL | 392301 |
| CVE-2021-27931 | LumisXP <10.0.0 - Blind XML External Entity Attack | lumis_experience_platform | 9.1 | critical | 392301 |
| CVE-2021-28918 | Netmask NPM Package - Server-Side Request Forgery | netmask | 9.1 | critical | 347009 |
| CVE-2021-37425 | Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE) | mobiletogether server | 9.1 | CRITICAL | 330791 |
| CVE-2021-37593 | PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection | peel shopping | 9.1 | CRITICAL | 390727, 392301, 392648 |
| CVE-2021-46419 | Telesquare TLR-2855KS6 - Arbitrary File Deletion | tlr-2855ks6 firmware | 9.1 | CRITICAL | 392301, 393134 |
| CVE-2022-26960 | elFinder <=2.1.60 - Local File Inclusion | elfinder | 9.1 | critical | 347009 |
| CVE-2022-27593 | QNAP QTS Photo Station External Reference - Local File Inclusion | photo_station | 9.1 | critical | 340007 |
| CVE-2022-44727 | PrestaShop lgcookieslaw - SQL Injection | eu_cookie_law_gdpr | 9.1 | CRITICAL | 380122 |
| CVE-2023-36934 | MOVEit Transfer - SQL Injection | moveit_transfer | 9.1 | critical | 340016 |
| CVE-2024-3673 | Web Directory Free < 1.7.3 - Local File Inclusion | web-directory-free | 9.1 | CRITICAL | 344360 |
| CVE-2024-40422 | Devika v1 - Path Traversal | devika | 9.1 | CRITICAL | 347009 |
| CVE-2024-5276 | Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection | filecatalyst workflow | 9.1 | CRITICAL | 341245 |
| CVE-2024-53537 | OpenPanel 0.3.4 - Directory Traversal | openpanel | 9.1 | CRITICAL | 340007 |
| CVE-2024-53900 | Mongoose < 8.8.3 - Remote Code Execution | mongoose | 9.1 | critical | 340095 |
| CVE-2024-5975 | CZ Loan Management <= 1.1 - SQL Injection | cz-loan-management | 9.1 | CRITICAL | 380122 |
| CVE-2024-8673 | Z-Downloads < 1.11.7 - Cross-Site Scripting | z-downloads | 9.1 | CRITICAL | 377360 |
| CVE-2025-49029 | WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution | bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget | 9.1 | CRITICAL | 377360 |
| CVE-2026-40887 | Vendure Core - SQL Injection | - | 9.1 | CRITICAL | 340156 |
| CVE-2008-4668 | Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion | com_imagebrowser | 9.0 | HIGH | 347009 |
| CVE-2013-5758 | Yealink VoIP Phone SIP-T38G - Privilege Escalation | sip-t38g | 9.0 | HIGH | 344360, 344370, 390726, 392647 |
| CVE-2014-5308 | TestLink 1.9.11 - Multiple SQL Injections | testlink | 9.0 | HIGH | 350147, 390726, 392647 |
| CVE-2014-7884 | ArcSight Logger - Arbitrary File Upload / Code Execution | arcsight logger | 9.0 | HIGH | 390726, 392647 |
| CVE-2019-7671 | Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting | flexair | 9.0 | CRITICAL | 340147, 390726, 392647 |
| CVE-2021-40438 | Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery | http_server | 9.0 | critical | 345271 |
| CVE-2021-45046 | Apache Log4j2 - Remote Code Injection | log4j | 9.0 | critical | 345115 |
| CVE-2023-34192 | Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scripting | collaboration | 9.0 | critical | 341266 |
| CVE-2025-5086 | Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization | - | 9.0 | critical | 331702 |
| CVE-2026-54157 | LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery | lobe-chat | 9.0 | CRITICAL | 392301 |
| CVE-2025-1302 | JSONPath Plus < 10.3.0 - Remote Code Execution | - | 8.9 | HIGH | 345240 |
| CVE-2013-4863 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.8 | HIGH | 390726, 392647 |
| CVE-2014-8356 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 | HIGH | 390726, 392301, 392647 |
| CVE-2014-8357 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 | HIGH | 390726, 392301, 392647 |
| CVE-2014-9118 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | 8.8 | HIGH | 390726, 392301, 392647 |
| CVE-2015-0104 | IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution | change and configuration management database | 8.8 | HIGH | 392301 |
| CVE-2015-4117 | Vesta Control Panel 0.9.8 - OS Command Injection | control panel | 8.8 | HIGH | 344370 |
| CVE-2016-10960 | WordPress wSecure Lite < 2.4 - Remote Code Execution | wsecure | 8.8 | high | 392301 |
| CVE-2016-4808 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 8.8 | HIGH | 344360 |
| CVE-2016-4977 | Spring Security OAuth2 Remote Command Execution | spring_security_oauth | 8.8 | high | 393655 |
| CVE-2016-6277 | NETGEAR Routers - Remote Code Execution | d6220_firmware | 8.8 | high | 347009 |
| CVE-2017-11398 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 8.8 | HIGH | 330791 |
| CVE-2017-11610 | XML-RPC Server - Remote Code Execution | supervisor | 8.8 | high | 344364 |
| CVE-2017-14535 | Trixbox - 2.8.0.4 OS Command Injection | trixbox | 8.8 | high | 347009 |
| CVE-2017-5799 | HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion | opencall media platform | 8.8 | HIGH | 390726, 392301, 392647 |
| CVE-2017-6090 | PhpColl 2.5.1 Arbitrary File Upload | phpcollab | 8.8 | HIGH | 391746 |
| CVE-2017-6823 | Fiyo CMS 2.0.6.1 - Privilege Escalation | fiyo cms | 8.8 | HIGH | 390724 |
| CVE-2017-9413 | Subsonic 6.1.1 - Server-Side Request Forgery | subsonic | 8.8 | HIGH | 390726, 392301, 392647 |
| CVE-2017-9822 | DotNetNuke 5.0.0 - 9.3.0 - Cookie Deserialization Remote Code Execution | dotnetnuke | 8.8 | high | 344365 |
| CVE-2018-10093 | AudioCodes 420HD - Remote Code Execution | 420hd_ip_phone_firmware | 8.8 | high | 347009 |
| CVE-2018-10823 | D-Link Routers - Remote Command Injection | dwr-116_firmware | 8.8 | high | 347009 |
| CVE-2018-11442 | EasyService Billing 1.0 - Cross-Site Request Forgery | easyservice billing | 8.8 | HIGH | 340147 |
| CVE-2018-11445 | EasyService Billing 1.0 - Cross-Site Request Forgery | easyservice billing | 8.8 | HIGH | 340147 |
| CVE-2018-12613 | PhpMyAdmin <4.8.2 - Local File Inclusion | phpmyadmin | 8.8 | high | 347009 |
| CVE-2018-15142 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 8.8 | HIGH | 344360, 344370 |
| CVE-2018-15884 | RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin) | mp c4504ex firmware | 8.8 | HIGH | 350147 |
| CVE-2018-5406 | KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities | kace systems management appliance firmware | 8.8 | HIGH | 390727, 392301, 392648 |
| CVE-2018-7700 | DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution | dedecms | 8.8 | high | 344370 |
| CVE-2018-7765 | Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection | u.motion builder | 8.8 | HIGH | 341245, 344364 |
| CVE-2019-14530 | OpenEMR <5.0.2 - Local File Inclusion | openemr | 8.8 | high | 347009 |
| CVE-2019-15642 | Webmin < 1.920 - Authenticated Remote Code Execution | webmin | 8.8 | high | 344362 |
| CVE-2019-19824 | TOTOLINK Realtek SD Routers - Remote Command Injection | a3002ru_firmware | 8.8 | high | 340014 |
| CVE-2019-20224 | Pandora FMS 7.0NG - Remote Command Injection | pandora_fms | 8.8 | high | 344363 |
| CVE-2019-9082 | ThinkPHP < 3.2.4 - Remote Code Execution | - | 8.8 | high | 393753 |
| CVE-2019-9189 | Prima Access Control 2.3.35 - Arbitrary File Upload | flexair | 8.8 | HIGH | 344360, 390726, 392647 |
| CVE-2020-11978 | Apache Airflow <=1.10.10 - Remote Code Execution | airflow | 8.8 | HIGH | 344364 |
| CVE-2020-13851 | Artica Pandora FMS 7.44 - Remote Code Execution | pandora_fms | 8.8 | high | 347009 |
| CVE-2020-17505 | Artica Web Proxy 4.30 - OS Command Injection | web_proxy | 8.8 | high | 340017 |
| CVE-2020-2036 | Palo Alto Networks PAN-OS Web Interface - Cross Site-Scripting | pan-os | 8.8 | HIGH | 347198 |
| CVE-2020-24579 | D-Link DSL 2888a - Authentication Bypass/Remote Command Execution | dsl2888a_firmware | 8.8 | high | 347009, 392301 |
| CVE-2020-24949 | PHP-Fusion 9.03.50 - Remote Code Execution | php-fusion | 8.8 | high | 393655 |
| CVE-2020-25760 | Visitor Management System in PHP 1.0 - SQL Injection (Authenticated) | visitor management system | 8.8 | HIGH | 390727, 392301, 392648 |
| CVE-2020-26217 | XStream <1.4.14 - Remote Code Execution | xstream | 8.8 | high | 344363 |
| CVE-2020-5192 | Hospital Management System 4.0 - 'searchdata' SQL Injection | hospital management system | 8.8 | HIGH | 340016, 390727, 392301, 392648 |
| CVE-2020-5504 | phpMyAdmin 5.0.0 - SQL Injection | phpmyadmin | 8.8 | HIGH | 390727, 392301, 392648 |
| CVE-2020-5776 | MAGMI - Cross-Site Request Forgery | magmi | 8.8 | high | 344364 |
| CVE-2020-6010 | WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated) | learnpress | 8.8 | HIGH | 380122 |
| CVE-2020-7991 | Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password) | framework | 8.8 | HIGH | 340147 |
| CVE-2020-8163 | Ruby on Rails <5.0.1 - Remote Code Execution | rails | 8.8 | high | 347009 |
| CVE-2020-8641 | Lotus Core CMS 1.0.1 - Local File Inclusion | lotus_core_cms | 8.8 | high | 347009 |
| CVE-2020-8813 | Cacti v1.2.8 - Remote Code Execution | cacti | 8.8 | high | 340014 |
| CVE-2020-9043 | WordPress wpCentral <1.5.1 - Information Disclosure | wpcentral | 8.8 | HIGH | 377360 |
| CVE-2021-20086 | Odoo Apps - Cross-Site Scripting via Prototype Pollution | jquery-bbq | 8.8 | high | 347198 |
| CVE-2021-22053 | Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Execution | spring_cloud_netflix | 8.8 | high | 340087, 340193 |
| CVE-2021-24347 | WordPress SP Project & Document Manager <4.22 - Authenticated Shell Upload | sp_project_&_document_manager | 8.8 | HIGH | 377360 |
| CVE-2021-24750 | WordPress Visitor Statistics (Real Time Traffic) <4.8 -SQL Injection | wp_visitor_statistics_(real_time_traffic) | 8.8 | high | 340016 |
| CVE-2021-25052 | WordPress Button Generator <2.3.3 - Remote File Inclusion | button_generator | 8.8 | high | 340464 |
| CVE-2021-25082 | WordPress Popup Builder < 4.0.7 - Remote Code Execution | popup builder | 8.8 | HIGH | 377360 |
| CVE-2021-28151 | Hongdian H8922 3.0.5 - Remote Command Injection | h8922_firmware | 8.8 | high | 392301 |
| CVE-2021-32819 | Nodejs Squirrelly - Remote Code Execution | squirrelly | 8.8 | high | 340014 |
| CVE-2021-3577 | Motorola Baby Monitors - Remote Command Execution | halo+_camera_firmware | 8.8 | high | 393655 |
| CVE-2022-0439 | Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injection | email subscribers & newsletters | 8.8 | HIGH | 377360 |
| CVE-2022-1329 | Elementor Website Builder - Remote Code Execution | website_builder | 8.8 | HIGH | 377360 |
| CVE-2022-1883 | Terraboard <2.2.0 - SQL Injection | terraboard | 8.8 | HIGH | 341245 |
| CVE-2022-28079 | College Management System 1.0 - 'course_code' SQL Injection (Authenticated) | college management system | 8.8 | HIGH | 340016, 340145 |
| CVE-2022-28080 | Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated) | event management system | 8.8 | HIGH | 340016, 340145 |
| CVE-2022-3142 | NEX-Forms Plugin < 7.9.7 - SQL Injection | nex-forms | 8.8 | high | 380122 |
| CVE-2022-33891 | Apache Spark UI - Remote Command Injection | spark | 8.8 | high | 344361 |
| CVE-2022-3768 | WordPress WPSmartContracts <1.3.12 - SQL Injection | wpsmartcontracts | 8.8 | high | 380122 |
| CVE-2022-3800 | IBAX - SQL Injection | go-ibax | 8.8 | high | 344366 |
| CVE-2022-46443 | Bangresto - SQL Injection | bangresto | 8.8 | high | 340016 |
| CVE-2023-0261 | WordPress WP TripAdvisor Review Slider <10.8 - Authenticated SQL Injection | wp_tripadvisor_review_slider | 8.8 | high | 380122 |
| CVE-2023-0630 | Slimstat Analytics < 4.9.3.3 Subscriber - SQL Injection | slimstat_analytics | 8.8 | high | 380122 |
| CVE-2023-0903 | Employee Task Management System v1.0 - SQL Injection on edit-task.php | employee task management system | 8.8 | HIGH | 340016 |
| CVE-2023-0904 | Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?) | employee task management system | 8.8 | HIGH | 340016 |
| CVE-2023-0912 | Auto Dealer Management System v1.0 - SQL Injection | auto dealer management system | 8.8 | HIGH | 340016 |
| CVE-2023-0913 | Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php | auto dealer management system | 8.8 | HIGH | 340016 |
| CVE-2023-0915 | Auto Dealer Management System v1.0 - SQL Injection on manage_user.php | auto dealer management system | 8.8 | HIGH | 340016 |
| CVE-2023-0962 | Music Gallery Site v1.0 - SQL Injection on page Master.php | music gallery site | 8.8 | HIGH | 390727, 392301, 392648 |
| CVE-2023-23492 | Login with Phone Number - Cross-Site Scripting | login_with_phone_number | 8.8 | high | 347198 |
| CVE-2023-23897 | Ozette Plugins - Cross-Site Request Forgery | simple_mobile_url_redirect | 8.8 | HIGH | 377360 |
| CVE-2023-30625 | Rudder Server < 1.3.0-rc.1 - SQL Injection | rudder-server | 8.8 | high | 392301 |
| CVE-2023-32749 | Pydio Cells 4.1.2 - Unauthorised Role Assignments | cells | 8.8 | HIGH | 330791 |
| CVE-2023-37462 | XWiki Platform - Remote Code Execution | xwiki | 8.8 | high | 340130 |
| CVE-2023-39108 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 | high | 347009 |
| CVE-2023-39109 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 | high | 347009 |
| CVE-2023-39110 | rConfig 3.9.4 - Server-Side Request Forgery | rconfig | 8.8 | high | 347009 |
| CVE-2023-4169 | Ruijie RG-EW1200G Router - Password Reset | rg-ew1200g_firmware | 8.8 | high | 392301 |
| CVE-2023-4415 | Ruijie RG-EW1200G Router Background - Login Bypass | rg-ew1200g_firmware | 8.8 | high | 392301 |
| CVE-2023-45375 | PrestaShop PireosPay - SQL Injection | pireospay | 8.8 | HIGH | 341245 |
| CVE-2023-48777 | WordPress Elementor 3.18.1 - File Upload/Remote Code Execution | website_builder | 8.8 | HIGH | 377360 |
| CVE-2023-49230 | Peplink Balance Two before 8.4.0 - Unauthenticated Config Upload | balance_two_firmware | 8.8 | HIGH | 392301 |
| CVE-2023-50094 | reNgine 2.2.0 - Command Injection | rengine | 8.8 | HIGH | 330791 |
| CVE-2023-7137 | Client Details System 1.0 - SQL Injection | client details system | 8.8 | HIGH | 380122 |
| CVE-2024-30464 | WPZOOM Social Icons Widget <= 4.2.15 - Missing Authorization | social-icons-widget-by-wpzoom | 8.8 | HIGH | 377360 |
| CVE-2024-35584 | openSIS < 9.1 - SQL Injection | opensis | 8.8 | high | 380122 |
| CVE-2024-36597 | AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability. | life insurance management system | 8.8 | HIGH | 340145 |
| CVE-2024-41667 | OpenAM<=15.0.3 FreeMarker - Template Injection | - | 8.8 | HIGH | 344360, 392647 |
| CVE-2024-7029 | AVTECH IP Camera - Command Injection | - | 8.8 | high | 344363 |
| CVE-2024-7340 | W&B Weave Server - Remote Arbitrary File Leak | - | 8.8 | high | 347009 |
| CVE-2024-8252 | WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusion | clean-login | 8.8 | HIGH | 344360 |
| CVE-2025-2075 | Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | uncanny automator | 8.8 | HIGH | 377360 |
| CVE-2025-32614 | EventON Lite <= 2.4 - Authenticated Local File Inclusion | flavor | 8.8 | HIGH | 344360, 377360 |
| CVE-2021-4463 | Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download | - | 8.7 | HIGH | 347009 |
| CVE-2021-47795 | GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting | geowebserver | 8.7 | HIGH | 341266, 390716 |
| CVE-2022-41800 | F5 BIG-IP Appliance Mode - Command Injection | big-ip_access_policy_manager | 8.7 | HIGH | 344362 |
| CVE-2023-7327 | Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read | - | 8.7 | HIGH | 390716 |
| CVE-2024-6911 | PerkinElmer ProcessPlus <= 1.11.6507.0 - Local File Inclusion | processplus | 8.7 | HIGH | 347019 |
| CVE-2026-31831 | Tautulli <= 2.16.1 - Path Traversal | tautulli | 8.7 | HIGH | 346019 |
| CVE-2026-33497 | Langflow < 1.7.0 - Path Traversal | langflow | 8.7 | HIGH | 300006 |
| CVE-2026-35029 | LiteLLM - Arbitrary File Read | litellm | 8.7 | HIGH | 344360 |
| CVE-2015-4694 | WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrieval | zip_attachments | 8.6 | high | 347009 |
| CVE-2018-16288 | LG SuperSign EZ CMS 2.5 - Local File Inclusion | supersign_cms | 8.6 | high | 347009 |
| CVE-2021-22214 | Gitlab CE/EE 10.5 - Server-Side Request Forgery | gitlab | 8.6 | HIGH | 344362 |
| CVE-2021-32820 | Express-handlebars - Local File Inclusion | express_handlebars | 8.6 | high | 347009 |
| CVE-2022-0783 | Multiple Shipping Address Woocommerce < 2.0 - SQL Injection | multiple_shipping_addresses_for_woocommerce | 8.6 | high | 380122 |
| CVE-2022-24900 | Piano LED Visualizer 1.3 - Local File Inclusion | piano_led_visualizer | 8.6 | high | 347009 |
| CVE-2022-41412 | perfSONAR 4.x <= 4.4.4 - Server-Side Request Forgery | perfsonar | 8.6 | high | 340007 |
| CVE-2023-26360 | Adobe ColdFusion - Local File Read | coldfusion | 8.6 | high | 340007, 344360 |
| CVE-2023-28787 | Quiz and Survey Master <= 8.1.4 - SQL Injection | Quiz And Survey Master | 8.6 | critical | 380122 |
| CVE-2023-3722 | Avaya Aura Device Services - OS Command Injection | aura_device_services | 8.6 | high | 392301 |
| CVE-2023-43662 | ShokoServer System - Local File Inclusion (LFI) | shokoserver | 8.6 | high | 390716 |
| CVE-2023-4490 | WordPress Job Portal < 2.0.6 - SQL Injection | - | 8.6 | high | 380122 |
| CVE-2023-47105 | Chaosblade < 1.7.4 - Remote Code Execution | chaosblade | 8.6 | high | 393655 |
| CVE-2024-13726 | Themes Coder Ecommerce <= 1.3.4 - SQL Injection | tc-ecommerce | 8.6 | HIGH | 380122 |
| CVE-2024-21136 | Oracle Retail Xstore Suite - Pre-authenticated Path Traversal | retail_xstore_office | 8.6 | high | 347019 |
| CVE-2024-23167 | GestSup - Cross-Site Scripting | gestsup | 8.6 | high | 333141 |
| CVE-2024-24919 | Check Point Quantum Gateway - Information Disclosure | quantum_security_gateway | 8.6 | high | 392301 |
| CVE-2024-31850 | CData Arc < 23.4.8839 - Path Traversal | arc | 8.6 | HIGH | 344365 |
| CVE-2024-31851 | CData Sync < 23.4.8843 - Path Traversal | - | 8.6 | HIGH | 344365 |
| CVE-2024-34470 | HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion | mailinspector | 8.6 | HIGH | 347009 |
| CVE-2024-48248 | NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read | backup & replication director | 8.6 | HIGH | 390726 |
| CVE-2024-48766 | NetAlert X - Arbitary File Read | netalertx | 8.6 | critical | 344360 |
| CVE-2024-9186 | Automation By Autonami < 3.3.0 - SQL Injection | wp-marketing-automations | 8.6 | HIGH | 380122 |
| CVE-2025-10897 | WooCommerce Designer Pro <= 1.9.28 - Arbitrary File Read | - | 8.6 | high | 344360 |
| CVE-2025-2558 | WordPress The Wound Theme <= 0.0.1 - Local File Inclusion | the-wound | 8.6 | HIGH | 344360, 347009 |
| CVE-2025-31131 | Yeswiki < 4.5.2 - Unauthenticated Path Traversal | - | 8.6 | high | 347009 |
| CVE-2025-34045 | WeiPHP 5.0 - Path Traversal | - | 8.6 | high | 344360 |
| CVE-2026-30958 | OneUptime < 10.0.21 - Path Traversal | oneuptime | 8.6 | HIGH | 347009 |
| CVE-2026-3326 | XStore Theme < 9.7.3 - SQL Injection | - | 8.6 | HIGH | 380122 |
| CVE-2015-2996 | SysAid Help Desk <15.2 - Local File Inclusion | sysaid | 8.5 | HIGH | 347009 |
| CVE-2021-39144 | XStream 1.4.18 - Remote Code Execution | xstream | 8.5 | high | 344363 |
| CVE-2024-9054 | Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection | timeprovider 4100 firmware | 8.5 | HIGH | 392301 |
| CVE-2026-34885 | WordPress Media Library Assistant <= 3.34 - SQL Injection | David Lingren Media LIbrary Assistant | 8.5 | HIGH | 377360 |
| CVE-2012-10018 | WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload | mapplic | 8.3 | HIGH | 377360 |
| CVE-2024-35219 | OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete | - | 8.3 | HIGH | 340007 |
| CVE-2024-5420 | SEH utnserver Pro/ProMAX/INU-100 20.1.22 - Cross-Site Scripting | - | 8.3 | high | 340147 |
| CVE-2017-10075 | Oracle Content Server - Cross-Site Scripting | webcenter_content | 8.2 | high | 347198 |
| CVE-2020-13379 | Grafana 3.0.1-7.0.1 - Server-Side Request Forgery | grafana | 8.2 | high | 340165 |
| CVE-2020-26248 | PrestaShop Product Comments <4.2.0 - SQL Injection | productcomments | 8.2 | high | 380122 |
| CVE-2022-2633 | All-In-One Video Gallery <=2.6.0 - Server-Side Request Forgery | all-in-one_video_gallery | 8.2 | high | 340163 |
| CVE-2024-21893 | Ivanti SAML - Server Side Request Forgery (SSRF) | connect_secure | 8.2 | high | 392301 |
| CVE-2024-40348 | Bazarr < 1.4.3 - Arbitrary File Read | bazarr | 8.2 | HIGH | 347009 |
| CVE-2025-2609 | MagnusBilling Login Logs - Cross-Site Scripting | magnusbilling | 8.2 | high | 333141 |
| CVE-2025-44177 | White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI) | protop | 8.2 | HIGH | 347009, 390727, 392648 |
| CVE-2025-49002 | DataEase - Remote Code Execution | dataease | 8.2 | HIGH | 340195 |
| CVE-2026-23482 | Blinko < 1.8.4 - Path Traversal | blinko | 8.2 | HIGH | 347009 |
| CVE-2013-2678 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 8.1 | HIGH | 392301 |
| CVE-2013-4862 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 8.1 | HIGH | 390726, 392647 |
| CVE-2016-1337 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 8.1 | HIGH | 333141, 340147, 344363, 390726, 392301, 392647 |
| CVE-2016-3081 | Apache S2-032 Struts - Remote Code Execution | struts | 8.1 | high | 347009 |
| CVE-2017-12615 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | 8.1 | HIGH | 347009, 380026, 392301 |
| CVE-2017-12617 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | 8.1 | HIGH | 392301 |
| CVE-2017-14095 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 8.1 | HIGH | 330791 |
| CVE-2017-15715 | Apache httpd <=2.4.29 - Arbitrary File Upload | http_server | 8.1 | high | 344365 |
| CVE-2017-9805 | Apache Struts2 S2-052 - Remote Code Execution | struts | 8.1 | high | 344360 |
| CVE-2018-1000130 | Jolokia Agent - JNDI Code Injection | webarchive_agent | 8.1 | high | 344362 |
| CVE-2018-11231 | Opencart Divido - Sql Injection | divido | 8.1 | high | 392301 |
| CVE-2018-11776 | Apache Struts2 S2-057 - Remote Code Execution | struts | 8.1 | high | 347009 |
| CVE-2018-12455 | Intelbras NPLUG 1.0.0.14 - Authentication Bypass | nplug | 8.1 | critical | 390716 |
| CVE-2018-1335 | Apache Tika < 1.1.8 - Header Command Injection | tika | 8.1 | HIGH | 340138 |
| CVE-2018-6961 | VMware NSX SD-WAN Edge - Command Injection | nsx_sd-wan_edge | 8.1 | critical | 393655 |
| CVE-2019-6340 | Drupal - Remote Code Execution | drupal | 8.1 | high | 392301 |
| CVE-2021-23394 | elFinder < 2.1.58 - Remote Code Execution | elfinder | 8.1 | high | 393781 |
| CVE-2021-25094 | Wordpress Tatsubuilder <= 3.3.11 - Remote Code Execution | tatsu | 8.1 | HIGH | 382238 |
| CVE-2023-26067 | Lexmark Printers - Command Injection | cxtpc_firmware | 8.1 | high | 392301 |
| CVE-2023-5815 | News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion | news_&_blog_designer_pack | 8.1 | high | 347006 |
| CVE-2023-6831 | mlflow - Path Traversal | mlflow | 8.1 | high | 390709 |
| CVE-2024-30188 | Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write | dolphinscheduler | 8.1 | HIGH | 390726 |
| CVE-2024-38473 | Apache HTTP Server - ACL Bypass | Apache HTTP Server | 8.1 | high | 390709 |
| CVE-2025-48954 | Discourse OAuth Social Login - Cross-site Scripting | - | 8.1 | high | 347198, 390712 |
| CVE-2025-52970 | Fortinet FortiWeb - Authentication Bypass to Admin Privilege | FortiWeb | 8.1 | HIGH | 340157 |
| CVE-2026-11111 | CVE-2026-11111 Research Note | ExampleProduct | 8.1 | HIGH | 340016, 340162 |
| CVE-2020-36836 | WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion | wp_fastest_cache | 8.0 | HIGH | 377360 |
| CVE-2021-20167 | Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun | rax43_firmware | 8.0 | high | 392301 |
| CVE-2009-1558 | Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion | wvc54gca | 7.8 | HIGH | 347009 |
| CVE-2010-4231 | Camtron CMNC-200 IP Camera - Directory Traversal | cmnc-200_firmware | 7.8 | HIGH | 347009 |
| CVE-2011-3315 | Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal | unified_ip_interactive_voice_response | 7.8 | high | 347009 |
| CVE-2014-2962 | Belkin N150 Router 1.00.08/1.00.09 - Path Traversal | n150_f9k1009_firmware | 7.8 | high | 347009 |
| CVE-2015-3035 | TP-LINK - Local File Inclusion | tl-wr841n_(9.0)_firmware | 7.8 | high | 347009 |
| CVE-2015-4669 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 7.8 | HIGH | 344360, 347198, 390726, 392647 |
| CVE-2019-20499 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 | HIGH | 330791, 344361, 390726, 392647 |
| CVE-2019-20500 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 | HIGH | 330791, 344361, 390726, 392647 |
| CVE-2019-20501 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 | HIGH | 330791, 344361, 390726, 392647 |
| CVE-2021-21315 | Node.JS System Information Library <5.3.1 - Remote Command Injection | systeminformation | 7.8 | high | 347009 |
| CVE-2022-25485 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 7.8 | high | 344360 |
| CVE-2022-25486 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 7.8 | high | 344360 |
| CVE-2023-46022 | Blood Bank 1.0 - 'bid' SQLi | blood bank | 7.8 | HIGH | 390727, 392301, 392648 |
| CVE-2016-3473 | Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection | business intelligence publisher | 7.7 | HIGH | 390704, 392301 |
| CVE-2020-35749 | WordPress Simple Job Board <2.9.4 - Local File Inclusion | simple_board_job | 7.7 | high | 347009 |
| CVE-2021-21234 | Spring Boot Actuator Logview Directory Traversal | spring-boot-actuator-logview | 7.7 | high | 340007, 347009 |
| CVE-2021-43831 | Gradio < 2.5.0 - Arbitrary File Read | gradio | 7.7 | high | 347009 |
| CVE-2024-43687 | Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS) | timeprovider 4100 firmware | 7.7 | HIGH | 392301 |
| CVE-2025-46822 | Java-springboot-codebase 1.1 - Arbitrary File Read | - | 7.7 | HIGH | 347009 |
| CVE-2025-59341 | esm.sh <= v136 - Local File Inclusion | esm.sh | 7.7 | HIGH | 347009 |
| CVE-2025-47783 | Label Studio < 1.18.0 - Reflected XSS | label-studio | 7.6 | HIGH | 340147 |
| CVE-2002-1131 | SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting | squirrelmail | 7.5 | HIGH | 341266 |
| CVE-2006-2842 | Squirrelmail <=1.4.6 - Local File Inclusion | squirrelmail | 7.5 | HIGH | 347009 |
| CVE-2008-1059 | WordPress Sniplets 1.1.2 - Local File Inclusion | sniplets_plugin | 7.5 | HIGH | 344360 |
| CVE-2009-2015 | Joomla! MooFAQ 1.0 - Local File Inclusion | joomla | 7.5 | HIGH | 347009 |
| CVE-2009-3318 | Joomla! Roland Breedveld Album 1.14 - Local File Inclusion | joomla | 7.5 | HIGH | 347009 |
| CVE-2009-4202 | Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion | joomla! | 7.5 | HIGH | 347009 |
| CVE-2009-4223 | KR-Web <=1.1b2 - Remote File Inclusion | kr-php_web_content_server | 7.5 | HIGH | 340162 |
| CVE-2009-4679 | Joomla! Portfolio Nexus - Remote File Inclusion | com_if_nexus | 7.5 | HIGH | 347009 |
| CVE-2010-0157 | Joomla! Component com_biblestudy - Local File Inclusion | joomla! | 7.5 | HIGH | 347009 |
| CVE-2010-0759 | Joomla! Plugin Core Design Scriptegrator - Local File Inclusion | scriptegrator_plugin | 7.5 | HIGH | 347009 |
| CVE-2010-0972 | Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion | com_gcalendar | 7.5 | HIGH | 347009 |
| CVE-2010-0985 | Joomla! Component com_abbrev - Local File Inclusion | com_abbrev | 7.5 | HIGH | 347009 |
| CVE-2010-1306 | Joomla! Component Picasa 2.0 - Local File Inclusion | com_joomlapicasa2 | 7.5 | HIGH | 347009 |
| CVE-2010-1470 | Joomla! Component Web TV 1.0 - Local File Inclusion | com_webtv | 7.5 | HIGH | 347009 |
| CVE-2010-1471 | Joomla! Component Address Book 1.5.0 - Local File Inclusion | com_addressbook | 7.5 | HIGH | 347009 |
| CVE-2010-1472 | Joomla! Component Horoscope 1.5.0 - Local File Inclusion | com_horoscope | 7.5 | HIGH | 347009 |
| CVE-2010-1495 | Joomla! Component Matamko 1.01 - Local File Inclusion | com_matamko | 7.5 | HIGH | 347009 |
| CVE-2010-1531 | Joomla! Component redSHOP 1.0 - Local File Inclusion | com_redshop | 7.5 | HIGH | 347009 |
| CVE-2010-1533 | Joomla! Component TweetLA 1.0.1 - Local File Inclusion | com_tweetla | 7.5 | HIGH | 347009 |
| CVE-2010-1535 | Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion | com_travelbook | 7.5 | HIGH | 347009 |
| CVE-2010-1602 | Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion | com_zimbcomment | 7.5 | HIGH | 347009 |
| CVE-2010-1603 | Joomla! Component ZiMBCore 0.1 - Local File Inclusion | com_zimbcore | 7.5 | HIGH | 347009 |
| CVE-2010-1653 | Joomla! Component Graphics 1.0.6 - Local File Inclusion | com_graphics | 7.5 | HIGH | 347009 |
| CVE-2010-1717 | Joomla! Component iF surfALERT 1.2 - Local File Inclusion | if_surfalert | 7.5 | HIGH | 347009 |
| CVE-2010-1875 | Joomla! Component Property - Local File Inclusion | com_properties | 7.5 | HIGH | 347009 |
| CVE-2010-1878 | Joomla! Component OrgChart 1.0.0 - Local File Inclusion | com_orgchart | 7.5 | HIGH | 347009 |
| CVE-2010-1952 | Joomla! Component BeeHeard 1.0 - Local File Inclusion | com_beeheard | 7.5 | HIGH | 347009 |
| CVE-2010-1953 | Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion | com_multimap | 7.5 | HIGH | 347009 |
| CVE-2010-1954 | Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion | com_multiroot | 7.5 | HIGH | 347009 |
| CVE-2010-1955 | Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion | com_blogfactory | 7.5 | HIGH | 347009 |
| CVE-2010-1956 | Joomla! Component Gadget Factory 1.0.0 - Local File Inclusion | com_gadgetfactory | 7.5 | HIGH | 347009 |
| CVE-2010-1957 | Joomla! Component Love Factory 1.3.4 - Local File Inclusion | com_lovefactory | 7.5 | HIGH | 347009 |
| CVE-2010-1977 | Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusion | com_jwhmcs | 7.5 | HIGH | 347009 |
| CVE-2010-1980 | Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion | com_joomlaflickr | 7.5 | HIGH | 347009 |
| CVE-2010-1983 | Joomla! Component redTWITTER 1.0 - Local File Inclusion | com_redtwitter | 7.5 | HIGH | 347009 |
| CVE-2010-2033 | Joomla! Percha Categories Tree 0.6 - Local File Inclusion | com_perchacategoriestree | 7.5 | HIGH | 347009 |
| CVE-2010-2034 | Joomla! Component Percha Image Attach 1.1 - Directory Traversal | com_perchaimageattach | 7.5 | HIGH | 347009 |
| CVE-2010-2035 | Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal | com_perchagallery | 7.5 | HIGH | 347009 |
| CVE-2010-2036 | Joomla! Component Percha Fields Attach 1.0 - Directory Traversal | com_perchafieldsattach | 7.5 | HIGH | 347009 |
| CVE-2010-2037 | Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal | com_perchadownloadsattach | 7.5 | HIGH | 347009 |
| CVE-2010-2045 | Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion | com_dioneformwizard | 7.5 | HIGH | 347009 |
| CVE-2010-2050 | Joomla! Component MS Comment 0.8.0b - Local File Inclusion | com_mscomment | 7.5 | HIGH | 347009 |
| CVE-2010-2128 | Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion | com_jequoteform | 7.5 | HIGH | 347009 |
| CVE-2010-2259 | Joomla! Component com_bfsurvey - Local File Inclusion | com_bfsurvey_profree | 7.5 | HIGH | 347009 |
| CVE-2010-2682 | Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion | com_realtyna | 7.5 | HIGH | 347009 |
| CVE-2010-2918 | Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion | com_joomla_visites | 7.5 | HIGH | 347009 |
| CVE-2010-3426 | Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion | com_jphone | 7.5 | HIGH | 347009 |
| CVE-2010-4282 | Pandora Fms < 3.1.1 - Directory Traversal | pandora_fms | 7.5 | high | 347009 |
| CVE-2010-4719 | Joomla! Component JRadio - Local File Inclusion | com_jradio | 7.5 | high | 347009 |
| CVE-2010-4769 | Joomla! Component Jimtawl 1.0.2 - Local File Inclusion | com_jimtawl | 7.5 | high | 347009 |
| CVE-2010-4977 | Joomla! Component Canteen 1.0 - Local File Inclusion | com_canteen | 7.5 | high | 347009 |
| CVE-2010-5028 | Joomla! Component JE Job 1.0 - Local File Inclusion | com_jejob | 7.5 | high | 347009 |
| CVE-2011-4448 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 7.5 | HIGH | 344360, 390715, 390726, 392647 |
| CVE-2011-4899 | WordPress Core 3.3.1 - Multiple Vulnerabilities | wordpress | 7.5 | HIGH | 340147, 390727, 392301, 392648 |
| CVE-2012-1226 | Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities | dolibarr_erp/crm | 7.5 | high | 347009 |
| CVE-2012-1823 | PHP CGI v5.3.12/5.4.2 Remote Code Execution | php | 7.5 | high | 340165 |
| CVE-2013-0249 | cURL - Buffer Overflow (PoC) | curl | 7.5 | HIGH | 390727, 392301, 392648 |
| CVE-2013-2680 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 7.5 | HIGH | 392301 |
| CVE-2013-5639 | Gnew 2013.1 - Multiple Vulnerabilities (2) | gnew | 7.5 | HIGH | 390727, 392301, 392648 |
| CVE-2013-5640 | Gnew 2013.1 - Multiple Vulnerabilities (2) | gnew | 7.5 | HIGH | 390727, 392301, 392648 |
| CVE-2013-5694 | Opsview pre 4.4.1 - Blind SQL Injection | opsview | 7.5 | HIGH | 344370, 390726, 392647 |
| CVE-2013-6041 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 7.5 | HIGH | 333140, 344360, 390726, 392647 |
| CVE-2014-10037 | DomPHP 0.83 - Directory Traversal | domphp | 7.5 | high | 347009 |
| CVE-2014-3704 | Drupal SQL Injection | drupal | 7.5 | high | 392301 |
| CVE-2014-3744 | Node.js st module Directory Traversal | node.js | 7.5 | high | 347009 |
| CVE-2014-6389 | PHPCompta/NOALYSS 6.7.1 5638 - Remote Command Execution | phpcompta/noalyss | 7.5 | HIGH | 390726, 392301, 392647 |
| CVE-2014-8675 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 7.5 | HIGH | 340155, 390726, 392647 |
| CVE-2014-8682 | Gogs (Go Git Service) - SQL Injection | gogs | 7.5 | high | 340016, 340017 |
| CVE-2014-9145 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 | HIGH | 344360, 390720, 390726, 392647 |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 | HIGH | 344360, 390720, 390726, 392647 |
| CVE-2014-9215 | PBBoard CMS 3.0.1 - SQL Injection | pbboard | 7.5 | HIGH | 380026, 390726, 392647 |
| CVE-2014-9464 | Microweber CMS 0.95 - SQL Injection | microweber | 7.5 | HIGH | 390726, 392301, 392647 |
| CVE-2014-9735 | WordPress RevSlider - Remote Code Execution via File Upload | showbiz_pro | 7.5 | high | 337469 |
| CVE-2015-1000005 | WordPress Candidate Application Form <= 1.3 - Local File Inclusion | candidate-application-form | 7.5 | high | 347009 |
| CVE-2015-1000010 | WordPress Simple Image Manipulator < 1.0 - Local File Inclusion | simple-image-manipulator | 7.5 | high | 347009 |
| CVE-2015-1000012 | WordPress MyPixs <=0.3 - Local File Inclusion | mypixs | 7.5 | high | 347009 |
| CVE-2015-1400 | NPDS CMS REvolution-13 - SQL Injection | revolution | 7.5 | HIGH | 334168, 390726, 392647 |
| CVE-2015-1427 | ElasticSearch - Remote Code Execution | elasticsearch | 7.5 | high | 344360 |
| CVE-2015-1503 | IceWarp Mail Server < 11.1.1 - Directory Traversal | mail server | 7.5 | HIGH | 347009, 390726, 390727, 392301, 392647, 392648 |
| CVE-2015-1518 | RedaxScript CMS 2.2.0 - SQL Injection | redaxscript | 7.5 | HIGH | 380026, 390726, 392647 |
| CVE-2015-2080 | Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers | fedora | 7.5 | HIGH | 344361, 344365, 390724 |
| CVE-2015-2196 | WordPress Spider Calendar <=1.4.9 - SQL Injection | spider_calendar | 7.5 | high | 380122 |
| CVE-2015-2824 | WordPress Plugin Simple Ads Manager - Multiple SQL Injections | simple ads manager | 7.5 | HIGH | 380026, 390720, 390724, 390726, 392647 |
| CVE-2015-3648 | ResourceSpace - Local File inclusion | resourcespace | 7.5 | high | 347009 |
| CVE-2015-4074 | Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusion | helpdesk_pro | 7.5 | high | 347009 |
| CVE-2015-4632 | Koha 3.20.1 - Directory Traversal | koha | 7.5 | high | 347009 |
| CVE-2015-5469 | WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion | mdc_youtube_downloader | 7.5 | high | 347009 |
| CVE-2015-6401 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter | 7.5 | HIGH | 333141, 340147, 344363, 390726, 392301, 392647 |
| CVE-2015-7245 | D-Link DVG-N5402SP - Local File Inclusion | dvg-n5402sp_firmware | 7.5 | HIGH | 392301 |
| CVE-2015-7297 | Joomla! Core SQL Injection | joomla! | 7.5 | high | 340159 |
| CVE-2015-9406 | mTheme Unus < 2.3 - Directory Traversal | mtheme-unus | 7.5 | high | 344360 |
| CVE-2016-10367 | Opsview Monitor Pro - Local File Inclusion | opsview | 7.5 | high | 390709 |
| CVE-2016-10924 | Wordpress Zedna eBook download <1.2 - Local File Inclusion | zedna_ebook_download | 7.5 | high | 344360 |
| CVE-2016-10956 | WordPress Mail Masta 1.0 - Local File Inclusion | mail-masta | 7.5 | high | 347009 |
| CVE-2016-1328 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 7.5 | HIGH | 333141, 340147, 344363, 390726, 392301, 392647 |
| CVE-2016-1336 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | 7.5 | HIGH | 333141, 340147, 344363, 390726, 392301, 392647 |
| CVE-2016-2389 | SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion | netweaver | 7.5 | high | 347009 |
| CVE-2016-4309 | Symphony CMS 2.6.7 - Session Fixation | symphony | 7.5 | HIGH | 390727, 392301, 392648 |
| CVE-2016-4806 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 7.5 | HIGH | 344360 |
| CVE-2016-6601 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 7.5 | HIGH | 347009, 390727, 392301, 392648 |
| CVE-2017-1000028 | Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusion | glassfish_server | 7.5 | high | 347009 |
| CVE-2017-1000029 | Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusion | glassfish_server | 7.5 | high | 347009 |
| CVE-2017-1000170 | WordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File Inclusion | jqueryfiletree | 7.5 | high | 392301 |
| CVE-2017-10271 | Oracle WebLogic Server - Remote Command Execution | weblogic_server | 7.5 | high | 344362 |
| CVE-2017-10974 | Yaws 1.91 - Local File Inclusion | yaws | 7.5 | high | 350591 |
| CVE-2017-11456 | Geneko Routers - Path Traversal | gwr352 3g router firmware | 7.5 | HIGH | 346019 |
| CVE-2017-11512 | ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval | servicedesk | 7.5 | high | 340007, 347019 |
| CVE-2017-14523 | Wonder CMS 2.3.1 - 'Host' Header Injection | wondercms | 7.5 | HIGH | 392301 |
| CVE-2017-14849 | Node.js <8.6.0 - Directory Traversal | node.js | 7.5 | high | 347009 |
| CVE-2017-15363 | Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 - Local File Inclusion | restler | 7.5 | high | 340007 |
| CVE-2017-15647 | FiberHome Routers - Local File Inclusion | routerfiberhome_firmware | 7.5 | high | 347009 |
| CVE-2017-16806 | Ulterius Server < 1.9.5.0 - Directory Traversal | ulterius_server | 7.5 | high | 347009 |
| CVE-2017-16877 | Nextjs <2.4.1 - Local File Inclusion | next.js | 7.5 | high | 347009 |
| CVE-2017-16894 | Laravel <5.5.21 - Information Disclosure | laravel | 7.5 | high | 390709 |
| CVE-2017-5850 | OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service | openbsd | 7.5 | HIGH | 390727, 392301, 392648 |
| CVE-2017-6190 | D-Link DWR-116 / DWR-116A1 - Arbitrary File Download | dwr-116 firmware | 7.5 | HIGH | 347009, 390727, 392648 |
| CVE-2017-9833 | BOA Web Server 0.94.14 - Arbitrary File Access | boa | 7.5 | high | 347009 |
| CVE-2018-10201 | Ncomputing vSPace Pro 10 and 11 - Directory Traversal | vspace_pro | 7.5 | high | 390716 |
| CVE-2018-10822 | D-Link Routers - Local File Inclusion | dwr-116_firmware | 7.5 | high | 347009 |
| CVE-2018-10956 | IPConfigure Orchid Core VMS 2.0.5 - Local File Inclusion | orchid_core_vms | 7.5 | high | 347009 |
| CVE-2018-11222 | Pandora FMS <=7.0NG.722 - Remote Code Execution | pandora_fms | 7.5 | HIGH | 390726 |
| CVE-2018-12054 | Schools Alert Management Script - Arbitrary File Read | schools_alert_management_script | 7.5 | high | 344360 |
| CVE-2018-12909 | Webgrind <= 1.5 - Local File Inclusion | webgrind | 7.5 | high | 347009 |
| CVE-2018-1306 | Apache Portals Pluto 3.0.0 - Remote Code Execution | pluto | 7.5 | HIGH | 390727, 392648 |
| CVE-2018-14912 | cgit < 1.2.1 - Directory Traversal | cgit | 7.5 | high | 347009 |
| CVE-2018-14918 | LOYTEC LGATE-902 6.3.2 - Local File Inclusion | lgate-902_firmware | 7.5 | high | 347009 |
| CVE-2018-15138 | LG-Ericsson iPECS NMS 30M - Local File Inclusion | ipecs_nms | 7.5 | high | 347009 |
| CVE-2018-15535 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 7.5 | HIGH | 347009, 390720, 390727, 392648 |
| CVE-2018-15745 | Argus Surveillance DVR 4.0.0.0 - Local File Inclusion | dvr | 7.5 | high | 340007 |
| CVE-2018-15811 | DotNetNuke 9.2 - 9.2.1 - Weak Encryption & Cookie Deserialization | dotnetnuke | 7.5 | high | 344365 |
| CVE-2018-16299 | WordPress Localize My Post 1.0 - Local File Inclusion | localize_my_post | 7.5 | high | 347009 |
| CVE-2018-18323 | Centos Web Panel 0.9.8.480 - Local File Inclusion | webpanel | 7.5 | high | 347009 |
| CVE-2018-18325 | DotNetNuke 9.2 - 9.2.2 - Weak Encryption & Cookie Deserialization | dotnetnuke | 7.5 | high | 344365 |
| CVE-2018-19326 | Zyxel VMG1312-B10D 5.13AAXA.8 - Local File Inclusion | vmg1312-b10d_firmware | 7.5 | high | 347009 |
| CVE-2018-19458 | PHP Proxy 3.0.3 - Local File Inclusion | php-proxy | 7.5 | high | 347009 |
| CVE-2018-19753 | Tarantella Enterprise <3.11 - Local File Inclusion | tarantella_enterprise | 7.5 | high | 347009 |
| CVE-2018-20463 | WordPress JSmol2WP <=1.07 - Local File Inclusion | jsmol2wp | 7.5 | high | 344360 |
| CVE-2018-20470 | Tyto Sahi pro 7.x/8.x - Local File Inclusion | sahi_pro | 7.5 | high | 340007 |
| CVE-2018-3760 | Ruby On Rails - Local File Inclusion | cloudforms | 7.5 | high | 347009 |
| CVE-2018-6008 | Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion | jtag_members_directory | 7.5 | high | 347009 |
| CVE-2018-6184 | Zeit Next.js < 4.2.3 - Local File Inclusion | next.js | 7.5 | high | 347009 |
| CVE-2018-7171 | TwonkyMedia Server 7.0.11-8.5 - Directory Traversal | twonky server | 7.5 | HIGH | 390727, 392301, 392648 |
| CVE-2018-7422 | WordPress Site Editor <=1.1.1 - Local File Inclusion | site_editor | 7.5 | high | 344360, 347009 |
| CVE-2018-7490 | uWSGI PHP Plugin Local File Inclusion | uwsgi | 7.5 | high | 347009 |
| CVE-2018-7719 | Acrolinx Server <5.2.5 - Local File Inclusion | acrolinx_server | 7.5 | high | 347019 |
| CVE-2018-8033 | Apache OFBiz - XML External Entity Injection | ofbiz | 7.5 | high | 341256 |
| CVE-2018-8727 | Mirasys DVMS Workstation <=5.12.6 - Local File Inclusion | dvms_workstation | 7.5 | high | 390716 |
| CVE-2018-9118 | WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion | wp_background_takeover_advertisements | 7.5 | high | 344360 |
| CVE-2018-9205 | Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion | avatar_uploader | 7.5 | high | 347009 |
| CVE-2019-12276 | GrandNode 4.40 - Local File Inclusion | grandnode | 7.5 | high | 347009 |
| CVE-2019-12593 | IceWarp Mail Server <=10.4.4 - Local File Inclusion | mail_server | 7.5 | high | 347019 |
| CVE-2019-14205 | WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion | adaptive_images | 7.5 | high | 344360 |
| CVE-2019-14206 | Nevma Adaptive Images - Arbitrary File Deletion | adaptive_images | 7.5 | HIGH | 340007, 377360 |
| CVE-2019-14251 | T24 Web Server - Local File Inclusion | t24 | 7.5 | high | 347009 |
| CVE-2019-14322 | Pallets Werkzeug <0.15.5 - Local File Inclusion | windows | 7.5 | high | 390716 |
| CVE-2019-16123 | PilusCart <=1.4.1 - Local File Inclusion | piluscart | 7.5 | high | 347009 |
| CVE-2019-16469 | Adobe Experience Manager - Expression Language Injection | experience_manager | 7.5 | high | 393655 |
| CVE-2019-16758 | Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal | services monitor firmware | 7.5 | HIGH | 346019 |
| CVE-2019-17538 | Jiangnan Online Judge 0.8.0 - Local File Inclusion | jiangnan_online_judge | 7.5 | high | 347009 |
| CVE-2019-18371 | Xiaomi Mi WiFi R3G Routers - Local file Inclusion | millet_router_3g_firmware | 7.5 | high | 347009 |
| CVE-2019-18665 | DOMOS 5.5 - Local File Inclusion | domos | 7.5 | high | 347009 |
| CVE-2019-18922 | Allied Telesis AT-GS950/8 - Local File Inclusion | at-gs950/8_firmware | 7.5 | high | 347009 |
| CVE-2019-19731 | Roxy Fileman 1.4.5 - Directory Traversal | roxy fileman | 7.5 | HIGH | 340007 |
| CVE-2019-19822 | TOTOLINK/Realtek Routers - Information Disclosure | - | 7.5 | high | 390716 |
| CVE-2019-19823 | TOTOLINK/Realtek Routers - Information Disclosure | - | 7.5 | high | 390716 |
| CVE-2019-5418 | Rails File Content Disclosure | rails | 7.5 | high | 390719 |
| CVE-2019-7254 | eMerge E3 1.00-06 - Local File Inclusion | linear_emerge_essential_firmware | 7.5 | high | 347009 |
| CVE-2019-7315 | Genie Access WIP3BVAF IP Camera - Local File Inclusion | wip3bvaf | 7.5 | high | 347009 |
| CVE-2019-7481 | SonicWall SRA 4600 VPN - SQL Injection | sma_100_firmware | 7.5 | high | 340016 |
| CVE-2019-9922 | Joomla! Harmis Messenger 1.2.2 - Local File Inclusion | je_messenger | 7.5 | high | 347009 |
| CVE-2020-10973 | WAVLINK - Access Control | wn530hg4_firmware | 7.5 | high | 390716 |
| CVE-2020-11738 | WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion | duplicator | 7.5 | high | 344360, 347009 |
| CVE-2020-12447 | Onkyo TX-NR585 Web Interface - Directory Traversal | tx-nr585_firmware | 7.5 | high | 347009 |
| CVE-2020-13158 | Artica Proxy Community Edition <4.30.000000 - Local File Inclusion | artica_proxy | 7.5 | high | 347009 |
| CVE-2020-13886 | Intelbras TIP 200/200 LITE/300 - Local File Inclusion | - | 7.5 | high | 347009 |
| CVE-2020-14864 | Oracle Fusion - Directory Traversal/Local File Inclusion | business_intelligence | 7.5 | high | 347009 |
| CVE-2020-17519 | Apache Flink - Local File Inclusion | flink | 7.5 | high | 390709 |
| CVE-2020-19360 | FHEM 6.0 - Local File Inclusion | fhem | 7.5 | high | 347009 |
| CVE-2020-22165 | PHPGurukul Hospital Management System 4.0 - SQL Injection | hospital_management_system | 7.5 | HIGH | 380122 |
| CVE-2020-23575 | Kyocera Printer d-COPIA253MF - Directory Traversal | d-copia253mf_plus_firmware | 7.5 | high | 347009 |
| CVE-2020-24285 | INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion | tip200 | 7.5 | high | 347009 |
| CVE-2020-27191 | LionWiki <3.2.12 - Local File Inclusion | lionwiki | 7.5 | high | 347009 |
| CVE-2020-27467 | Processwire CMS <2.7.1 - Local File Inclusion | processwire | 7.5 | high | 347009 |
| CVE-2020-35580 | SearchBlox <9.2.2 - Local File Inclusion | searchblox | 7.5 | high | 347009 |
| CVE-2020-35598 | Advanced Comment System 1.0 - Local File Inclusion | advanced_comment_system | 7.5 | high | 347009 |
| CVE-2020-35736 | GateOne 1.1 - Local File Inclusion | gateone | 7.5 | high | 347009 |
| CVE-2020-5410 | Spring Cloud Config Server - Local File Inclusion | spring_cloud_config | 7.5 | high | 390709 |
| CVE-2020-5766 | SRS Simple Hits Counter 1.0.3-1.0.4 - Unauthenticated Blind SQL Injection | srs_simple_hits_counter | 7.5 | HIGH | 380123 |
| CVE-2020-8209 | Citrix XenMobile Server - Local File Inclusion | xenmobile_server | 7.5 | high | 347009 |
| CVE-2020-8982 | Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Read | sharefile_storagezones_controller | 7.5 | high | 340007 |
| CVE-2020-9483 | SkyWalking SQLI | skywalking | 7.5 | HIGH | 341250 |
| CVE-2021-20123 | Draytek VigorConnect 1.6.0-B - Local File Inclusion | vigorconnect | 7.5 | high | 340007, 347009 |
| CVE-2021-20124 | Draytek VigorConnect 6.0-B3 - Local File Inclusion | vigorconnect | 7.5 | high | 347009 |
| CVE-2021-24170 | User Profile Picture < 2.5.0 - Sensitive Information Disclosure | user_profile_picture | 7.5 | HIGH | 377360 |
| CVE-2021-24227 | Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion | patreon_wordpress | 7.5 | high | 347009 |
| CVE-2021-24340 | WordPress Statistics <13.0.8 - Blind SQL Injection | wp_statistics | 7.5 | high | 380122 |
| CVE-2021-24644 | Images to WebP < 1.9 - Authenticated Local File Inclusion | images_to_webp | 7.5 | HIGH | 377360 |
| CVE-2021-25864 | Hue Magic 3.0.0 - Local File Inclusion | huemagic | 7.5 | high | 347009 |
| CVE-2021-25899 | Void Aural Rec Monitor 9.0.0.1 - SQL Injection | aurall_rec_monitor | 7.5 | high | 380122 |
| CVE-2021-27316 | Doctor Appointment System 1.0 - SQL Injection | doctor_appointment_system | 7.5 | high | 380122 |
| CVE-2021-27319 | Doctor Appointment System 1.0 - SQL Injection | doctor_appointment_system | 7.5 | high | 380122 |
| CVE-2021-27320 | Doctor Appointment System 1.0 - SQL Injection | doctor_appointment_system | 7.5 | high | 380122 |
| CVE-2021-3223 | Node RED Dashboard <2.26.2 - Local File Inclusion | node-red-dashboard | 7.5 | high | 347009 |
| CVE-2021-32789 | WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection | woocommerce_blocks | 7.5 | HIGH | 360150 |
| CVE-2021-33807 | Cartadis Gespage 8.2.1 - Directory Traversal | gespage | 7.5 | high | 344360 |
| CVE-2021-34805 | FAUST iServer 9.0.018.018.4 - Local File Inclusion | faust_iserver | 7.5 | high | 347019 |
| CVE-2021-35250 | SolarWinds Serv-U 15.3 - Directory Traversal | serv-u | 7.5 | high | 340007 |
| CVE-2021-35380 | TermTalk Server 3.24.0.2 - Local File Inclusion | termtalk_server | 7.5 | high | 340007 |
| CVE-2021-36748 | PrestaHome Blog for PrestaShop <1.7.8 - SQL Injection | blog | 7.5 | HIGH | 341245 |
| CVE-2021-37589 | Virtua Software Cobranca 12S - SQLi | cobranca | 7.5 | HIGH | 340156 |
| CVE-2021-39312 | WordPress True Ranker <2.2.4 - Local File Inclusion | true_ranker | 7.5 | high | 344360 |
| CVE-2021-39316 | WordPress DZS Zoomsounds <=6.50 - Local File Inclusion | zoomsounds | 7.5 | high | 347009 |
| CVE-2021-39433 | BIQS IT Biqs-drive v1.83 Local File Inclusion | biqsdrive | 7.5 | high | 347009 |
| CVE-2021-40150 | Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure | e1_zoom_firmware | 7.5 | high | 390716 |
| CVE-2021-40661 | IND780 - Local File Inclusion | ind780_firmware | 7.5 | high | 340007 |
| CVE-2021-40822 | Geoserver - Server-Side Request Forgery | geoserver | 7.5 | HIGH | 340007 |
| CVE-2021-40978 | MKdocs 1.2.2 - Directory Traversal | mkdocs | 7.5 | high | 347009 |
| CVE-2021-41277 | Metabase - Local File Inclusion | metabase | 7.5 | high | 340165, 347009 |
| CVE-2021-41291 | ECOA Building Automation System - Directory Traversal Content Disclosure | ecs_router_controller-ecs_firmware | 7.5 | high | 347009 |
| CVE-2021-41293 | ECOA Building Automation System - Arbitrary File Retrieval | ecs_router_controller-ecs_firmware | 7.5 | high | 392301 |
| CVE-2021-41460 | ECShop 4.1.0 - SQL Injection | ecshop | 7.5 | high | 340159 |
| CVE-2021-41569 | SAS/Internet 9.4 1520 - Local File Inclusion | sas/intrnet | 7.5 | high | 347009 |
| CVE-2021-41648 | PuneethReddyHC action.php SQL Injection | online-shopping-system-advanced | 7.5 | high | 392301 |
| CVE-2021-41773 | Apache 2.4.49 - Path Traversal and Remote Code Execution | http_server | 7.5 | high | 347009 |
| CVE-2021-43287 | Pre-Auth Takeover of Build Pipelines in GoCD | gocd | 7.5 | high | 347009 |
| CVE-2021-43495 | AlquistManager Local File Inclusion | alquist | 7.5 | high | 347009 |
| CVE-2021-43496 | Clustering Local File Inclusion | clustering | 7.5 | high | 347009 |
| CVE-2021-43734 | kkFileview v4.0.0 - Local File Inclusion | kkfileview | 7.5 | high | 340165, 347009 |
| CVE-2021-43778 | GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability. | barcode | 7.5 | high | 347009 |
| CVE-2021-43798 | Grafana v8.x - Arbitrary File Read | grafana | 7.5 | high | 347009 |
| CVE-2021-45043 | HD-Network Realtime Monitoring System 2.0 - Local File Inclusion | hd-network_real-time_monitoring_system | 7.5 | high | 344360 |
| CVE-2021-46104 | webp_server_go 0.4.0 - Path Traversal | webp_server_go | 7.5 | high | 390709 |
| CVE-2021-46107 | Ligeo Archives Ligeo Basics - Server Side Request Forgery | ligeo_basics | 7.5 | high | 340162, 347009 |
| CVE-2021-46381 | DLINK DAP-1620 A1 v1.01 - Directory Traversal | dap-1620 firmware | 7.5 | HIGH | 344360, 390726, 392301, 392647 |
| CVE-2021-46417 | Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI) | colibri firmware | 7.5 | HIGH | 347009 |
| CVE-2021-46418 | Telesquare TLR-2855KS6 - Arbitrary File Creation | tlr-2855ks6 | 7.5 | HIGH | 392301 |
| CVE-2022-0656 | uDraw <3.3.3 - Local File Inclusion | web_to_print_shop\ | 7.5 | high | 344360 |
| CVE-2022-0666 | Microweber < 1.2.11 - CRLF Injection | microweber | 7.5 | high | 330708 |
| CVE-2022-1119 | WordPress Simple File List <3.2.8 - Local File Inclusion | simple-file-list | 7.5 | high | 344360 |
| CVE-2022-1768 | WordPress RSVPMaker <=9.3.2 - SQL Injection | rsvpmaker | 7.5 | high | 380122 |
| CVE-2022-23347 | BigAnt Server v5.6.06 - Local File Inclusion | bigant_server | 7.5 | high | 340007 |
| CVE-2022-23854 | AVEVA InTouch Access Anywhere Secure Gateway - Local File Inclusion | intouch_access_anywhere | 7.5 | high | 390716 |
| CVE-2022-24124 | Casdoor 1.13.0 - Unauthenticated SQL Injection | casdoor | 7.5 | HIGH | 341245 |
| CVE-2022-24264 | Cuppa CMS v1.0 - SQL injection | cuppacms | 7.5 | high | 340016 |
| CVE-2022-24265 | Cuppa CMS v1.0 - SQL injection | cuppacms | 7.5 | high | 380122 |
| CVE-2022-24266 | Cuppa CMS v1.0 - SQL injection | cuppacms | 7.5 | high | 380122 |
| CVE-2022-24716 | Icinga Web 2 - Arbitrary File Disclosure | icinga_web_2 | 7.5 | high | 347009 |
| CVE-2022-26233 | Barco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusion | control_room_management_suite | 7.5 | high | 347019 |
| CVE-2022-26271 | 74cmsSE v3.4.1 - Arbitrary File Read | 74cms | 7.5 | high | 340007 |
| CVE-2022-27043 | Yearning - Directory Traversal | yearning | 7.5 | high | 347009, 347019 |
| CVE-2022-29014 | Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusion | sila_firmware | 7.5 | high | 344360 |
| CVE-2022-29298 | SolarView Compact 6.00 - Local File Inclusion | sv-cpt-mc310_firmware | 7.5 | high | 347009 |
| CVE-2022-31474 | BackupBuddy - Local File Inclusion | backupbuddy | 7.5 | high | 347009 |
| CVE-2022-33901 | WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read | multisafepay_plugin_for_woocommerce | 7.5 | high | 347009 |
| CVE-2022-34121 | CuppaCMS v1.0 - Local File Inclusion | cuppacms | 7.5 | high | 344360 |
| CVE-2022-34127 | GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin | manageentities | 7.5 | HIGH | 344360 |
| CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversal | pcoweb_hvac_bacnet_gateway | 7.5 | high | 347009 |
| CVE-2022-38794 | Zaver - Local File Inclusion | zaver | 7.5 | high | 347009 |
| CVE-2022-38840 | Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE) | man-eam-0003 | 7.5 | high | 344360 |
| CVE-2022-4140 | WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access | welcart_e-commerce | 7.5 | high | 347009 |
| CVE-2022-47501 | Apache OFBiz < 18.12.07 - Local File Inclusion | ofbiz | 7.5 | high | 340165, 347009 |
| CVE-2023-0126 | SonicWall SMA1000 LFI | sma1000 | 7.5 | high | 347009 |
| CVE-2023-0159 | Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE | extensive_vc_addons_for_wpbakery_page_builder | 7.5 | high | 344360 |
| CVE-2023-0905 | Employee Task Management System v1.0 - Broken Authentication | employee task management system | 7.5 | HIGH | 350147 |
| CVE-2023-22047 | Oracle Peoplesoft - Unauthenticated File Read | peoplesoft_enterprise | 7.5 | high | 340165, 347009 |
| CVE-2023-23063 | Cellinx NVT Web Server - Local File Disclosure | nvt_web_server | 7.5 | high | 347009 |
| CVE-2023-2356 | Mlflow <2.3.0 - Local File Inclusion | mlflow | 7.5 | HIGH | 340007 |
| CVE-2023-26256 | STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion | stagil_navigation | 7.5 | high | 347009 |
| CVE-2023-27639 | PrestaShop TshirteCommerce - Directory Traversal | custom_product_designer | 7.5 | high | 340007 |
| CVE-2023-27640 | PrestaShop tshirtecommerce - Directory Traversal | custom_product_designer | 7.5 | high | 340007 |
| CVE-2023-2766 | Weaver OA 9.5 - Information Disclosure | weaver_office_automation | 7.5 | high | 390716 |
| CVE-2023-29887 | Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion | spreadsheet-reader | 7.5 | high | 347009 |
| CVE-2023-31059 | Repetier Server - Directory Traversal | repetier-server | 7.5 | high | 347019 |
| CVE-2023-32235 | Ghost CMS < 5.42.1 - Path Traversal | ghost | 7.5 | high | 390703 |
| CVE-2023-32590 | Subscribe to Category <= 2.7.4 - SQL Injection | subscribe to category | 7.5 | HIGH | 380122 |
| CVE-2023-33510 | Jeecg P3 Biz Chat - Local File Inclusion | jeecg_p3_biz_chat | 7.5 | high | 347009 |
| CVE-2023-34092 | Vite Dev Server - Information Exposure | - | 7.5 | high | 390709 |
| CVE-2023-34105 | SRS - Command Injection | simple_realtime_server | 7.5 | HIGH | 344364 |
| CVE-2023-34133 | SonicWall GMS and Analytics - SQL Injection | analytics | 7.5 | high | 380123 |
| CVE-2023-34843 | Traggo Server - Local File Inclusion | traggo | 7.5 | high | 347019 |
| CVE-2023-35843 | NocoDB version <= 0.106.1 - Arbitrary File Read | nocodb | 7.5 | high | 347009 |
| CVE-2023-35844 | Lightdash version <= 0.510.3 Arbitrary File Read | lightdash | 7.5 | high | 347009 |
| CVE-2023-36284 | QloApps 1.6.0 - SQL Injection | qloapps | 7.5 | HIGH | 380122 |
| CVE-2023-37474 | Copyparty <= 1.8.2 - Directory Traversal | copyparty | 7.5 | high | 347009 |
| CVE-2023-38879 | openSIS v9.0 - Path Traversal | opensis | 7.5 | high | 347009 |
| CVE-2023-38950 | ZKTeco BioTime v8.5.5 - Path Traversal | biotime | 7.5 | high | 340007 |
| CVE-2023-39026 | FileMage Gateway - Directory Traversal | windows | 7.5 | high | 347019 |
| CVE-2023-39141 | Aria2 WebUI - Path traversal | webui-aria2 | 7.5 | high | 347009 |
| CVE-2023-40279 | OpenClinic GA 5.247.01 - Path Traversal (Authenticated) | openclinic ga | 7.5 | HIGH | 390727, 392301, 392648 |
| CVE-2023-40924 | SolarView Compact < 6.00 - Directory Traversal | solarview_compact_firmware | 7.5 | high | 347009 |
| CVE-2023-43261 | Milesight Routers - Information Disclosure | ur51 | 7.5 | high | 390716 |
| CVE-2023-48241 | XWiki < 4.10.15 - Information Disclosure | xwiki | 7.5 | high | 390722 |
| CVE-2023-6020 | Ray Static File - Local File Inclusion | ray | 7.5 | high | 347009 |
| CVE-2023-6023 | VertaAI ModelDB - Path Traversal | modeldb | 7.5 | high | 347009 |
| CVE-2023-6038 | H2O ImportFiles - Local File Inclusion | h2o | 7.5 | high | 344360, 347009 |
| CVE-2023-6063 | WP Fastest Cache 1.2.2 - Unauthenticated SQL Injection | wp fastest cache | 7.5 | HIGH | 380122 |
| CVE-2023-6567 | LearnPress <= 4.2.5.7 - SQL Injection | learnpress | 7.5 | high | 380122 |
| CVE-2023-6909 | Mlflow <2.9.2 - Path Traversal | mlflow | 7.5 | high | 392301 |
| CVE-2023-6977 | Mlflow <2.8.0 - Local File Inclusion | mlflow | 7.5 | high | 344360 |
| CVE-2024-0705 | Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection | stripe payment plugin for woocommerce | 7.5 | HIGH | 380122 |
| CVE-2024-11303 | Korenix JetPort 5601v3 - Path Traversal | jetport_5601 | 7.5 | high | 347009 |
| CVE-2024-12008 | W3 Total Cache < 2.8.2 - Log File Exposure | w3-total-cache | 7.5 | HIGH | 390716 |
| CVE-2024-12025 | WordPress Collapsing Categories <= 3.0.8 - SQL Injection | - | 7.5 | high | 380122 |
| CVE-2024-12849 | Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Read | error-log-viewer-wp | 7.5 | HIGH | 344360 |
| CVE-2024-13322 | Ads Pro Plugin <= 4.88 - Unauthenticated SQL Injection | - | 7.5 | high | 380122 |
| CVE-2024-1483 | Mlflow < 2.9.2 - Path Traversal | mlflow | 7.5 | HIGH | 340007 |
| CVE-2024-1561 | Gradio 4.3-4.12 - Local File Read | gradio | 7.5 | HIGH | 344365 |
| CVE-2024-1728 | Gradio > 4.19.1 UploadButton - Path Traversal | gradio | 7.5 | HIGH | 344360 |
| CVE-2024-20440 | Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials | - | 7.5 | high | 390716 |
| CVE-2024-23334 | aiohttp - Directory Traversal | aiohttp | 7.5 | high | 347009 |
| CVE-2024-26291 | Avid NEXIS Agent - Arbitrary File Read | nexis | 7.5 | high | 347009 |
| CVE-2024-27292 | Docassemble - Local File Inclusion | - | 7.5 | high | 347009 |
| CVE-2024-2879 | WordPress Plugin LayerSlider 7.9.11-7.10.0 - SQL Injection | layerslider | 7.5 | HIGH | 380122 |
| CVE-2024-28995 | SolarWinds Serv-U - Directory Traversal | serv-u | 7.5 | high | 340007, 347019 |
| CVE-2024-2928 | MLflow < 2.11.3 - Path Traversal | mlflow | 7.5 | HIGH | 340007 |
| CVE-2024-32736 | CyberPower < v2.8.3 - SQL Injection | - | 7.5 | high | 340016 |
| CVE-2024-32737 | CyberPower - SQL Injection | - | 7.5 | high | 340016 |
| CVE-2024-32738 | CyberPower - SQL Injection | - | 7.5 | high | 340016 |
| CVE-2024-32739 | CyberPower < v2.8.3 - SQL Injection | - | 7.5 | high | 340016 |
| CVE-2024-36420 | Flowise 1.4.3 - Arbitrary File Read | flowise | 7.5 | HIGH | 344360 |
| CVE-2024-36991 | Splunk Enterprise - Local File Inclusion | splunk | 7.5 | HIGH | 390716 |
| CVE-2024-3848 | Mlflow < 2.11.0 - Path Traversal | mlflow | 7.5 | HIGH | 340007 |
| CVE-2024-38816 | WebMvc.fn/WebFlux.fn - Path Traversal | - | 7.5 | high | 347009 |
| CVE-2024-38819 | Spring Framework Path Traversal in Functional Web Frameworks | spring_framework | 7.5 | high | 347009 |
| CVE-2024-41628 | Cluster Control CMON API - Directory Traversal | cluster_control | 7.5 | HIGH | 347009 |
| CVE-2024-45241 | CentralSquare CryWolf - Path Traversal | crywolf | 7.5 | high | 340007 |
| CVE-2024-45293 | TablePress < 2.4.3 - XXE Injection | tablepress | 7.5 | HIGH | 377360 |
| CVE-2024-45388 | Hoverfly < 1.10.3 - Arbitrary File Read | - | 7.5 | high | 344360 |
| CVE-2024-46938 | Sitecore Experience Platform <= 10.4 - Arbitrary File Read | experience_commerce | 7.5 | HIGH | 340007, 347019 |
| CVE-2024-4956 | Sonatype Nexus Repository Manager 3 - Local File Inclusion | nexus | 7.5 | high | 347009 |
| CVE-2024-5334 | Devika - Local File Inclusion | - | 7.5 | high | 347009 |
| CVE-2024-6049 | Lawo AG vsm LTC Time Sync (vTimeSync) - Path Traversal | - | 7.5 | HIGH | 390716 |
| CVE-2024-6250 | LOLLMS WebUI - Absolute Path Traversal | lollms_web_ui | 7.5 | high | 392301 |
| CVE-2024-6587 | LiteLLM - Server-Side Request Forgery | litellm | 7.5 | HIGH | 340162 |
| CVE-2024-6893 | Journyx - XML External Entities Injection (XXE) | journyx-jtime | 7.5 | high | 344360 |
| CVE-2024-8484 | REST API TO MiniProgram <= 4.7.1 - SQL Injection | rest-api-to-miniprogram | 7.5 | HIGH | 380122 |
| CVE-2024-8522 | LearnPress < 4.2.7.1 - SQL Injection | learnpress | 7.5 | critical | 380122 |
| CVE-2024-8529 | LearnPress < 4.2.7.1 - SQL Injection | learnpress | 7.5 | HIGH | 380122 |
| CVE-2024-8752 | WebIQ 2.15.9 - Directory Traversal | webiq | 7.5 | high | 347019 |
| CVE-2024-9362 | Polyaxon - Unauthenticated Directory Traversal | - | 7.5 | HIGH | 347009 |
| CVE-2024-9935 | PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download | pdf-generator-addon-for-elementor-page-builder | 7.5 | HIGH | 347009 |
| CVE-2025-10162 | WordPress OrderConvo < 14 - Path Traversal | - | 7.5 | high | 344360 |
| CVE-2025-12055 | MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal | - | 7.5 | high | 344365 |
| CVE-2025-13339 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read | hippoo-mobile-app-for-woocommerce | 7.5 | HIGH | 344360, 347009 |
| CVE-2025-13801 | Yoco Payments <= 3.8.8 - Path Traversal | - | 7.5 | HIGH | 347009 |
| CVE-2025-14437 | WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File | hummingbird-performance | 7.5 | high | 390716 |
| CVE-2025-2011 | Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection | - | 7.5 | high | 340016 |
| CVE-2025-24799 | GLPI < 10.0.17 - Pre-Auth SQL Injection | GLPI | 7.5 | critical | 380122 |
| CVE-2025-27817 | Apache Kafka Client - Arbitrary File Read | kafka | 7.5 | HIGH | 344360 |
| CVE-2025-30208 | Vite - Arbitrary File Read | vite | 7.5 | HIGH | 347009 |
| CVE-2025-30567 | WordPress WP01 - Path Traversal | wp01 | 7.5 | high | 390709 |
| CVE-2025-34023 | Karel IP Phone IP1211 Web Management Panel - Local File Inclusion | - | 7.5 | high | 347009 |
| CVE-2025-34031 | Moodle Jmol Filter 6.1 - Local File Inclusion | - | 7.5 | high | 347009 |
| CVE-2025-4008 | MeteoBridge <= 6.1 - Remote Code Execution | - | 7.5 | high | 393655 |
| CVE-2025-4396 | Relevanssi <= 4.24.4 (Free) - Unauthenticated SQL Injection | - | 7.5 | high | 380122 |
| CVE-2025-44137 | MapTiler Tileserver-php v2.0 - Unauthenticated File Read | - | 7.5 | high | 347009 |
| CVE-2025-47445 | WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download | Arraytics Eventin wp-event-solution | 7.5 | high | 347009 |
| CVE-2025-5287 | Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection | - | 7.5 | high | 380122 |
| CVE-2025-54726 | WordPress JS Archive List <= 6.1.5 - SQL Injection | Miguel Useche JS Archive List jquery-archive-list-widget | 7.5 | high | 380122 |
| CVE-2025-55523 | Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download | - | 7.5 | high | 347009 |
| CVE-2025-55748 | XWiki Platform - Path Traversal | - | 7.5 | high | 340007 |
| CVE-2025-59049 | Mockoon < 9.2.0 - Path Traversal | mockoon | 7.5 | high | 347009 |
| CVE-2025-61884 | Oracle E-Business Suite - Server-Side Request Forgery | - | 7.5 | high | 342259 |
| CVE-2025-66744 | Yonyou YonBIP - Path Traversal | - | 7.5 | high | 340007 |
| CVE-2025-69411 | ionCube Tester Plus <= 1.3 - Local File Inclusion | ioncube-tester-plus | 7.5 | HIGH | 347009 |
| CVE-2026-0560 | LolLMS < 2.2.0 - Server-Side Request Forgery | lollms | 7.5 | HIGH | 360151 |
| CVE-2026-1557 | WP Responsive Images <= 1.0 - Arbitrary File Read | - | 7.5 | high | 344360 |
| CVE-2026-1581 | wpForo Forum <= 2.4.14 - SQL Injection | - | 7.5 | critical | 380122 |
| CVE-2026-2413 | Ally – Web Accessibility & Usability <= 4.0.3 - SQL Injection | - | 7.5 | high | 380122 |
| CVE-2026-2416 | Geo Mashup <= 1.13.17 - SQL Injection | - | 7.5 | HIGH | 380122 |
| CVE-2026-28414 | Gradio - Absolute Path Traversal | gradio | 7.5 | HIGH | 390716 |
| CVE-2026-3018 | WordPress Newsletters <= 4.13 - Unauthenticated SQL Injection | newsletters | 7.5 | HIGH | 380122 |
| CVE-2026-3396 | WCAPF WooCommerce Ajax Product Filter - SQL Injection | - | 7.5 | HIGH | 380122 |
| CVE-2026-39364 | Vite Dev Server - Directory Traversal | - | 7.5 | high | 390709 |
| CVE-2026-9282 | W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read | w3-total-cache | 7.5 | HIGH | 344360 |
| CVE-2017-15643 | Ikraus Anti Virus 2.16.7 - Remote Code Execution | ikarus antivirus | 7.4 | HIGH | 390727, 392301, 392648 |
| CVE-2017-9355 | Subsonic 6.1.1 - XML External Entity Injection | subsonic | 7.4 | HIGH | 390726, 392301, 392647 |
| CVE-2024-11740 | Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Execution | download_manager | 7.3 | high | 344370 |
| CVE-2024-33288 | Prison Management System - SQL Injection Authentication Bypass | prison_management_system | 7.3 | HIGH | 341245 |
| CVE-2024-36683 | PrestaShop productsalert - SQL Injection | the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop | 7.3 | HIGH | 380122 |
| CVE-2024-46507 | Yeti Platform < 2.1.12 - Server-Side Template Injection to RCE | yeti | 7.3 | HIGH | 340130 |
| CVE-2024-48259 | Cloudlog - SQL Injection | cloudlog | 7.3 | high | 340016 |
| CVE-2024-7188 | Bylancer Quicklancer 2.4 G - SQL Injection | quicklancer | 7.3 | high | 380122 |
| CVE-2025-10090 | Jinher OA - SQL Injection | - | 7.3 | high | 344366, 361149 |
| CVE-2025-14340 | Payara Server - Cross-Site Scripting | - | 7.3 | HIGH | 341266 |
| CVE-2026-6433 | FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code Execution | custom-css-js-php | 7.3 | HIGH | 340016 |
| CVE-2015-4027 | Acunetix WVS 10 - Local Privilege Escalation | web vulnerability scanner | 7.2 | HIGH | 390726, 392647 |
| CVE-2016-10940 | WordPress zm-gallery plugin 1.0 SQL Injection | zm-gallery | 7.2 | high | 340017 |
| CVE-2018-1002000 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 7.2 | HIGH | 380122, 390726, 392647 |
| CVE-2018-10735 | NagiosXI <= 5.4.12 commandline.php SQL injection | nagios_xi | 7.2 | high | 340016 |
| CVE-2018-10736 | NagiosXI <= 5.4.12 - SQL injection | nagios_xi | 7.2 | high | 340016 |
| CVE-2018-10737 | NagiosXI <= 5.4.12 logbook.php SQL injection | nagios_xi | 7.2 | high | 340155 |
| CVE-2018-10738 | NagiosXI <= 5.4.12 menuaccess.php - SQL injection | nagios_xi | 7.2 | high | 340155 |
| CVE-2019-16996 | Metinfo 7.0.0 beta - SQL Injection | metinfo | 7.2 | high | 340016 |
| CVE-2019-16997 | Metinfo 7.0.0 beta - SQL Injection | metinfo | 7.2 | high | 340016 |
| CVE-2019-17418 | MetInfo 7.0.0 beta - SQL Injection | metinfo | 7.2 | high | 340016 |
| CVE-2019-18396 | Technicolor TD5130.2 - Remote Command Execution | td5130v2 firmware | 7.2 | HIGH | 344361 |
| CVE-2019-1936 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | 7.2 | HIGH | 350147, 390724, 390727, 392301, 392648 |
| CVE-2019-2767 | Oracle Business Intelligence Publisher - XML External Entity Injection | bi_publisher | 7.2 | high | 380018 |
| CVE-2019-9041 | ZZZCMS 1.6.1 - Remote Code Execution | zzzphp | 7.2 | high | 380026 |
| CVE-2020-14883 | Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution | weblogic_server | 7.2 | high | 380026 |
| CVE-2020-20969 | PluckCMS 4.7.10 - Unrestricted File Upload | pluck | 7.2 | HIGH | 390727, 392301, 392648 |
| CVE-2021-24145 | WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Upload | modern_events_calendar_lite | 7.2 | high | 382238 |
| CVE-2021-24155 | WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload | backup_guard | 7.2 | HIGH | 377360 |
| CVE-2021-24554 | WordPress Paytm Donation <=1.3.2 - Authenticated SQL Injection | paytm-pay | 7.2 | high | 380122 |
| CVE-2021-24627 | G Auto-Hyperlink <= 1.0.1 - SQL Injection | g_auto-hyperlink | 7.2 | high | 340017 |
| CVE-2021-24786 | Download Monitor < 4.4.5 - SQL Injection | download_monitor | 7.2 | high | 380122 |
| CVE-2021-24791 | Header Footer Code Manager < 1.1.14 - Admin+ SQL Injection | header_footer_code_manager | 7.2 | high | 380122 |
| CVE-2021-24862 | WordPress RegistrationMagic <5.0.1.6 - Authenticated SQL Injection | registrationmagic | 7.2 | high | 380122 |
| CVE-2021-24970 | WordPress All-In-One Video Gallery <2.5.0 - Local File Inclusion | all-in-one_video_gallery | 7.2 | HIGH | 377360 |
| CVE-2021-30203 | Dzzoffice 2.02.1 - Cross-Site Scripting | dzzoffice | 7.2 | high | 333141 |
| CVE-2021-33544 | Geutebruck - Remote Command Injection | g-cam_ebc-2110 | 7.2 | high | 393655 |
| CVE-2021-39411 | Hospital Management System 1.0 - Cross-Site Scripting | hospital_management_system | 7.2 | high | 340147 |
| CVE-2022-0228 | Popup Builder < 4.0.7 - SQL Injection | popup_builder | 7.2 | high | 380122 |
| CVE-2022-2219 | Unyson < 2.7.27 - Cross Site Scripting | unyson | 7.2 | high | 341266 |
| CVE-2022-29316 | Complete Online Job Search System 1.0 - Cross-Site Scripting | - | 7.2 | high | 340147 |
| CVE-2022-31974 | Online Fire Reporting System v1.0 - SQL injection | online_fire_reporting_system | 7.2 | high | 340016 |
| CVE-2022-31975 | Online Fire Reporting System v1.0 - SQL injection | online_fire_reporting_system | 7.2 | high | 340016 |
| CVE-2022-31984 | Online Fire Reporting System v1.0 - SQL injection | online_fire_reporting_system | 7.2 | high | 340016 |
| CVE-2022-32007 | Complete Online Job Search System 1.0 - SQL Injection | complete_online_job_search_system | 7.2 | high | 340016 |
| CVE-2022-32015 | Complete Online Job Search System 1.0 - SQL Injection | complete_online_job_search_system | 7.2 | high | 340016 |
| CVE-2022-32018 | Complete Online Job Search System 1.0 - SQL Injection | complete_online_job_search_system | 7.2 | high | 340016 |
| CVE-2022-32022 | Car Rental Management System 1.0 - SQL Injection | car_rental_management_system | 7.2 | high | 340156 |
| CVE-2022-32024 | Car Rental Management System 1.0 - SQL Injection | car_rental_management_system | 7.2 | high | 340016 |
| CVE-2022-32025 | Car Rental Management System 1.0 - SQL Injection | car_rental_management_system | 7.2 | high | 340016 |
| CVE-2022-32026 | Car Rental Management System 1.0 - SQL Injection | car_rental_management_system | 7.2 | high | 340016 |
| CVE-2022-32028 | Car Rental Management System 1.0 - SQL Injection | car_rental_management_system | 7.2 | high | 340016 |
| CVE-2022-34590 | Hospital Management System 1.0 - SQL Injection | hospital_management_system | 7.2 | high | 340145 |
| CVE-2023-0669 | Fortra GoAnywhere MFT - Remote Code Execution | goanywhere_managed_file_transfer | 7.2 | high | 344370 |
| CVE-2023-0900 | AP Pricing Tables Lite <= 1.1.6 - SQL Injection | pricing_table_builder | 7.2 | HIGH | 377360 |
| CVE-2023-1211 | phpIPAM 1.5.1 - SQL Injection | phpipam | 7.2 | HIGH | 380122 |
| CVE-2023-1408 | Video List Manager <= 1.7 - SQL Injection | video_list_manager | 7.2 | high | 380122 |
| CVE-2023-33439 | Faculty Evaluation System v1.0 - SQL Injection | faculty_evaluation_system | 7.2 | high | 340159 |
| CVE-2023-33629 | H3C Magic R300-2100M - Remote Code Execution | magic_r300-2100m_firmware | 7.2 | high | 392301 |
| CVE-2023-47873 | WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload | wp_child_theme_generator | 7.2 | HIGH | 377360 |
| CVE-2025-29635 | D-Link DIR-823X set_prohibiting - Command Injection | dir-823x_firmware | 7.2 | HIGH | 340014 |
| CVE-2025-32813 | Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request | netmri | 7.2 | high | 393655 |
| CVE-2025-5961 | WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload | migration, backup, staging | 7.2 | HIGH | 377360 |
| CVE-2019-10717 | BlogEngine.NET 3.3.7.0 - Local File Inclusion | blogengine.net | 7.1 | HIGH | 340007 |
| CVE-2019-25246 | BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure | n100_h.264_vga_ip_camera | 7.1 | HIGH | 347009 |
| CVE-2022-35507 | Proxmox - CRLF Injection | proxmox_mail_gateway | 7.1 | high | 390714 |
| CVE-2024-10152 | Simple Certain Time to Show Content - Cross-Site Scripting | simple_certain_time_to_show_content | 7.1 | HIGH | 377360 |
| CVE-2024-11921 | Give WP Plugin < 3.19.0 - Cross-Site Scripting | - | 7.1 | high | 341266 |
| CVE-2024-12638 | Bulk Me Now! Plugin <= 2.0 - Cross-Site Scripting | bulk_me_now | 7.1 | HIGH | 377360 |
| CVE-2024-12749 | WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting | competition_form | 7.1 | HIGH | 377360 |
| CVE-2024-12878 | Lazy Blocks <= 3.8.2 - Cross-Site Scripting | lazy blocks | 7.1 | HIGH | 377360 |
| CVE-2024-13055 | Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting | dyn_business_panel | 7.1 | HIGH | 377360 |
| CVE-2024-13094 | WP Triggers Lite - Cross-Site Scripting | wp_triggers_lite | 7.1 | HIGH | 377360 |
| CVE-2024-13330 | JustRows WordPress - Cross-Site Scripting | justrows_free | 7.1 | HIGH | 377360 |
| CVE-2024-13569 | WordPress Front End Users - Reflected XSS | front_end_users | 7.1 | HIGH | 377360 |
| CVE-2024-13624 | WordPress WPMovieLibrary Plugin <= 2.1.4.8 - Cross-Site Scripting | wpmovielibrary | 7.1 | HIGH | 341266, 377360 |
| CVE-2024-35694 | Wordpress WPMobile.App >= 11.42 - Cross-Site Scripting | wpmobile.app | 7.1 | high | 341266 |
| CVE-2024-41357 | phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS) | phpipam | 7.1 | HIGH | 340147 |
| CVE-2019-6793 | GitLab Enterprise Edition - Server-Side Request Forgery | gitlab | 7.0 | high | 390616 |
| CVE-2018-3238 | Oracle Fusion Middleware WebCenter Sites 11.1.1.8.0 - Cross-Site Scripting | webcenter_sites | 6.9 | medium | 341266 |
| CVE-2024-10758 | NEWS-BUZZ News Management System 1.0 - SQL Injection | news-buzz | 6.9 | MEDIUM | 380122 |
| CVE-2024-9474 | PAN-OS Management Web Interface - Command Injection | pan-os | 6.9 | MEDIUM | 344363 |
| CVE-2025-5298 | Campcodes Online Hospital Management System 1.0 - SQL Injection | online hospital management system | 6.9 | MEDIUM | 390726, 392647 |
| CVE-2025-62613 | VDO.Ninja - DOM-Based Cross-Site Scripting | - | 6.9 | MEDIUM | 347198 |
| CVE-2026-29059 | Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversal | windmill | 6.9 | MEDIUM | 347009 |
| CVE-2004-0519 | SquirrelMail 1.4.x - Folder Name Cross-Site Scripting | propack | 6.8 | MEDIUM | 341266 |
| CVE-2007-0885 | Jira Rainbow.Zen - Cross-Site Scripting | rainbow.zen | 6.8 | MEDIUM | 341266 |
| CVE-2007-4556 | OpenSymphony XWork/Apache Struts2 - Remote Code Execution | xwork | 6.8 | MEDIUM | 344360 |
| CVE-2008-2650 | CMSimple 3.1 - Local File Inclusion | cmsimple | 6.8 | MEDIUM | 347009 |
| CVE-2008-6172 | Joomla! Component RWCards 3.0.11 - Local File Inclusion | rwcards | 6.8 | MEDIUM | 347009 |
| CVE-2009-3053 | Joomla! Agora 3.0.0b - Local File Inclusion | joomla | 6.8 | MEDIUM | 347009 |
| CVE-2010-1056 | Joomla! Component com_rokdownloads - Local File Inclusion | com_rokdownloads | 6.8 | MEDIUM | 347009 |
| CVE-2010-1219 | Joomla! Component com_janews - Local File Inclusion | com_janews | 6.8 | MEDIUM | 347009 |
| CVE-2010-1469 | Joomla! Component JProject Manager 1.0 - Local File Inclusion | com_jprojectmanager | 6.8 | MEDIUM | 347009 |
| CVE-2010-1473 | Joomla! Component Advertising 0.25 - Local File Inclusion | com_advertising | 6.8 | MEDIUM | 347009 |
| CVE-2010-1474 | Joomla! Component Sweetykeeper 1.5 - Local File Inclusion | com_sweetykeeper | 6.8 | MEDIUM | 347009 |
| CVE-2010-1475 | Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion | com_preventive | 6.8 | MEDIUM | 347009 |
| CVE-2010-1476 | Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion | com_alphauserpoints | 6.8 | MEDIUM | 347009 |
| CVE-2010-1478 | Joomla! Component Jfeedback 1.2 - Local File Inclusion | com_jfeedback | 6.8 | MEDIUM | 347009 |
| CVE-2010-1607 | Joomla! Component WMI 1.5.0 - Local File Inclusion | com_wmi | 6.8 | MEDIUM | 347009 |
| CVE-2010-1715 | Joomla! Component Online Exam 1.5.0 - Local File Inclusion | com_onlineexam | 6.8 | MEDIUM | 347009 |
| CVE-2010-1718 | Joomla! Component Archery Scores 1.0.6 - Local File Inclusion | com_archeryscores | 6.8 | MEDIUM | 347009 |
| CVE-2010-1719 | Joomla! Component MT Fire Eagle 1.2 - Local File Inclusion | com_mtfireeagle | 6.8 | MEDIUM | 347009 |
| CVE-2010-1722 | Joomla! Component Online Market 2.x - Local File Inclusion | com_market | 6.8 | MEDIUM | 347009 |
| CVE-2010-1723 | Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusion | com_drawroot | 6.8 | MEDIUM | 347009 |
| CVE-2010-1979 | Joomla! Component Affiliate Datafeeds 880 - Local File Inclusion | com_datafeeds | 6.8 | MEDIUM | 347009 |
| CVE-2010-1981 | Joomla! Component Fabrik 2.0 - Local File Inclusion | fabrik | 6.8 | MEDIUM | 347009 |
| CVE-2010-2122 | Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrieval | com_simpledownload | 6.8 | MEDIUM | 347009 |
| CVE-2010-2507 | Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion | com_picasa2gallery | 6.8 | MEDIUM | 347009 |
| CVE-2010-2680 | Joomla! Component jesectionfinder - Local File Inclusion | com_jesectionfinder | 6.8 | MEDIUM | 347009 |
| CVE-2010-2857 | Joomla! Component Music Manager - Local File Inclusion | com_music | 6.8 | MEDIUM | 347009 |
| CVE-2010-2920 | Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusion | com_foobla_suggestions | 6.8 | MEDIUM | 347009 |
| CVE-2010-4617 | Joomla! Component JotLoader 2.2.1 - Local File Inclusion | com_jotloader | 6.8 | medium | 347009 |
| CVE-2011-2744 | Chyrp 2.x - Local File Inclusion | chyrp | 6.8 | medium | 347009 |
| CVE-2011-4449 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 | MEDIUM | 344360, 390715, 390726, 392647 |
| CVE-2011-4452 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 | MEDIUM | 344360, 390715, 390726, 392647 |
| CVE-2012-0286 | stoneware webnetwork6 - Multiple Vulnerabilities | webnetwork | 6.8 | MEDIUM | 390726, 392301, 392647 |
| CVE-2012-0392 | Apache Struts2 S2-008 RCE | struts | 6.8 | medium | 347009 |
| CVE-2012-3350 | Webmatic 3.1.1 - Blind SQL Injection | webmatic | 6.8 | MEDIUM | 390727, 392301, 392648 |
| CVE-2014-0864 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 6.8 | MEDIUM | 392301 |
| CVE-2014-2383 | Dompdf < v0.6.0 - Local File Inclusion | dompdf | 6.8 | medium | 347009 |
| CVE-2014-3120 | ElasticSearch v1.1.1/1.2 RCE | elasticsearch | 6.8 | medium | 344360 |
| CVE-2015-2755 | WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting | ab_google_map_travel | 6.8 | MEDIUM | 377360 |
| CVE-2015-5161 | eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injection | zend framework | 6.8 | MEDIUM | 390727, 392301, 392648 |
| CVE-2012-1258 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.5 | MEDIUM | 341266, 390727, 392301, 392648 |
| CVE-2012-4240 | Group Office Calendar - '/calendar/json.php' SQL Injection | groupoffice | 6.5 | MEDIUM | 340016 |
| CVE-2013-4861 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 | MEDIUM | 390726, 392647 |
| CVE-2013-4865 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | 6.5 | MEDIUM | 390726, 392647 |
| CVE-2014-7176 | Enalean Tuleap 7.4.99.5 - Blind SQL Injection | tuleap | 6.5 | MEDIUM | 390726, 392301, 392647 |
| CVE-2015-4062 | WordPress NewStatPress 0.9.8 - SQL Injection | newstatpress | 6.5 | medium | 380122 |
| CVE-2017-14537 | Trixbox 2.8.0 - Path Traversal | trixbox | 6.5 | medium | 344360, 347009 |
| CVE-2017-3546 | Oracle PeopleSoft - Server-Side Request Forgery | peoplesoft enterprise peopletools | 6.5 | MEDIUM | 390727, 392301, 392648 |
| CVE-2017-6338 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities | interscan web security virtual appliance | 6.5 | MEDIUM | 340147, 390724 |
| CVE-2017-6339 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities | interscan web security virtual appliance | 6.5 | MEDIUM | 340147, 390724 |
| CVE-2017-9416 | Odoo 8.0/9.0/10.0 - Local File Inclusion | odoo | 6.5 | medium | 347009 |
| CVE-2018-15140 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 6.5 | MEDIUM | 344360, 344370 |
| CVE-2018-15141 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 6.5 | MEDIUM | 344360, 344370 |
| CVE-2018-18809 | TIBCO JasperReports Library - Directory Traversal | jasperreports_library | 6.5 | medium | 340007 |
| CVE-2018-3714 | node-srv - Local File Inclusion | node-srv | 6.5 | medium | 347009 |
| CVE-2018-5404 | KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities | kace systems management appliance firmware | 6.5 | MEDIUM | 390727, 392301, 392648 |
| CVE-2018-7690 | Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure | fortify software security center | 6.5 | MEDIUM | 390727, 392301, 392648 |
| CVE-2018-7691 | Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2) | fortify software security center | 6.5 | MEDIUM | 330791 |
| CVE-2018-9038 | Monstra CMS 3.0.4 - Arbitrary Folder Deletion | monstra | 6.5 | MEDIUM | 390727, 392301, 392648 |
| CVE-2019-11013 | Nimble Streamer <=3.5.4-9 - Local File Inclusion | nimble_streamer | 6.5 | medium | 347009 |
| CVE-2019-12616 | phpMyAdmin 4.8 - Cross-Site Request Forgery | phpmyadmin | 6.5 | MEDIUM | 390727, 392301, 392648 |
| CVE-2019-14312 | Aptana Jaxer 1.0.3.4547 - Local File inclusion | jaxer | 6.5 | medium | 347009 |
| CVE-2019-3778 | Spring Security OAuth - Open Redirector | spring security oauth | 6.5 | MEDIUM | 390703, 390727, 392648 |
| CVE-2019-3799 | Spring Cloud Config Server - Local File Inclusion | spring_cloud_config | 6.5 | medium | 347009 |
| CVE-2019-7439 | JioFi 4G M2S 1.0.2 - Denial of Service | jiofi 4g m2s firmware | 6.5 | MEDIUM | 340147 |
| CVE-2020-13945 | Apache APISIX - Insufficiently Protected Credentials | apisix | 6.5 | MEDIUM | 380026 |
| CVE-2020-5405 | Spring Cloud Config - Local File Inclusion | spring_cloud_config | 6.5 | medium | 390709 |
| CVE-2020-6950 | Eclipse Mojarra - Local File Read | mojarra | 6.5 | medium | 340007 |
| CVE-2020-8615 | Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery | tutor_lms | 6.5 | MEDIUM | 377360 |
| CVE-2021-21402 | Jellyfin <10.7.0 - Local File Inclusion | jellyfin | 6.5 | medium | 347019 |
| CVE-2021-22145 | Elasticsearch 7.10.0-7.13.3 - Information Disclosure | elasticsearch | 6.5 | MEDIUM | 330791 |
| CVE-2021-24405 | WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS | easy cookies policy | 6.5 | MEDIUM | 390585, 390726, 392647 |
| CVE-2021-24947 | WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Read | responsive_vector_maps | 6.5 | medium | 347009 |
| CVE-2021-27124 | Doctor Appointment System 1.0 - SQL Injection | doctor_appointment_system | 6.5 | medium | 340016 |
| CVE-2021-28149 | Hongdian H8922 3.0.5 Devices - Local File Inclusion | h8922_firmware | 6.5 | medium | 347009 |
| CVE-2021-29006 | rConfig 3.9.6 - Local File Inclusion | rconfig | 6.5 | medium | 347009 |
| CVE-2021-31195 | Microsoft Exchange Server - Cross-Site Scripting | exchange_server | 6.5 | medium | 350148 |
| CVE-2021-31249 | CHIYU TCP/IP Converter - Carriage Return Line Feed Injection | bf-430_firmware | 6.5 | medium | 341266 |
| CVE-2021-34369 | Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR) | civic platform | 6.5 | MEDIUM | 390727, 392301, 392648 |
| CVE-2021-36749 | Apache Druid - Local File Inclusion | druid | 6.5 | MEDIUM | 344360 |
| CVE-2021-39165 | Cachet <=2.3.18 - SQL Injection | cachet | 6.5 | medium | 380122 |
| CVE-2021-40651 | OS4Ed OpenSIS Community 8.0 - Local File Inclusion | opensis | 6.5 | medium | 347009 |
| CVE-2021-41349 | Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scripting | exchange_server | 6.5 | medium | 340147 |
| CVE-2022-1398 | External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request Forgery | external_media_without_import | 6.5 | MEDIUM | 377360 |
| CVE-2022-34125 | GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin | cmdb | 6.5 | MEDIUM | 344360 |
| CVE-2022-37299 | Shirne CMS 1.2.0 - Local File Inclusion | shirne_cms | 6.5 | medium | 347009 |
| CVE-2022-38812 | AeroCMS 0.1.1 - SQL Injection | aerocms | 6.5 | medium | 340016 |
| CVE-2022-40734 | Laravel Filemanager v2.5.1 - Local File Inclusion | laravel_filemanager | 6.5 | medium | 340007 |
| CVE-2023-27167 | Suprema BioStar 2 v2.8.16 - SQL Injection | biostar 2 | 6.5 | MEDIUM | 330791 |
| CVE-2023-3188 | Owncast - Server Side Request Forgery | owncast | 6.5 | medium | 392301 |
| CVE-2023-3345 | LMS by Masteriyo < 1.6.8 - Information Exposure | masteriyo | 6.5 | MEDIUM | 377360 |
| CVE-2023-45826 | Leantime < 2.4 - Authenticated SQL Injection | leantime | 6.5 | MEDIUM | 390726 |
| CVE-2024-24565 | CrateDB Database - Arbitrary File Read | cratedb | 6.5 | MEDIUM | 340016, 344360 |
| CVE-2024-4257 | BlueNet Technology Clinical Browsing System 1.2.1 - Sql Injection | clinical browsing system | 6.5 | MEDIUM | 341245 |
| CVE-2024-55457 | MasterSAM Star Gate v11 - Local File Inclusion | - | 6.5 | high | 347009 |
| CVE-2024-9765 | EKC Tournament Manager WordPress plugin - Path Traversal | ekc_tournament_manager | 6.5 | MEDIUM | 377360 |
| CVE-2025-13652 | WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection | cbx-bookmark-favorite | 6.5 | MEDIUM | 377360 |
| CVE-2025-28367 | mojoPortal <=2.9.0.1 - Directory Traversal | - | 6.5 | medium | 344360 |
| CVE-2025-32430 | XWiki Platform - Cross-Site Scripting | xwiki-platform | 6.5 | medium | 347198 |
| CVE-2025-32815 | NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentials | netmri | 6.5 | medium | 344360 |
| CVE-2025-4388 | Liferay Portal - Cross-Site Scripting | - | 6.5 | medium | 347198 |
| CVE-2025-53771 | Microsoft SharePoint Server - Authentication Bypass (ToolShell) | - | 6.5 | medium | 350147 |
| CVE-2025-54249 | Adobe Experience Manager ≤ 6.5.23.0 – SSRF | experience_manager | 6.5 | MEDIUM | 390726 |
| CVE-2025-55911 | ClipBucket 5.5.2 Build | clipbucket | 6.5 | MEDIUM | 340162 |
| CVE-2025-61224 | DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site Scripting | dokuwiki | 6.5 | MEDIUM | 333141 |
| CVE-2000-0760 | Jakarta Tomcat 3.1 and 3.0 - Information Disclosure | tomcat | 6.4 | MEDIUM | 310094 |
| CVE-2009-0932 | Horde/Horde Groupware - Local File Inclusion | horde | 6.4 | MEDIUM | 390614 |
| CVE-2011-4450 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.4 | MEDIUM | 344360, 390715, 390726, 392647 |
| CVE-2012-3153 | Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153) | fusion_middleware | 6.4 | medium | 340165 |
| CVE-2012-4940 | Axigen Mail Server Filename Directory Traversal | axigen_free_mail_server | 6.4 | medium | 347019 |
| CVE-2025-13418 | Responsive Pricing Table <= 5.1.12 - Cross-Site Scripting | responsive-pricing-table | 6.4 | MEDIUM | 377360 |
| CVE-2017-9640 | Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write | i-vu | 6.3 | MEDIUM | 390727, 392301, 392648 |
| CVE-2024-11305 | Altenergy Power Control Software - SQL Injection | energy_communication_unit_firmware | 6.3 | medium | 340016 |
| CVE-2024-2330 | NS-ASG Application Security Gateway 6.3 - Sql Injection | - | 6.3 | medium | 340157 |
| CVE-2024-2621 | Fujian Kelixin Communication - Command Injection | - | 6.3 | medium | 380122 |
| CVE-2024-32231 | Stash < 0.26.0 - SQL Injection | stash | 6.3 | MEDIUM | 340016 |
| CVE-2024-7120 | Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 - Command Injection | - | 6.3 | medium | 344363 |
| CVE-2024-7801 | Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection | timeprovider 4100 firmware | 6.3 | MEDIUM | 392301 |
| CVE-2025-10210 | ChanCMS <= 3.3.0 - SQL Injection | - | 6.3 | medium | 340159 |
| CVE-2025-54589 | Copyparty <=1.18.6 - Cross-Site Scripting | copyparty | 6.3 | medium | 341266 |
| CVE-2025-11371 | Gladinet CentreStack & TrioFox - Local File Inclusion | - | 6.2 | medium | 347019 |
| CVE-2026-29066 | TinaCMS - Path Traversal | tinacms | 6.2 | MEDIUM | 347009 |
| CVE-2011-4336 | Tiki Wiki CMS Groupware 7.0 Cross-Site Scripting | tikiwiki_cms/groupware | 6.1 | medium | 341266 |
| CVE-2012-1260 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.1 | MEDIUM | 341266, 390727, 392301, 392648 |
| CVE-2012-1261 | Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities | scrutinizer netflow & sflow analyzer | 6.1 | MEDIUM | 341266, 390727, 392301, 392648 |
| CVE-2012-5193 | Bitweaver 2.8.1 - Multiple Vulnerabilities | bitweaver | 6.1 | MEDIUM | 340147, 380026 |
| CVE-2013-2679 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 6.1 | MEDIUM | 392301 |
| CVE-2013-2684 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 6.1 | MEDIUM | 392301 |
| CVE-2014-100004 | Sitecore CMS - Cross-Site Scripting | sitecore.net | 6.1 | medium | 347198 |
| CVE-2014-4535 | Import Legacy Media <= 0.1 - Cross-Site Scripting | import_legacy_media | 6.1 | MEDIUM | 341266 |
| CVE-2014-4536 | Infusionsoft Gravity Forms Add-on < 1.5.7 - Cross-Site Scripting | infusionsoft_gravity_forms | 6.1 | MEDIUM | 341266 |
| CVE-2014-4539 | Movies <= 0.6 - Cross-Site Scripting | movies | 6.1 | MEDIUM | 341266 |
| CVE-2014-4544 | Podcast Channels < 0.28 - Cross-Site Scripting | podcast_channels | 6.1 | medium | 341266 |
| CVE-2014-4550 | Shortcode Ninja <= 1.4 - Cross-Site Scripting | ninja | 6.1 | MEDIUM | 341266 |
| CVE-2014-4558 | WooCommerce Swipe <= 2.7.1 - Cross-Site Scripting | swipehq-payment-gateway-woocommerce | 6.1 | MEDIUM | 341266 |
| CVE-2014-4561 | Ultimate Weather Plugin <= 1.0 - Cross-Site Scripting | ultimate-weather | 6.1 | MEDIUM | 341266 |
| CVE-2014-4592 | WP Planet <= 0.1 - Cross-Site Scripting | wp-planet | 6.1 | medium | 341266 |
| CVE-2014-9606 | Netsweeper 4.0.8 - Cross-Site Scripting | netsweeper | 6.1 | medium | 341266 |
| CVE-2014-9607 | Netsweeper 4.0.4 - Cross-Site Scripting | netsweeper | 6.1 | medium | 341266 |
| CVE-2014-9608 | Netsweeper 4.0.3 - Cross-Site Scripting | netsweeper | 6.1 | medium | 341266 |
| CVE-2014-9615 | Netsweeper 4.0.4 - Cross-Site Scripting | netsweeper | 6.1 | medium | 341266 |
| CVE-2015-4668 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 6.1 | MEDIUM | 344360, 347198, 390726, 392647 |
| CVE-2015-6544 | Combodo iTop <2.2.0-2459 - Cross-Site Scripting | itop | 6.1 | medium | 341266 |
| CVE-2015-8349 | SourceBans <2.0 - Cross-Site Scripting | sourcebans | 6.1 | medium | 341266 |
| CVE-2015-8350 | WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS | call_to_action | 6.1 | MEDIUM | 377360 |
| CVE-2015-9312 | NewStatPress <=1.0.4 - Cross-Site Scripting | newstatpress | 6.1 | medium | 347198 |
| CVE-2015-9414 | WordPress Symposium <=15.8.1 - Cross-Site Scripting | wp-symposium | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000126 | WordPress Admin Font Editor <=1.8 - Cross-Site Scripting | admin-font-editor | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000127 | WordPress AJAX Random Post <=2.00 - Cross-Site Scripting | ajax-random-post | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000128 | WordPress anti-plagiarism <=3.60 - Cross-Site Scripting | anti-plagiarism | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000129 | WordPress defa-online-image-protector <=3.3 - Cross-Site Scripting | defa-online-image-protector | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000130 | WordPress e-search <=1.0 - Cross-Site Scripting | e-search | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000131 | WordPress e-search <=1.0 - Cross-Site Scripting | esearch | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000132 | WordPress enhanced-tooltipglossary 3.2.8 - Cross-Site Scripting | tooltip_glossary | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000133 | WordPress forget-about-shortcode-buttons 1.1.1 - Cross-Site Scripting | forget_about_shortcode_buttons | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000134 | WordPress HDW Video Gallery <=1.2 - Cross-Site Scripting | hdw-tube | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000135 | WordPress HDW Video Gallery <=1.2 - Cross-Site Scripting | hdw-tube | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000136 | WordPress heat-trackr 1.0 - Cross-Site Scripting | heat-trackr | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000137 | WordPress Hero Maps Pro 2.1.0 - Cross-Site Scripting | hero-maps-pro | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000138 | WordPress Admin Font Editor <=1.8 - Cross-Site Scripting | indexisto | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000139 | WordPress Infusionsoft Gravity Forms <=1.5.11 - Cross-Site Scripting | infusionsoft | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000140 | WordPress New Year Firework <=1.1.9 - Cross-Site Scripting | new-year-firework | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000141 | WordPress Page Layout builder v1.9.3 - Cross-Site Scripting | page-layout-builder | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000142 | WordPress MW Font Changer <=4.2.5 - Cross-Site Scripting | parsi-font | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000143 | WordPress Photoxhibit 2.1.8 - Cross-Site Scripting | photoxhibit | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000146 | WordPress Pondol Form to Mail <=1.1 - Cross-Site Scripting | pondol-formmail | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000148 | WordPress S3 Video <=0.983 - Cross-Site Scripting | s3-video | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000149 | WordPress Simpel Reserveren <=3.5.2 - Cross-Site Scripting | simpel-reserveren | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000152 | WordPress Tidio-form <=1.0 - Cross-Site Scripting | tidio-form | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000153 | WordPress Tidio Gallery <=1.1 - Cross-Site Scripting | tidio-gallery | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000154 | WordPress WHIZZ <=1.0.7 - Cross-Site Scripting | whizz | 6.1 | MEDIUM | 341266 |
| CVE-2016-1000155 | WordPress WPSOLR <=8.6 - Cross-Site Scripting | wpsolr-search-engine | 6.1 | MEDIUM | 341266 |
| CVE-2016-10973 | Brafton WordPress Plugin < 3.4.8 - Cross-Site Scripting | brafton | 6.1 | medium | 347198 |
| CVE-2016-4975 | Apache mod_userdir CRLF injection | http_server | 6.1 | medium | 330708 |
| CVE-2016-7981 | SPIP <3.1.2 - Cross-Site Scripting | spip | 6.1 | medium | 341266 |
| CVE-2016-8527 | Aruba Airwave <8.2.3.1 - Cross-Site Scripting | airwave | 6.1 | MEDIUM | 341266 |
| CVE-2017-1000163 | Phoenix Framework - Open Redirect | phoenix | 6.1 | medium | 344365 |
| CVE-2017-11107 | phpLDAPadmin <= 1.2.3 - Reflected XSS | phpldapadmin | 6.1 | MEDIUM | 341266 |
| CVE-2017-11629 | FineCMS <=5.0.10 - Cross-Site Scripting | finecms | 6.1 | medium | 341266 |
| CVE-2017-12583 | DokuWiki - Cross-Site Scripting | dokuwiki | 6.1 | medium | 347198 |
| CVE-2017-12794 | Django Debug Page - Cross-Site Scripting | django | 6.1 | medium | 341266 |
| CVE-2017-14096 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 6.1 | MEDIUM | 330791 |
| CVE-2017-14622 | WordPress 2kb Amazon Affiliates Store <2.1.1 - Cross-Site Scripting | 2kb_amazon_affiliates_store | 6.1 | medium | 341266 |
| CVE-2017-15287 | Dreambox WebControl 2.0.0 - Cross-Site Scripting | bouqueteditor | 6.1 | medium | 341266 |
| CVE-2017-15687 | Logitech Media Server - Cross-Site Scripting | media server | 6.1 | MEDIUM | 347198 |
| CVE-2017-17043 | WordPress Emag Marketplace Connector 1.0 - Cross-Site Scripting | emag_marketplace_connector | 6.1 | MEDIUM | 341266 |
| CVE-2017-17059 | WordPress amtyThumb Posts 8.1.3 - Cross-Site Scripting | amtythumb | 6.1 | MEDIUM | 341266 |
| CVE-2017-17451 | WordPress Mailster <=1.5.4 - Cross-Site Scripting | wp_mailster | 6.1 | MEDIUM | 341266 |
| CVE-2017-18024 | AvantFAX 3.3.3 - Cross-Site Scripting | avantfax | 6.1 | medium | 340147 |
| CVE-2017-18487 | AdPush < 1.44 - Cross-Site Scripting | google_adsense | 6.1 | medium | 341266 |
| CVE-2017-18490 | Contact Form Multi by BestWebSoft < 1.2.1 - Cross-Site Scripting | contact_form_multi | 6.1 | medium | 341266 |
| CVE-2017-18491 | Contact Form by BestWebSoft < 4.0.6 - Cross-Site Scripting | contact_form | 6.1 | medium | 341266 |
| CVE-2017-18492 | Contact Form to DB by BestWebSoft < 1.5.7 - Cross-Site Scripting | contact_form_to_db | 6.1 | medium | 341266 |
| CVE-2017-18493 | Custom Admin Page by BestWebSoft < 0.1.2 - Cross-Site Scripting | custom_admin_page | 6.1 | medium | 341266 |
| CVE-2017-18494 | Custom Search by BestWebSoft < 1.36 - Cross-Site Scripting | custom_search | 6.1 | medium | 341266 |
| CVE-2017-18496 | Htaccess by BestWebSoft < 1.7.6 - Cross-Site Scripting | htaccess | 6.1 | medium | 341266 |
| CVE-2017-18500 | Social Buttons Pack by BestWebSof < 1.1.1 - Cross-Site Scripting | social_buttons_pack | 6.1 | medium | 341266 |
| CVE-2017-18501 | Social Login by BestWebSoft < 0.2 - Cross-Site Scripting | social_login | 6.1 | medium | 341266 |
| CVE-2017-18502 | Subscriber by BestWebSoft < 1.3.5 - Cross-Site Scripting | subscriber | 6.1 | medium | 341266 |
| CVE-2017-18505 | BestWebSoft's Twitter < 2.55 - Cross-Site Scripting | twitter_button | 6.1 | medium | 341266 |
| CVE-2017-18516 | LinkedIn by BestWebSoft < 1.0.5 - Cross-Site Scripting | 6.1 | medium | 341266 | |
| CVE-2017-18517 | Pinterest by BestWebSoft < 1.0.5 - Cross-Site Scripting | 6.1 | medium | 341266 | |
| CVE-2017-18518 | SMTP by BestWebSoft < 1.1.0 - Cross-Site Scripting | smtp | 6.1 | medium | 341266 |
| CVE-2017-18527 | Pagination by BestWebSoft < 1.0.7 - Cross-Site Scripting | pagination | 6.1 | medium | 341266 |
| CVE-2017-18528 | PDF & Print by BestWebSoft < 1.9.4 - Cross-Site Scripting | pdf_&_print | 6.1 | medium | 341266 |
| CVE-2017-18529 | PromoBar by BestWebSoft < 1.1.1 - Cross-Site Scripting | promobar | 6.1 | medium | 341266 |
| CVE-2017-18530 | Rating by BestWebSoft < 0.2 - Cross-Site Scripting | rating | 6.1 | medium | 341266 |
| CVE-2017-18532 | Realty by BestWebSoft < 1.1.0 - Cross-Site Scripting | realty | 6.1 | medium | 341266 |
| CVE-2017-18536 | WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting | stop_user_enumeration | 6.1 | medium | 341266 |
| CVE-2017-18537 | Visitors Online by BestWebSoft < 1.0.0 - Cross-Site Scripting | visitors_online | 6.1 | medium | 341266 |
| CVE-2017-18542 | Zendesk Help Center by BestWebSoft < 1.0.5 - Cross-Site Scripting | zendesk_help_center | 6.1 | medium | 341266 |
| CVE-2017-18556 | Google Analytics by BestWebSoft < 1.7.1 - Cross-Site Scripting | google_analytics | 6.1 | medium | 341266 |
| CVE-2017-18557 | Google Maps by BestWebSoft < 1.3.6 - Cross-Site Scripting | google_maps | 6.1 | medium | 341266 |
| CVE-2017-18558 | Testimonials by BestWebSoft < 0.1.9 - Cross-Site Scripting | testimonials | 6.1 | medium | 341266 |
| CVE-2017-18562 | Error Log Viewer by BestWebSoft < 1.0.6 - Cross-Site Scripting | error_log_viewer | 6.1 | medium | 341266 |
| CVE-2017-18564 | Sender by BestWebSoft < 1.2.1 - Cross-Site Scripting | sender | 6.1 | medium | 341266 |
| CVE-2017-18565 | Updater by BestWebSoft < 1.35 - Cross-Site Scripting | updater | 6.1 | medium | 341266 |
| CVE-2017-18566 | User Role by BestWebSoft < 1.5.6 - Cross-Site Scripting | user_role | 6.1 | medium | 341266 |
| CVE-2017-18590 | Timesheet Plugin < 0.1.5 - Cross-Site Scripting | timesheet | 6.1 | MEDIUM | 341266, 377360 |
| CVE-2017-18598 | WordPress Qards - Cross-Site Scripting | qards | 6.1 | MEDIUM | 393749 |
| CVE-2017-3132 | Fortinet FortiOS < 5.6.0 - Cross-Site Scripting | fortios | 6.1 | MEDIUM | 340147, 341266, 347198, 390727, 392648 |
| CVE-2017-3133 | Fortinet FortiOS < 5.6.0 - Cross-Site Scripting | fortios | 6.1 | MEDIUM | 340147, 341266, 347198, 390727, 392648 |
| CVE-2017-5631 | KMCIS CaseAware - Cross-Site Scripting | caseaware | 6.1 | medium | 341266 |
| CVE-2017-5798 | HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion | opencall media platform | 6.1 | MEDIUM | 390726, 392301, 392647 |
| CVE-2017-5868 | OpenVPN Access Server 2.1.4 - CRLF Injection | openvpn_access_server | 6.1 | medium | 330708 |
| CVE-2017-6443 | EPSON TMNet WebConfig 1.00 - Cross-Site Scripting | tmnet webconfig | 6.1 | MEDIUM | 340147 |
| CVE-2017-6478 | MaNGOSWebV4 < 4.0.8 - Cross-Site Scripting | - | 6.1 | medium | 341266 |
| CVE-2017-7391 | Magmi 0.7.22 - Cross-Site Scripting | magmi | 6.1 | medium | 341266 |
| CVE-2017-7855 | IceWarp WebMail 11.3.1.5 - Cross-Site Scripting | server | 6.1 | medium | 347198 |
| CVE-2017-9140 | Reflected XSS - Telerik Reporting Module | telerik_reporting | 6.1 | medium | 333141 |
| CVE-2017-9288 | WordPress Raygun4WP <=1.8.0 - Cross-Site Scripting | raygun4wp | 6.1 | MEDIUM | 341266 |
| CVE-2017-9506 | Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery | oauth | 6.1 | medium | 382291 |
| CVE-2017-9979 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | 6.1 | MEDIUM | 392301 |
| CVE-2018-1000129 | Jolokia 1.3.7 - Cross-Site Scripting | jolokia | 6.1 | medium | 347198 |
| CVE-2018-10095 | Dolibarr <7.0.2 - Cross-Site Scripting | dolibarr | 6.1 | medium | 341266 |
| CVE-2018-10230 | Zend Server <9.13 - Cross-Site Scripting | zend_server | 6.1 | medium | 341266 |
| CVE-2018-10383 | Lantronix SecureLinx Spider (SLS) 2.2+ - Cross-Site Scripting | securelinx_spider_firmware | 6.1 | MEDIUM | 333141 |
| CVE-2018-11227 | Monstra CMS <=3.0.4 - Cross-Site Scripting | monstra_cms | 6.1 | medium | 333141 |
| CVE-2018-11709 | WordPress wpForo Forum <= 1.4.11 - Cross-Site Scripting | wpforo_forum | 6.1 | medium | 341266 |
| CVE-2018-12111 | Canon PrintMe EFI - Cross-Site Scripting | efi printme | 6.1 | MEDIUM | 347198 |
| CVE-2018-12300 | Seagate NAS OS 4.3.15.1 - Open Redirect | nas_os | 6.1 | medium | 340163 |
| CVE-2018-12998 | Zoho manageengine - Cross-Site Scripting | firewall_analyzer | 6.1 | medium | 341266 |
| CVE-2018-13380 | Fortinet FortiOS - Cross-Site Scripting | fortios | 6.1 | medium | 341266, 347198 |
| CVE-2018-14013 | Synacor Zimbra Collaboration Suite Collaboration <8.8.11 - Cross-Site Scripting | zimbra_collaboration_suite | 6.1 | medium | 341266 |
| CVE-2018-16139 | BIBLIOsoft BIBLIOpac 2008 - Cross-Site Scripting | bibliopac | 6.1 | medium | 341266 |
| CVE-2018-16833 | ManageEngine Desktop Central 10.0.271 - Cross-Site Scripting | manageengine desktop central | 6.1 | MEDIUM | 333141 |
| CVE-2018-16979 | Monstra CMS 3.0.4 - HTTP Header Injection | monstra | 6.1 | medium | 330708 |
| CVE-2018-17082 | Apache2 - Transfer-Encoding Chunked XSS | php | 6.1 | medium | 392301 |
| CVE-2018-17310 | RICOH MP C1803 JPN Printer - Cross-Site Scripting | mp c1803 jpn firmware | 6.1 | MEDIUM | 350147 |
| CVE-2018-17313 | RICOH MP C1803 JPN Printer - Cross-Site Scripting | mp c307 firmware | 6.1 | MEDIUM | 350147 |
| CVE-2018-17587 | Airties AIR5342 1.0.0.18 - Cross-Site Scripting | air 5750 firmware | 6.1 | MEDIUM | 341266 |
| CVE-2018-17588 | Airties AIR5342 1.0.0.18 - Cross-Site Scripting | air 5021 firmware | 6.1 | MEDIUM | 341266 |
| CVE-2018-17590 | Airties AIR5342 1.0.0.18 - Cross-Site Scripting | air 5442 firmware | 6.1 | MEDIUM | 341266 |
| CVE-2018-17591 | Airties AIR5342 1.0.0.18 - Cross-Site Scripting | air 5343v2 firmware | 6.1 | MEDIUM | 341266 |
| CVE-2018-17593 | Airties AIR5342 1.0.0.18 - Cross-Site Scripting | air 5453 firmware | 6.1 | MEDIUM | 341266 |
| CVE-2018-18069 | WordPress sitepress-multilingual-cms 3.6.3 - Cross-Site Scripting | wpml | 6.1 | medium | 392301 |
| CVE-2018-18570 | Planon <Live Build 41 - Cross-Site Scripting | planon | 6.1 | medium | 341266 |
| CVE-2018-18608 | DedeCMS 5.7 SP2 - Cross-Site Scripting | dedecms | 6.1 | medium | 341266 |
| CVE-2018-18775 | Microstrategy Web 7 - Cross-Site Scripting | microstrategy_web | 6.1 | medium | 341266 |
| CVE-2018-19136 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 6.1 | medium | 341266 |
| CVE-2018-19137 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 6.1 | medium | 341266 |
| CVE-2018-19287 | WordPress Ninja Forms <3.3.18 - Cross-Site Scripting | ninja_forms | 6.1 | medium | 347198 |
| CVE-2018-19439 | Oracle Secure Global Desktop Administration Console 4.4 - Cross-Site Scripting | secure_global_desktop | 6.1 | medium | 341266 |
| CVE-2018-19877 | Adiscon LogAnalyzer <4.1.7 - Cross-Site Scripting | loganalyzer | 6.1 | medium | 341266 |
| CVE-2018-19933 | Bolt CMS < 3.6.2 - Cross-Site Scripting | bolt cms | 6.1 | MEDIUM | 340147 |
| CVE-2018-20462 | WordPress JSmol2WP <=1.07 - Cross-Site Scripting | jsmol2wp | 6.1 | MEDIUM | 341266 |
| CVE-2018-20503 | SirsiDynix e-Library 3.5.x - Cross-Site Scripting | 8100l/8 firmware | 6.1 | MEDIUM | 340147 |
| CVE-2018-20824 | Atlassian Jira WallboardServlet <7.13.1 - Cross-Site Scripting | jira | 6.1 | medium | 347198 |
| CVE-2018-5230 | Atlassian Jira Confluence - Cross-Site Scripting | jira | 6.1 | medium | 340112 |
| CVE-2018-5233 | Grav CMS <1.3.0 - Cross-Site Scripting | grav_cms | 6.1 | medium | 341266 |
| CVE-2018-5316 | WordPress SagePay Server Gateway for WooCommerce <1.0.9 - Cross-Site Scripting | sagepay_server_gateway_for_woocommerce | 6.1 | medium | 341266 |
| CVE-2018-5715 | SugarCRM 3.5.1 - Cross-Site Scripting | sugarcrm | 6.1 | medium | 341266 |
| CVE-2018-7203 | TwonkyMedia Server 7.0.11-8.5 - Persistent Cross-Site Scripting | twonky server | 6.1 | MEDIUM | 340147 |
| CVE-2018-7653 | YzmCMS v3.6 - Cross-Site Scripting | yzmcms | 6.1 | medium | 347198 |
| CVE-2018-8006 | Apache ActiveMQ <=5.15.5 - Cross-Site Scripting | activemq | 6.1 | medium | 341266 |
| CVE-2018-8024 | Apache Spark UI - Cross-Site Scripting | spark | 6.1 | medium | 341266 |
| CVE-2019-0221 | Apache Tomcat - Cross-Site Scripting | tomcat | 6.1 | medium | 341266 |
| CVE-2019-10092 | Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting | http_server | 6.1 | medium | 344365 |
| CVE-2019-1010287 | Timesheet Next Gen <=1.5.3 - Cross-Site Scripting | timesheet_next_gen | 6.1 | medium | 340147 |
| CVE-2019-10475 | Jenkins build-metrics 1.3 - Cross-Site Scripting | build-metrics | 6.1 | medium | 347198 |
| CVE-2019-11398 | UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scripting | ulicms | 6.1 | MEDIUM | 342259 |
| CVE-2019-11844 | RICOH SP 4520DN Printer - HTML Injection | sp 4520dn firmware | 6.1 | MEDIUM | 350147 |
| CVE-2019-11845 | RICOH SP 4510DN Printer - HTML Injection | sp 4510dn firmware | 6.1 | MEDIUM | 350147 |
| CVE-2019-12461 | WebPort 1.19.1 - Cross-Site Scripting | web_port | 6.1 | medium | 341266 |
| CVE-2019-12581 | Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting | uag2100 | 6.1 | medium | 341266 |
| CVE-2019-12935 | Shopware < 5.5.8 - Cross-Site Scripting | shopware | 6.1 | MEDIUM | 341266 |
| CVE-2019-13392 | MindPalette NateMail 3.0.15 - Cross-Site Scripting | natemail | 6.1 | medium | 342259 |
| CVE-2019-14427 | Ultimate Loan Manager 2.0 - Cross-Site Scripting | ultimate loan manager | 6.1 | MEDIUM | 390585 |
| CVE-2019-14470 | WordPress UserPro 4.9.32 - Cross-Site Scripting | instagram-php-api | 6.1 | MEDIUM | 347198 |
| CVE-2019-14696 | Open-School 3.0/Community Edition 2.3 - Cross-Site Scripting | open-school | 6.1 | medium | 341266 |
| CVE-2019-14789 | Custom 404 Pro < 3.2.8 - Cross-Site Scripting | custom_404_pro | 6.1 | medium | 347198 |
| CVE-2019-14950 | WP Live Chat Support <= 8.0.27 — Stored Cross-Site Scripting | live_chat | 6.1 | medium | 380026 |
| CVE-2019-14974 | SugarCRM Enterprise 9.0.0 - Cross-Site Scripting | sugarcrm | 6.1 | medium | 340112 |
| CVE-2019-15501 | L-Soft LISTSERV <16.5-2018a - Cross-Site Scripting | listserv | 6.1 | medium | 341266 |
| CVE-2019-15713 | WordPress My Calendar <= 3.1.9 - Cross-Site Scripting | my_calendar | 6.1 | MEDIUM | 341266 |
| CVE-2019-15811 | DomainMOD <=4.13.0 - Cross-Site Scripting | domainmod | 6.1 | medium | 333141 |
| CVE-2019-15889 | WordPress Download Manager <2.9.94 - Cross-Site Scripting | wordpress_download_manager | 6.1 | MEDIUM | 341266 |
| CVE-2019-16332 | WordPress API Bearer Auth <20190907 - Cross-Site Scripting | api_bearer_auth | 6.1 | MEDIUM | 341266 |
| CVE-2019-16525 | WordPress Checklist <1.1.9 - Cross-Site Scripting | checklist | 6.1 | MEDIUM | 341266 |
| CVE-2019-16931 | WordPress Visualizer <3.3.1 - Cross-Site Scripting | visualizer | 6.1 | MEDIUM | 340147 |
| CVE-2019-18859 | Digi AnywhereUSB 14 - Reflective Cross-Site Scripting | anywhereusb/14 firmware | 6.1 | MEDIUM | 341266, 390727, 392648 |
| CVE-2019-18957 | MicroStrategy Library <11.1.3 - Cross-Site Scripting | microstrategy_library | 6.1 | medium | 347198 |
| CVE-2019-19134 | WordPress Hero Maps Premium <=2.2.1 - Cross-Site Scripting | hero_maps_premium | 6.1 | medium | 341266 |
| CVE-2019-19368 | Rumpus FTP Web File Manager 8.2.9.1 - Cross-Site Scripting | rumpus | 6.1 | medium | 342259 |
| CVE-2019-1943 | CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities | sg200-50 firmware | 6.1 | MEDIUM | 390727, 392301, 392648 |
| CVE-2019-19908 | phpMyChat-Plus 1.98 - Cross-Site Scripting | phpmychat-plus | 6.1 | medium | 341266 |
| CVE-2019-20141 | WordPress Laborator Neon Theme 2.0 - Cross-Site Scripting | neon | 6.1 | medium | 347198 |
| CVE-2019-20210 | WordPress CTHthemes - Cross-Site Scripting | citybook | 6.1 | medium | 341266 |
| CVE-2019-3402 | Jira < 8.1.1 - Cross-Site Scripting | jira | 6.1 | medium | 341266 |
| CVE-2019-3911 | LabKey Server Community Edition <18.3.0 - Cross-Site Scripting | labkey_server | 6.1 | medium | 341266 |
| CVE-2019-6112 | WordPress Sell Media 2.4.1 - Cross-Site Scripting | sell_media | 6.1 | medium | 341266 |
| CVE-2019-6802 | Pypiserver <1.2.5 - Carriage Return Line Feed Injection | pypiserver | 6.1 | medium | 330708 |
| CVE-2019-7219 | Zarafa WebApp <=2.0.1.47791 - Cross-Site Scripting | webaccess | 6.1 | medium | 347198 |
| CVE-2019-7255 | Linear eMerge E3 - Cross-Site Scripting | linear_emerge_essential_firmware | 6.1 | medium | 341266 |
| CVE-2019-7438 | JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting | jiofi 4g m2s firmware | 6.1 | MEDIUM | 340149 |
| CVE-2019-8937 | HotelDruid 2.3.0 - Cross-Site Scripting | hoteldruid | 6.1 | medium | 341266 |
| CVE-2019-9553 | Bolt CMS 3.6.4 - Cross-Site Scripting | bolt | 6.1 | MEDIUM | 340148 |
| CVE-2019-9591 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 | MEDIUM | 341266, 390727, 392648 |
| CVE-2019-9592 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 | MEDIUM | 341266, 390727, 392648 |
| CVE-2019-9593 | ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities | connect onsite | 6.1 | MEDIUM | 341266, 390727, 392648 |
| CVE-2019-9912 | WP Google Maps < 7.10.43 - Cross-Site Scripting | wp_go_maps | 6.1 | MEDIUM | 347198 |
| CVE-2020-11930 | WordPress GTranslate <2.8.52 - Cross-Site Scripting | translate_wordpress_with_gtranslate | 6.1 | medium | 341266 |
| CVE-2020-12054 | WordPress Catch Breadcrumb <1.5.4 - Cross-Site Scripting | catch_breadcrumb | 6.1 | medium | 347198 |
| CVE-2020-13121 | Submitty <= 20.04.01 - Open Redirect | submitty | 6.1 | medium | 340162 |
| CVE-2020-13258 | Contentful <=2020-05-21 - Cross-Site Scripting | python_example | 6.1 | medium | 341266 |
| CVE-2020-13483 | Bitrix24 <=20.0.0 - Cross-Site Scripting | bitrix24 | 6.1 | medium | 344363, 390722 |
| CVE-2020-13820 | Extreme Management Center 8.4.1.24 - Cross-Site Scripting | extreme_management_center | 6.1 | medium | 333141 |
| CVE-2020-14413 | NeDi 1.9C - Cross-Site Scripting | nedi | 6.1 | medium | 347198 |
| CVE-2020-15500 | TileServer GL <=3.0.0 - Cross-Site Scripting | tileservergl | 6.1 | medium | 333141 |
| CVE-2020-15599 | Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting | victor cms | 6.1 | MEDIUM | 340147 |
| CVE-2020-15718 | RosarioSIS 6.7.2 - Cross-Site Scripting | rosariosis | 6.1 | medium | 347198 |
| CVE-2020-17362 | Nova Lite < 1.3.9 - Cross-Site Scripting | nova_lite | 6.1 | medium | 341266 |
| CVE-2020-18268 | Z-Blog <=1.5.2 - Open Redirect | z-blogphp | 6.1 | medium | 390500, 390501 |
| CVE-2020-19282 | Jeesns 1.4.2 - Cross-Site Scripting | jeesns | 6.1 | medium | 341266 |
| CVE-2020-19283 | Jeesns 1.4.2 - Cross-Site Scripting | jeesns | 6.1 | medium | 341266 |
| CVE-2020-19295 | Jeesns 1.4.2 - Cross-Site Scripting | jeesns | 6.1 | medium | 341266 |
| CVE-2020-1943 | Apache OFBiz <=16.11.07 - Cross-Site Scripting | ofbiz | 6.1 | medium | 347198 |
| CVE-2020-19515 | qdPM 9.1 - Cross-site Scripting | qdpm | 6.1 | medium | 347198 |
| CVE-2020-2096 | Jenkins Gitlab Hook <=1.4.2 - Cross-Site Scripting | gitlab_hook | 6.1 | medium | 341266 |
| CVE-2020-23517 | Aryanic HighMail (High CMS) - Cross-Site Scripting | high_cms | 6.1 | medium | 341266 |
| CVE-2020-24223 | Mara CMS 7.5 - Cross-Site Scripting | mara_cms | 6.1 | medium | 341266 |
| CVE-2020-24609 | Savsoft Quiz 5 - Stored Cross-Site Scripting | savsoft quiz | 6.1 | MEDIUM | 340147 |
| CVE-2020-24701 | OX Appsuite - Cross-Site Scripting | open-xchange_appsuite | 6.1 | medium | 341266 |
| CVE-2020-24902 | Quixplorer <=2.4.1 - Cross-Site Scripting | quixplorer | 6.1 | medium | 341266 |
| CVE-2020-24903 | Cute Editor for ASP.NET 6.4 - Cross-Site Scripting | cute_editor | 6.1 | medium | 341266 |
| CVE-2020-25495 | SCO Openserver 5.0.7 - 'section' Reflected XSS | openserver | 6.1 | MEDIUM | 341266 |
| CVE-2020-25864 | HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site Scripting | consul | 6.1 | medium | 392301 |
| CVE-2020-26153 | Event Espresso Core-Reg 4.10.7.p - Cross-Site Scripting | event_espresso | 6.1 | MEDIUM | 341266 |
| CVE-2020-27735 | Wing FTP 6.4.4 - Cross-Site Scripting | wing_ftp_server | 6.1 | medium | 350148 |
| CVE-2020-27982 | IceWarp WebMail 11.4.5.0 - Cross-Site Scripting | mail_server | 6.1 | medium | 347198 |
| CVE-2020-28351 | Mitel ShoreTel 19.46.1802.0 Devices - Cross-Site Scripting | shoretel | 6.1 | MEDIUM | 341266 |
| CVE-2020-29164 | PacsOne Server <7.1.1 - Cross-Site Scripting | pacsone_server | 6.1 | medium | 333141 |
| CVE-2020-29395 | Wordpress EventON Calendar 3.0.5 - Cross-Site Scripting | eventon | 6.1 | MEDIUM | 347198 |
| CVE-2020-3580 | Cisco ASA/FTD Software - Cross-Site Scripting | firepower_threat_defense | 6.1 | medium | 333141 |
| CVE-2020-36510 | WordPress 15Zine <3.3.0 - Cross-Site Scripting | 15zine | 6.1 | MEDIUM | 341266 |
| CVE-2020-36731 | Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update | flexible_checkout_fields_for_woocommerce | 6.1 | MEDIUM | 377360 |
| CVE-2020-5191 | Hospital Management System 4.0 - Persistent Cross-Site Scripting | hospital management system | 6.1 | MEDIUM | 342259 |
| CVE-2020-6171 | CLink Office 2.0 - Cross-Site Scripting | clink_office | 6.1 | medium | 341266 |
| CVE-2020-7107 | WordPress Ultimate FAQ <1.8.30 - Cross-Site Scripting | ultimate_faq | 6.1 | MEDIUM | 347198 |
| CVE-2020-8115 | Revive Adserver <=5.0.3 - Cross-Site Scripting | revive_adserver | 6.1 | medium | 350148 |
| CVE-2020-8191 | Citrix ADC/Gateway - Cross-Site Scripting | application_delivery_controller_firmware | 6.1 | medium | 340147 |
| CVE-2020-8512 | IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting | icewarp_server | 6.1 | medium | 347198 |
| CVE-2020-9344 | Jira Subversion ALM for Enterprise <8.8.2 - Cross-Site Scripting | subversion_application_lifecycle_management | 6.1 | medium | 341266 |
| CVE-2021-20137 | Gryphon Tower - Cross-Site Scripting | gryphon_tower | 6.1 | medium | 347198 |
| CVE-2021-20323 | Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting | keycloak | 6.1 | MEDIUM | 333141 |
| CVE-2021-20792 | WordPress Quiz and Survey Master <7.1.14 - Cross-Site Scripting | quiz_and_survey_master | 6.1 | medium | 341266 |
| CVE-2021-21799 | Advantech R-SeeNet 2.4.12 - Cross-Site Scripting | r-seenet | 6.1 | medium | 341266 |
| CVE-2021-21800 | Advantech R-SeeNet 2.4.12 - Cross-Site Scripting | r-seenet | 6.1 | medium | 341266 |
| CVE-2021-21801 | Advantech R-SeeNet - Cross-Site Scripting | r-seenet | 6.1 | medium | 347198 |
| CVE-2021-21802 | Advantech R-SeeNet - Cross-Site Scripting | r-seenet | 6.1 | medium | 347198 |
| CVE-2021-21803 | Advantech R-SeeNet - Cross-Site Scripting | r-seenet | 6.1 | medium | 347198 |
| CVE-2021-24165 | WordPress Ninja Forms <3.4.34 - Open Redirect | ninja_forms | 6.1 | MEDIUM | 377360 |
| CVE-2021-24169 | WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scripting | advanced_order_export | 6.1 | medium | 341266 |
| CVE-2021-24210 | WordPress PhastPress <1.111 - Open Redirect | phastpress | 6.1 | medium | 340162 |
| CVE-2021-24213 | GiveWP <= 2.9.7 - Cross-Site Scripting | givewp | 6.1 | MEDIUM | 377360 |
| CVE-2021-24214 | WordPress OpenID Connect Generic Client 3.8.0-3.8.1 - Cross-Site Scripting | openid_connect_generic_client | 6.1 | MEDIUM | 341266 |
| CVE-2021-24235 | WordPress Goto Tour & Travel Theme <2.0 - Cross-Site Scripting | goto | 6.1 | medium | 347198 |
| CVE-2021-24237 | WordPress Realteo <=1.2.3 - Cross-Site Scripting | findeo | 6.1 | medium | 347198 |
| CVE-2021-24245 | WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS) | stop spammers | 6.1 | MEDIUM | 333141 |
| CVE-2021-24274 | WordPress Supsystic Ultimate Maps <1.2.5 - Cross-Site Scripting | ultimate_maps | 6.1 | MEDIUM | 341266 |
| CVE-2021-24275 | Popup by Supsystic <1.10.5 - Cross-Site scripting | popup | 6.1 | medium | 341266 |
| CVE-2021-24276 | WordPress Supsystic Contact Form <1.7.15 - Cross-Site Scripting | contact_form | 6.1 | medium | 341266 |
| CVE-2021-24286 | WordPress Plugin Redirect 404 to Parent 1.3.0 - Cross-Site Scripting | redirect_404_to_parent | 6.1 | MEDIUM | 377360 |
| CVE-2021-24287 | WordPress Select All Categories and Taxonomies <1.3.2 - Cross-Site Scripting | select_all_categories_and_taxonomies,_change_checkbox_to_radio_buttons | 6.1 | MEDIUM | 377360 |
| CVE-2021-24291 | WordPress Photo Gallery by 10Web <1.5.69 - Cross-Site Scripting | photo_gallery | 6.1 | medium | 347198 |
| CVE-2021-24298 | WordPress Simple Giveaways <2.36.2 - Cross-Site Scripting | simple_giveaways | 6.1 | MEDIUM | 341266 |
| CVE-2021-24300 | WordPress WooCommerce <1.13.22 - Cross-Site Scripting | product_slider_for_woocommerce | 6.1 | medium | 347198 |
| CVE-2021-24316 | WordPress Mediumish Theme <=1.0.47 - Cross-Site Scripting | mediumish | 6.1 | medium | 341266 |
| CVE-2021-24320 | WordPress Bello Directory & Listing Theme <1.6.0 - Cross-Site Scripting | bello | 6.1 | MEDIUM | 341266 |
| CVE-2021-24335 | WordPress Car Repair Services & Auto Mechanic Theme <4.0 - Cross-Site Scripting | car_repair_services_&_auto_mechanic | 6.1 | MEDIUM | 341266 |
| CVE-2021-24342 | WordPress JNews Theme <8.0.6 - Cross-Site Scripting | jnews | 6.1 | MEDIUM | 340147 |
| CVE-2021-24364 | WordPress Jannah Theme <5.4.4 - Cross-Site Scripting | jannah | 6.1 | MEDIUM | 341266 |
| CVE-2021-24387 | WordPress Pro Real Estate 7 Theme <3.1.1 - Cross-Site Scripting | real_estate_7 | 6.1 | medium | 341266 |
| CVE-2021-24389 | WordPress FoodBakery <2.2 - Cross-Site Scripting | foodbakery | 6.1 | medium | 341266 |
| CVE-2021-24407 | WordPress Jannah Theme <5.4.5 - Cross-Site Scripting | jannah | 6.1 | MEDIUM | 392301 |
| CVE-2021-24409 | Prismatic < 2.8 - Cross-Site Scripting | prismatic | 6.1 | medium | 347198 |
| CVE-2021-24435 | WordPress Titan Framework plugin <= 1.12.1 - Cross-Site Scripting | titan_framework | 6.1 | medium | 333141, 347198 |
| CVE-2021-24436 | WordPress W3 Total Cache <2.1.4 - Cross-Site Scripting | w3_total_cache | 6.1 | medium | 341266 |
| CVE-2021-24452 | WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting | w3_total_cache | 6.1 | MEDIUM | 377360 |
| CVE-2021-24488 | WordPress Post Grid <2.1.8 - Cross-Site Scripting | post_grid | 6.1 | medium | 347198 |
| CVE-2021-24495 | Wordpress Marmoset Viewer <1.9.3 - Cross-Site Scripting | marmoset_viewer | 6.1 | medium | 347198 |
| CVE-2021-24498 | WordPress Calendar Event Multi View <1.4.01 - Cross-Site Scripting | calendar_event_multi_view | 6.1 | medium | 347198 |
| CVE-2021-24510 | WordPress MF Gig Calendar <=1.1 - Cross-Site Scripting | mf_gig_calendar | 6.1 | medium | 341266 |
| CVE-2021-24522 | ProfilePress < 3.1.11 - Cross-Site Scripting | profilepress | 6.1 | MEDIUM | 341266 |
| CVE-2021-24563 | WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated) | frontend uploader | 6.1 | MEDIUM | 392301 |
| CVE-2021-24657 | Limit Login Attempts WordPress - Stored Cross-site Scripting | limit login attempts | 6.1 | MEDIUM | 377360 |
| CVE-2021-24838 | WordPress AnyComment <0.3.5 - Open Redirect | anycomment | 6.1 | medium | 390145 |
| CVE-2021-24875 | WordPress eCommerce Product Catalog <3.0.39 - Cross-Site Scripting | ecommerce_product_catalog | 6.1 | medium | 347198 |
| CVE-2021-24876 | Registrations for The Events Calendar < 2.7.5 - Authenticated Reflected Cross-Site Scripting | registrations_for_the_events_calendar | 6.1 | MEDIUM | 377360 |
| CVE-2021-24910 | WordPress Transposh Translation <1.0.8 - Cross-Site Scripting | transposh_wordpress_translation | 6.1 | medium | 347198 |
| CVE-2021-24926 | WordPress Domain Check <1.0.17 - Cross-Site Scripting | domain_check | 6.1 | medium | 341266 |
| CVE-2021-24934 | Visual CSS Style Editor < 7.5.4 - Cross-Site Scripting | visual_css_style_editor | 6.1 | medium | 341266 |
| CVE-2021-24940 | WordPress Persian Woocommerce <=5.8.0 - Cross-Site Scripting | persian-woocommerce | 6.1 | medium | 347198 |
| CVE-2021-24956 | Blog2Social < 6.8.7 - Cross-Site Scripting | blog2social | 6.1 | medium | 341266 |
| CVE-2021-24979 | Paid Memberships Pro < 2.6.6 - Cross-Site Scripting | paid_memberships_pro | 6.1 | medium | 347198 |
| CVE-2021-24987 | WordPress Super Socializer <7.13.30 - Cross-Site Scripting | super_socializer | 6.1 | medium | 347198 |
| CVE-2021-25008 | The Code Snippets WordPress Plugin < 2.14.3 - Cross-Site Scripting | code_snippets | 6.1 | medium | 347198 |
| CVE-2021-25016 | Chaty < 2.8.2 - Cross-Site Scripting | chaty | 6.1 | medium | 347198 |
| CVE-2021-25055 | WordPress FeedWordPress < 2022.0123 - Authenticated Cross-Site Scripting | feedwordpress | 6.1 | medium | 347198 |
| CVE-2021-25063 | WordPress Contact Form 7 Skins <=2.5.0 - Cross-Site Scripting | contact_form_7_skins | 6.1 | medium | 347198 |
| CVE-2021-25074 | WordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open Redirect | webp_converter_for_media | 6.1 | medium | 340162 |
| CVE-2021-25078 | Affiliates Manager < 2.9.0 - Cross Site Scripting | affiliates_manager | 6.1 | medium | 347198 |
| CVE-2021-25079 | Contact Form Entries < 1.2.4 - Cross-Site Scripting | contact_form_entries | 6.1 | medium | 341266 |
| CVE-2021-25085 | WOOF WordPress plugin - Cross-Site Scripting | woocommerce_products_filter | 6.1 | medium | 347198 |
| CVE-2021-25104 | WordPress Ocean Extra <1.9.5 - Cross-Site Scripting | ocean_extra | 6.1 | medium | 341266 |
| CVE-2021-25112 | WordPress WHMCS Bridge <6.4b - Cross-Site Scripting | whmcs_bridge | 6.1 | medium | 347198 |
| CVE-2021-25120 | Easy Social Feed < 6.2.7 - Cross-Site Scripting | easy_social_feed | 6.1 | medium | 341266 |
| CVE-2021-25161 | Aruba Instant Access Point (IAP) - Cross-Site Scripting | aruba-instant-access-point | 6.1 | medium | 390722 |
| CVE-2021-26247 | Cacti - Cross-Site Scripting | cacti | 6.1 | medium | 341266 |
| CVE-2021-26475 | EPrints 3.4.2 - Cross-Site Scripting | eprints | 6.1 | medium | 341266 |
| CVE-2021-26702 | EPrints 3.4.2 - Cross-Site Scripting | eprints | 6.1 | medium | 341266 |
| CVE-2021-26710 | Redwood Report2Web 4.3.4.5 & 4.5.3 - Cross-Site Scripting | report2web | 6.1 | medium | 341266 |
| CVE-2021-26723 | Jenzabar 9.2x-9.2.2 - Cross-Site Scripting | jenzabar | 6.1 | medium | 341266 |
| CVE-2021-26947 | Odoo <= 15.0 - Cross-Site Scripting | odoo | 6.1 | medium | 341266, 347198 |
| CVE-2021-27309 | Clansphere CMS 2011.4 - Cross-Site Scripting | clansphere | 6.1 | medium | 341266 |
| CVE-2021-27310 | Clansphere CMS 2011.4 - Cross-Site Scripting | clansphere | 6.1 | medium | 341266 |
| CVE-2021-27330 | Triconsole Datepicker Calendar <3.77 - Cross-Site Scripting | datepicker_calendar | 6.1 | medium | 341266 |
| CVE-2021-27519 | FUDForum 3.1.0 - Cross-Site Scripting | fudforum | 6.1 | medium | 347198 |
| CVE-2021-27520 | FUDForum 3.1.0 - Cross-Site Scripting | fudforum | 6.1 | medium | 347198 |
| CVE-2021-27695 | openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting | openmaint | 6.1 | MEDIUM | 330791 |
| CVE-2021-29625 | Adminer <=4.8.0 - Cross-Site Scripting | adminer | 6.1 | medium | 341266 |
| CVE-2021-3002 | Seo Panel 4.8.0 - Cross-Site Scripting | seo_panel | 6.1 | medium | 333141 |
| CVE-2021-30049 | SysAid Technologies 20.3.64 b14 - Cross-Site Scripting | sysaid | 6.1 | medium | 341266 |
| CVE-2021-30134 | Php-mod/curl Library <2.3.2 - Cross-Site Scripting | php_curl_class | 6.1 | medium | 347198 |
| CVE-2021-30213 | Knowage Suite 7.3 - Cross-Site Scripting | knowage | 6.1 | medium | 341266 |
| CVE-2021-31537 | SIS Informatik REWE GO SP17 <7.7 - Cross-Site Scripting | sis-rewe_go | 6.1 | medium | 341266 |
| CVE-2021-31589 | BeyondTrust Secure Remote Access Base <=6.0.1 - Cross-Site Scripting | appliance_base_software | 6.1 | medium | 347198 |
| CVE-2021-31682 | WebCTRL OEM <= 6.5 - Cross-Site Scripting | webctrl | 6.1 | medium | 341266 |
| CVE-2021-31862 | SysAid 20.4.74 - Cross-Site Scripting | sysaid | 6.1 | medium | 341266 |
| CVE-2021-32478 | Moodle 3.8-3.10.3 - Reflected XSS & Open Redirect | moodle | 6.1 | medium | 350148 |
| CVE-2021-33904 | Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS) | civic platform | 6.1 | MEDIUM | 390727, 392301, 392648 |
| CVE-2021-34370 | Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS) | civic platform | 6.1 | MEDIUM | 390727, 392301, 392648 |
| CVE-2021-34630 | GTranslate < 2.8.65 - Cross-Site Scripting | gtranslate | 6.1 | medium | 341266 |
| CVE-2021-34640 | WordPress Securimage-WP-Fixed <=3.5.4 - Cross-Site Scripting | securimage-wp-fixed | 6.1 | medium | 341266 |
| CVE-2021-34643 | WordPress Skaut Bazar <1.3.3 - Cross-Site Scripting | skaut-bazar | 6.1 | medium | 341266 |
| CVE-2021-35265 | MaxSite CMS > V106 - Cross-Site Scripting | maxsite_cms | 6.1 | medium | 347198 |
| CVE-2021-35488 | Thruk 2.40-2 - Cross-Site Scripting | thruk | 6.1 | medium | 341266 |
| CVE-2021-36450 | Verint Workforce Optimization 15.2.8.10048 - Cross-Site Scripting | workforce_optimization | 6.1 | medium | 350147 |
| CVE-2021-36646 | KodExplorer - Cross-Site Scripting | kod-explorer | 6.1 | MEDIUM | 341266 |
| CVE-2021-37416 | Zoho ManageEngine ADSelfService Plus <=6103 - Cross-Site Scripting | manageengine_adselfservice_plus | 6.1 | medium | 341266 |
| CVE-2021-37573 | Tiny Java Web Server - Cross-Site Scripting | tiny_java_web_server | 6.1 | medium | 347198 |
| CVE-2021-37833 | Hotel Druid 3.0.2 - Cross-Site Scripting | hoteldruid | 6.1 | medium | 341266 |
| CVE-2021-38702 | Cyberoam NetGenie Cross-Site Scripting | netgenie_c0101b1-20141120-ng11vo_firmware | 6.1 | medium | 341266 |
| CVE-2021-38704 | ClinicCases 7.3.3 Cross-Site Scripting | cliniccases | 6.1 | medium | 341266 |
| CVE-2021-39320 | WordPress Under Construction <1.19 - Cross-Site Scripting | underconstruction | 6.1 | medium | 341266 |
| CVE-2021-39322 | WordPress Easy Social Icons Plugin < 3.0.9 - Cross-Site Scripting | easy_social_icons | 6.1 | medium | 341266 |
| CVE-2021-39350 | FV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site Scripting | fv_flowplayer_video_player | 6.1 | medium | 341266 |
| CVE-2021-40542 | Opensis-Classic 8.0 - Cross-Site Scripting | opensis | 6.1 | medium | 341266 |
| CVE-2021-40868 | Cloudron 6.2 Cross-Site Scripting | cloudron | 6.1 | medium | 341266 |
| CVE-2021-41467 | JustWriting - Cross-Site Scripting | justwriting | 6.1 | MEDIUM | 341266 |
| CVE-2021-41878 | i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS) | i-panel administration system | 6.1 | MEDIUM | 347198 |
| CVE-2021-41951 | Resourcespace - Cross-Site Scripting | resourcespace | 6.1 | medium | 341266 |
| CVE-2021-42551 | NetBiblio WebOPAC - Cross-Site Scripting | netbiblio | 6.1 | medium | 341245, 344370 |
| CVE-2021-42565 | myfactory FMS - Cross-Site Scripting | fms | 6.1 | medium | 341266 |
| CVE-2021-42567 | Apereo CAS Cross-Site Scripting | central_authentication_service | 6.1 | medium | 333141 |
| CVE-2021-43062 | Fortinet FortiMail 7.0.1 - Cross-Site Scripting | fortimail | 6.1 | medium | 347198 |
| CVE-2021-43574 | Atmail 6.5.0 - Cross-Site Scripting | atmail | 6.1 | medium | 341266 |
| CVE-2021-43725 | Spotweb <= 1.5.1 - Cross Site Scripting (Reflected) | spotweb | 6.1 | medium | 341266 |
| CVE-2021-43810 | Admidio - Cross-Site Scripting | admidio | 6.1 | medium | 340112 |
| CVE-2021-45380 | AppCMS - Cross-Site Scripting | appcms | 6.1 | medium | 341266 |
| CVE-2021-45422 | Reprise License Manager 14.2 - Cross-Site Scripting | reprise_license_manager | 6.1 | medium | 341266 |
| CVE-2021-45425 | SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS) | safari montage | 6.1 | MEDIUM | 341266 |
| CVE-2021-46387 | Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS) | zywall 2 plus internet security appliance firmware | 6.1 | MEDIUM | 333141 |
| CVE-2022-0087 | Keystone 6 Login Page - Open Redirect and Cross-Site Scripting | keystone | 6.1 | medium | 333140 |
| CVE-2022-0147 | WordPress Cookie Information/Free GDPR Consent Solution <2.0.8 - Cross-Site Scripting | wp-gdpr-compliance | 6.1 | medium | 347198 |
| CVE-2022-0149 | WooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site Scripting | store_exporter_for_woocommerce | 6.1 | medium | 341266 |
| CVE-2022-0189 | WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting | wp_rss_aggregator | 6.1 | MEDIUM | 377360 |
| CVE-2022-0201 | WordPress Permalink Manager <2.2.15 - Cross-Site Scripting | permalink_manager_lite | 6.1 | medium | 347198 |
| CVE-2022-0206 | WordPress NewStatPress <1.3.6 - Cross-Site Scripting | newstatpress | 6.1 | medium | 347198 |
| CVE-2022-0208 | WordPress Plugin MapPress <2.73.4 - Cross-Site Scripting | mappress | 6.1 | medium | 347198 |
| CVE-2022-0212 | WordPress Spider Calendar <=1.5.65 - Cross-Site Scripting | spidercalendar | 6.1 | medium | 347198 |
| CVE-2022-0234 | WordPress WOOCS < 1.3.7.5 - Cross-Site Scripting | woocs | 6.1 | medium | 347198 |
| CVE-2022-0250 | Redirection for Contact Form 7 < 2.5.0 - Cross-Site Scripting | redirection_for_contact_form_7 | 6.1 | medium | 341266 |
| CVE-2022-0271 | LearnPress <4.1.6 - Cross-Site Scripting | learnpress | 6.1 | medium | 347198 |
| CVE-2022-0346 | WordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code Execution | xml_sitemap_generator | 6.1 | medium | 340165, 347198 |
| CVE-2022-0381 | WordPress Embed Swagger <=1.0.0 - Cross-Site Scripting | embed_swagger | 6.1 | MEDIUM | 350148 |
| CVE-2022-0429 | WP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Cross-Site Scripting | wp_cerber_security,anti-spam&_malware_scan | 6.1 | medium | 347198 |
| CVE-2022-0437 | karma-runner DOM-based Cross-Site Scripting | karma | 6.1 | medium | 340112 |
| CVE-2022-0533 | Ditty (formerly Ditty News Ticker) < 3.0.15 - Cross-Site Scripting | ditty | 6.1 | medium | 347198 |
| CVE-2022-0599 | WordPress Mapping Multiple URLs Redirect Same Page <=5.8 - Cross-Site Scripting | mapping_multiple_urls_redirect_same_page | 6.1 | medium | 347198 |
| CVE-2022-0653 | Wordpress Profile Builder Plugin Cross-Site Scripting | profile_builder | 6.1 | medium | 340112 |
| CVE-2022-0678 | Microweber <1.2.11 - Cross-Site Scripting | microweber | 6.1 | medium | 341266 |
| CVE-2022-0864 | UpdraftPlus < 1.22.9 - Cross-Site Scripting | updraftplus | 6.1 | medium | 341266 |
| CVE-2022-0879 | Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting | - | 6.1 | medium | 347198 |
| CVE-2022-0899 | Header Footer Code Manager < 1.1.24 - Cross-Site Scripting | header_footer_code_manager | 6.1 | medium | 341266 |
| CVE-2022-1007 | WordPress Advanced Booking Calendar <1.7.1 - Cross-Site Scripting | advanced_booking_calendar | 6.1 | medium | 341266 |
| CVE-2022-1168 | WordPress WP JobSearch <1.5.1 - Cross-Site Scripting | jobsearch_wp_job_board | 6.1 | medium | 347198 |
| CVE-2022-1170 | JobMonster < 4.5.2.9 - Cross-Site Scripting | jobmonster | 6.1 | medium | 347198 |
| CVE-2022-1221 | WordPress Gwyn's Imagemap Selector <=0.3.3 - Cross-Site Scripting | gwyn's_imagemap_selector | 6.1 | medium | 341266 |
| CVE-2022-1439 | Microweber <1.2.15 - Cross-Site Scripting | microweber | 6.1 | medium | 347198 |
| CVE-2022-1724 | WordPress Simple Membership <4.1.1 - Cross-Site Scripting | simple_membership | 6.1 | MEDIUM | 341266 |
| CVE-2022-1756 | Newsletter < 7.4.5 - Cross-Site Scripting | newsletter | 6.1 | medium | 347198 |
| CVE-2022-1904 | WordPress Easy Pricing Tables <3.2.1 - Cross-Site Scripting | easy_pricing_tables | 6.1 | medium | 341266 |
| CVE-2022-1906 | WordPress Copyright Proof <=4.16 - Cross-Site-Scripting | copyright_proof | 6.1 | medium | 341266 |
| CVE-2022-1910 | WordPress Shortcodes and Extra Features for Phlox <2.9.8 - Cross-Site Scripting | shortcodes_and_extra_features_for_phlox_theme | 6.1 | medium | 341266 |
| CVE-2022-1933 | WordPress CDI <5.1.9 - Cross Site Scripting | collect_and_deliver_interface_for_woocommerce | 6.1 | medium | 341266 |
| CVE-2022-1937 | WordPress Awin Data Feed <=1.6 - Cross-Site Scripting | awin_data_feed | 6.1 | medium | 341266 |
| CVE-2022-1946 | WordPress Gallery <2.0.0 - Cross-Site Scripting | gallery | 6.1 | medium | 341266 |
| CVE-2022-2130 | Microweber < 1.2.17 - Cross-Site Scripting | microweber | 6.1 | medium | 341266 |
| CVE-2022-2168 | WordPress Download Manager < 3.2.44 - Authenticated Cross-Site Scripting | download_manager | 6.1 | medium | 341266 |
| CVE-2022-2174 | microweber 1.2.18 - Cross-site Scripting | microweber | 6.1 | medium | 341266 |
| CVE-2022-2187 | WordPress Contact Form 7 Captcha <0.1.2 - Cross-Site Scripting | contact_form_7_captcha | 6.1 | medium | 341266 |
| CVE-2022-22242 | Juniper Web Device Manager - Cross-Site Scripting | junos | 6.1 | medium | 341266 |
| CVE-2022-2290 | Trilium <0.52.4 - Cross-Site Scripting | trilium | 6.1 | medium | 347198 |
| CVE-2022-23397 | Cedar Gate EZ-NET <= 6.8.0 - Cross-Site Scripting | ez-net_portal | 6.1 | medium | 347198 |
| CVE-2022-23808 | phpMyAdmin < 5.1.2 - Cross-Site Scripting | phpmyadmin | 6.1 | medium | 341266 |
| CVE-2022-2383 | WordPress Feed Them Social <3.0.1 - Cross-Site Scripting | feed_them_social | 6.1 | MEDIUM | 347198 |
| CVE-2022-24384 | SmarterTools SmarterTrack - Cross-Site Scripting | smartertrack | 6.1 | medium | 347198 |
| CVE-2022-24899 | Contao <4.13.3 - Cross-Site Scripting | contao | 6.1 | medium | 341266 |
| CVE-2022-25323 | ZEROF Web Server 2.0 - Cross-Site Scripting | web_server | 6.1 | medium | 347198 |
| CVE-2022-2599 | WordPress Anti-Malware Security and Brute-Force Firewall <4.21.83 - Cross-Site Scripting | anti-malware_security_and_brute-force_firewall | 6.1 | medium | 347198 |
| CVE-2022-26564 | HotelDruid Hotel Management Software 3.0.3 - Cross-Site Scripting | hoteldruid | 6.1 | medium | 341266 |
| CVE-2022-2733 | Openemr < 7.0.0.1 - Cross-Site Scripting | openemr | 6.1 | medium | 347198 |
| CVE-2022-27926 | Zimbra Collaboration (ZCS) - Cross Site Scripting | collaboration | 6.1 | medium | 347198 |
| CVE-2022-28290 | WordPress Country Selector <1.6.6 - Cross-Site Scripting | wordpress_country_selector | 6.1 | medium | 340130 |
| CVE-2022-28363 | Reprise License Manager 14.2 - Cross-Site Scripting | reprise_license_manager | 6.1 | medium | 347198 |
| CVE-2022-28508 | MantisBT < 2.25.2 - Cross-Site Scripting | - | 6.1 | medium | 341266 |
| CVE-2022-29004 | Diary Management System 1.0 - Cross-Site Scripting | e-diary_management_system | 6.1 | medium | 340147 |
| CVE-2022-29005 | Online Birth Certificate System 1.2 - Stored Cross-Site Scripting | online_birth_certificate_system | 6.1 | medium | 340147 |
| CVE-2022-30489 | Wavlink WN-535G3 - Cross-Site Scripting | wn535g3_firmware | 6.1 | medium | 340147 |
| CVE-2022-30513 | School Dormitory Management System 1.0 - Authenticated Cross-Site Scripting | school_dormitory_management_system | 6.1 | medium | 392301 |
| CVE-2022-30514 | School Dormitory Management System 1.0 - Authenticated Cross-Site Scripting | school_dormitory_management_system | 6.1 | medium | 392301 |
| CVE-2022-3062 | Simple File List < 4.4.12 - Cross Site Scripting | simple-file-list | 6.1 | medium | 347198 |
| CVE-2022-30776 | Atmail 6.5.0 - Cross-Site Scripting | atmail | 6.1 | medium | 341266 |
| CVE-2022-30777 | Parallels H-Sphere 3.6.1713 - Cross-Site Scripting | h-sphere | 6.1 | medium | 341266 |
| CVE-2022-31299 | Haraj 3.7 - Cross-Site Scripting | haraj | 6.1 | medium | 341266 |
| CVE-2022-31373 | SolarView Compact 6.00 - Cross-Site Scripting | sv-cpt-mc310_firmware | 6.1 | medium | 341266 |
| CVE-2022-31470 | Axigen WebMail - Cross-Site Scripting | webmail | 6.1 | MEDIUM | 341266 |
| CVE-2022-31798 | Nortek Linear eMerge E3-Series - Cross-Site Scripting | emerge_e3_firmware | 6.1 | medium | 347198 |
| CVE-2022-32195 | Open edX <2022-06-06 - Cross-Site Scripting | open_edx | 6.1 | medium | 333141 |
| CVE-2022-3242 | Microweber <1.3.2 - Cross-Site Scripting | microweber | 6.1 | medium | 341266 |
| CVE-2022-32770 | WWBN AVideo 11.6 - Cross-Site Scripting | avideo | 6.1 | medium | 341266 |
| CVE-2022-32771 | WWBN AVideo 11.6 - Cross-Site Scripting | avideo | 6.1 | medium | 341266 |
| CVE-2022-32772 | WWBN AVideo 11.6 - Cross-Site Scripting | avideo | 6.1 | medium | 341266 |
| CVE-2022-33119 | NUUO NVRsolo Video Recorder 03.06.02 - Cross-Site Scripting | nvrsolo_firmware | 6.1 | medium | 340003 |
| CVE-2022-34048 | Wavlink WN-533A8 - Cross-Site Scripting | wn533a8_firmware | 6.1 | medium | 392301 |
| CVE-2022-34093 | Software Publico Brasileiro i3geo v7.0.5 - Cross-Site Scripting | i3geo | 6.1 | medium | 341266 |
| CVE-2022-34094 | Software Publico Brasileiro i3geo v7.0.5 - Cross-Site Scripting | i3geo | 6.1 | medium | 341266 |
| CVE-2022-34328 | PMB 7.3.10 - Cross-Site Scripting | pmb | 6.1 | medium | 341266 |
| CVE-2022-3484 | WordPress WPB Show Core - Cross-Site Scripting | wpb_show_core | 6.1 | medium | 341266 |
| CVE-2022-35155 | Bus Pass Management System 1.0 - Cross-Site Scripting (XSS) | bus pass management system | 6.1 | MEDIUM | 340147 |
| CVE-2022-35416 | H3C SSL VPN <=2022-07-10 - Cross-Site Scripting | ssl_vpn | 6.1 | medium | 342259 |
| CVE-2022-35493 | eShop 3.0.4 - Cross-Site Scripting | eshop_-ecommerce/_store_website | 6.1 | medium | 347198 |
| CVE-2022-35653 | Moodle LTI module Reflected - Cross-Site Scripting | moodle | 6.1 | medium | 333141 |
| CVE-2022-3578 | WordPress ProfileGrid <5.1.1 - Cross-Site Scripting | profilegrid | 6.1 | medium | 341266 |
| CVE-2022-37153 | Artica Proxy 4.30.000000 - Cross-Site Scripting | artica_proxy | 6.1 | medium | 340147 |
| CVE-2022-3766 | phpMyFAQ < 3.1.8 - Cross-Site Scripting | phpmyfaq | 6.1 | medium | 333141 |
| CVE-2022-38295 | Cuppa CMS v1.0 - Cross Site Scripting | cuppacms | 6.1 | medium | 340147 |
| CVE-2022-38463 | ServiceNow - Cross-Site Scripting | servicenow | 6.1 | medium | 350148 |
| CVE-2022-38467 | CRM Perks Forms < 1.1.1 - Cross Site Scripting | crm_perks_forms | 6.1 | medium | 347198 |
| CVE-2022-38553 | Academy Learning Management System <5.9.1 - Cross-Site Scripting | academy_learning_management_system | 6.1 | medium | 341266 |
| CVE-2022-3908 | WordPress Helloprint <1.4.7 - Cross-Site Scripting | helloprint | 6.1 | medium | 341266 |
| CVE-2022-39195 | LISTSERV 17 - Cross-Site Scripting | listserv | 6.1 | medium | 341266 |
| CVE-2022-40359 | Kae's File Manager <=1.4.7 - Cross-Site Scripting | kfm | 6.1 | medium | 341266 |
| CVE-2022-41441 | ReQlogic v11.3 - Cross Site Scripting | reqlogic | 6.1 | medium | 341266 |
| CVE-2022-41473 | RPCMS 3.0.2 - Cross-Site Scripting | rpcms | 6.1 | medium | 341266 |
| CVE-2022-42118 | Liferay Portal - Cross-site Scripting | liferay_portal | 6.1 | medium | 341266 |
| CVE-2022-42746 | CandidATS 3.0.0 - Cross-Site Scripting. | candidats | 6.1 | medium | 341266 |
| CVE-2022-42747 | CandidATS 3.0.0 - Cross-Site Scripting. | candidats | 6.1 | medium | 341266 |
| CVE-2022-42748 | CandidATS 3.0.0 - Cross-Site Scripting. | candidats | 6.1 | medium | 341266 |
| CVE-2022-42749 | CandidATS 3.0.0 - Cross-Site Scripting | candidats | 6.1 | medium | 341266 |
| CVE-2022-4295 | Show all comments < 7.0.1 - Cross-Site Scripting | show_all_comments | 6.1 | medium | 341266 |
| CVE-2022-4301 | WordPress Sunshine Photo Cart <2.9.15 - Cross-Site Scripting | sunshine_photo_cart | 6.1 | medium | 341266 |
| CVE-2022-43014 | OpenCATS 0.9.6 - Cross-Site Scripting | opencats | 6.1 | medium | 341266 |
| CVE-2022-43015 | OpenCATS 0.9.6 - Cross-Site Scripting | opencats | 6.1 | medium | 341266 |
| CVE-2022-43016 | OpenCATS 0.9.6 - Cross-Site Scripting | opencats | 6.1 | medium | 341266 |
| CVE-2022-43017 | OpenCATS 0.9.6 - Cross-Site Scripting | opencats | 6.1 | medium | 341266 |
| CVE-2022-43018 | OpenCATS 0.9.6 - Cross-Site Scripting | opencats | 6.1 | medium | 341266 |
| CVE-2022-4320 | WordPress Events Calendar <1.4.5 - Cross-Site Scripting | wordpress_events_calendar_plugin | 6.1 | medium | 341266 |
| CVE-2022-4321 | PDF Generator for WordPress < 1.1.2 - Cross Site Scripting | pdf_generator_for_wordpress | 6.1 | medium | 341266 |
| CVE-2022-4325 | WordPress Post Status Notifier Lite <1.10.1 - Cross-Site Scripting | post_status_notifier_lite | 6.1 | medium | 341266 |
| CVE-2022-46073 | Helmet Store Showroom - Cross Site Scripting | helmet_store_showroom | 6.1 | medium | 341266 |
| CVE-2022-46381 | Linear eMerge E3-Series - Cross-Site Scripting | linear_emerge_e3_access_control_firmware | 6.1 | medium | 333141 |
| CVE-2022-46888 | NexusPHP <1.7.33 - Cross-Site Scripting | nexusphp | 6.1 | medium | 341266 |
| CVE-2022-48012 | OpenCATS 0.9.7 - Cross-Site Scripting | opencats | 6.1 | medium | 340147 |
| CVE-2022-48197 | Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scripting | yui | 6.1 | medium | 341266 |
| CVE-2022-4897 | WordPress BackupBuddy <8.8.3 - Cross Site Scripting | backupbuddy | 6.1 | medium | 347198 |
| CVE-2022-4971 | Sassy Social Share <= 3.3.3 - Cross-Site Scripting | sassy_social_share | 6.1 | medium | 347198 |
| CVE-2023-0099 | Simple URLs < 115 - Cross Site Scripting | simple_urls | 6.1 | medium | 347198 |
| CVE-2023-0236 | WordPress Tutor LMS <2.0.10 - Cross Site Scripting | tutor_lms | 6.1 | medium | 333141 |
| CVE-2023-0334 | ShortPixel Adaptive Images < 3.6.3 - Cross Site Scripting | shortpixel_adaptive_images | 6.1 | medium | 347198 |
| CVE-2023-0448 | WP Helper Lite < 4.3 - Cross-Site Scripting | wp_helper_premium | 6.1 | medium | 347198 |
| CVE-2023-0514 | Membership Database <= 1.0 - Cross-Site Scripting | membership_database | 6.1 | MEDIUM | 377360 |
| CVE-2023-0527 | Online Security Guards Hiring System - Cross-Site Scripting | online_security_guards_hiring_system | 6.1 | medium | 333141 |
| CVE-2023-0602 | Twittee Text Tweet <= 1.0.8 - Cross-Site Scripting | twittee_text_tweet | 6.1 | medium | 341266 |
| CVE-2023-0676 | phpIPAM 1.5.1 - Cross-site Scripting | phpipam | 6.1 | medium | 340147 |
| CVE-2023-0942 | WordPress Japanized for WooCommerce <2.5.5 - Cross-Site Scripting | japanized_for_woocommerce | 6.1 | medium | 347198 |
| CVE-2023-0948 | WordPress Japanized for WooCommerce <2.5.8 - Cross-Site Scripting | japanized_for_woocommerce | 6.1 | medium | 341266 |
| CVE-2023-0968 | WordPress Watu Quiz <3.3.9.1 - Cross-Site Scripting | watu_quiz | 6.1 | medium | 347198 |
| CVE-2023-1080 | WordPress GN Publisher <1.5.6 - Cross-Site Scripting | gn_publisher | 6.1 | medium | 347198 |
| CVE-2023-1119 | WP-Optimize WordPress plugin < 3.2.13 - Cross-Site Scripting | wp-optimize,srbtranslatin | 6.1 | medium | 341266 |
| CVE-2023-1546 | MyCryptoCheckout < 2.124 - Cross-Site Scripting | mycryptocheckout | 6.1 | medium | 341266 |
| CVE-2023-1780 | Companion Sitemap Generator < 4.5.3 - Cross-Site Scripting | companion_sitemap_generator | 6.1 | medium | 347198 |
| CVE-2023-1835 | Ninja Forms < 3.6.22 - Cross-Site Scripting | ninja_forms | 6.1 | medium | 347198 |
| CVE-2023-1880 | Phpmyfaq v3.1.11 - Cross-Site Scripting | phpmyfaq | 6.1 | medium | 341266 |
| CVE-2023-1890 | Tablesome < 1.0.9 - Cross-Site Scripting | tablesome | 6.1 | medium | 341266 |
| CVE-2023-1893 | Login Configurator <=2.1 - Cross-Site Scripting | login_configurator | 6.1 | MEDIUM | 341266 |
| CVE-2023-2023 | Custom 404 Pro < 3.7.3 - Cross-Site Scripting | custom_404_pro | 6.1 | medium | 347198 |
| CVE-2023-2122 | Image Optimizer by 10web < 1.0.26 - Cross-Site Scripting | image_optimizer | 6.1 | medium | 347198 |
| CVE-2023-2256 | WordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site Scripting | woocommerce-product-addon | 6.1 | high | 341266 |
| CVE-2023-2272 | Tiempo.com <= 0.1.2 - Cross-Site Scripting | tiempo | 6.1 | MEDIUM | 377360 |
| CVE-2023-2309 | wpForo Forum <= 2.1.8 - Cross-Site Scripting | wpforo_forum | 6.1 | medium | 341266 |
| CVE-2023-23161 | Art Gallery Management System Project v1.0 - Cross-Site Scripting | art_gallery_management_system | 6.1 | medium | 347198 |
| CVE-2023-23491 | Quick Event Manager < 9.7.5 - Cross-Site Scripting | quick_event_manager | 6.1 | medium | 341266 |
| CVE-2023-24278 | Squidex <7.4.0 - Cross-Site Scripting | squidex | 6.1 | medium | 341266 |
| CVE-2023-24322 | mojoPortal 2.7.0.0 - Cross-Site Scripting | mojoportal | 6.1 | medium | 350148 |
| CVE-2023-24367 | Temenos T24 R20 - Cross-Site Scripting | t24 | 6.1 | medium | 341266 |
| CVE-2023-24488 | Citrix Gateway and Citrix ADC - Cross-Site Scripting | gateway | 6.1 | medium | 340099, 341266 |
| CVE-2023-24657 | phpIPAM - 1.6 - Cross-Site Scripting | phpipam | 6.1 | medium | 341266 |
| CVE-2023-24733 | PMB 7.4.6 - Cross-Site Scripting | pmb | 6.1 | medium | 341266 |
| CVE-2023-24737 | PMB v7.4.6 - Cross-Site Scripting | pmb | 6.1 | medium | 341266 |
| CVE-2023-2518 | WordPress Easy Forms for Mailchimp Plugin < 6.8.9 - Cross-Site Scripting | easy_forms_for_mailchimp | 6.1 | MEDIUM | 347198, 377360 |
| CVE-2023-25346 | ChurchCRM 4.5.3 - Cross-Site Scripting | churchcrm | 6.1 | medium | 341266 |
| CVE-2023-2624 | KiviCare WordPress Plugin - Cross-Site Scripting | kivicare | 6.1 | medium | 347198 |
| CVE-2023-27008 | ATutor < 2.2.1 - Cross Site Scripting | atutor | 6.1 | medium | 350148 |
| CVE-2023-27641 | L-Soft LISTSERV 16.5 - Cross-Site Scripting | listserv | 6.1 | medium | 341266 |
| CVE-2023-2779 | Super Socializer < 7.13.52 - Cross-Site Scripting | social_share,_social_login_and_social_comments | 6.1 | medium | 347198 |
| CVE-2023-27922 | Newsletter < 7.6.9 - Cross-Site Scripting | newsletter | 6.1 | medium | 341266 |
| CVE-2023-2813 | Wordpress Multiple Themes - Reflected Cross-Site Scripting | connections_reloaded | 6.1 | medium | 333141 |
| CVE-2023-2822 | Ellucian Ethos Identity CAS - Cross-Site Scripting | ethos_identity | 6.1 | medium | 347198 |
| CVE-2023-29439 | FooGallery plugin <= 2.2.35 - Cross-Site Scripting | foogallery | 6.1 | medium | 341266 |
| CVE-2023-2948 | OpenEMR < 7.0.1 - Cross-Site Scripting | openemr | 6.1 | medium | 344363 |
| CVE-2023-29489 | cPanel < 11.109.9999.116 - Cross-Site Scripting | cpanel | 6.1 | medium | 340099 |
| CVE-2023-2949 | OpenEMR < 7.0.1 - Cross-site Scripting | openemr | 6.1 | medium | 347198 |
| CVE-2023-29623 | Purchase Order Management v1.0 - Cross Site Scripting (Reflected) | purchase_order_management | 6.1 | medium | 333141 |
| CVE-2023-30210 | OURPHP <= 7.2.0 - Cross Site Scripting | ourphp | 6.1 | medium | 341266 |
| CVE-2023-30212 | OURPHP <= 7.2.0 - Cross Site Scripting | ourphp | 6.1 | medium | 341266 |
| CVE-2023-30256 | Webkul QloApps 1.5.2 - Cross-site Scripting | qloapps | 6.1 | medium | 347198 |
| CVE-2023-30777 | Advanced Custom Fields < 6.1.6 - Cross-Site Scripting | advanced_custom_fields | 6.1 | medium | 347198 |
| CVE-2023-30868 | Tree Page View Plugin < 1.6.7 - Cross-Site Scripting | cms_tree_page_view | 6.1 | medium | 341266 |
| CVE-2023-3169 | tagDiv Composer < 4.2 - Stored Cross-Site Scripting | tagdiv_composer | 6.1 | high | 380026 |
| CVE-2023-34599 | Gibbon v25.0.0 - Cross-Site Scripting | gibbon | 6.1 | medium | 341266 |
| CVE-2023-3479 | Hestiacp <= 1.7.7 - Cross-Site Scripting | control_panel | 6.1 | medium | 341266 |
| CVE-2023-35155 | XWiki - Cross-Site Scripting | xwiki | 6.1 | medium | 347198 |
| CVE-2023-35156 | XWiki >= 6.0-rc-1 - Cross-Site Scripting | xwiki | 6.1 | medium | 350148 |
| CVE-2023-35158 | XWiki - Cross-Site Scripting | xwiki | 6.1 | medium | 350148 |
| CVE-2023-35159 | XWiki >= 3.4-milestone-1 - Cross-Site Scripting | xwiki | 6.1 | medium | 350148 |
| CVE-2023-35160 | XWiki >= 2.5-milestone-2 - Cross-Site Scripting | xwiki | 6.1 | medium | 350148 |
| CVE-2023-35161 | XWiki >= 6.2-milestone-1 - Cross-Site Scripting | xwiki | 6.1 | medium | 350148 |
| CVE-2023-35162 | XWiki < 14.10.5 - Cross-Site Scripting | xwiki | 6.1 | medium | 350148 |
| CVE-2023-3521 | FOSSBilling < 0.5.3 - Cross-Site Scripting | fossbilling | 6.1 | medium | 347198 |
| CVE-2023-36287 | Webkul QloApps 1.6.0 - Cross-site Scripting | qloapps | 6.1 | medium | 350148 |
| CVE-2023-36289 | Webkul QloApps 1.6.0 - Cross-site Scripting | qloapps | 6.1 | medium | 333141 |
| CVE-2023-36306 | Adiscon LogAnalyzer v.4.1.13 - Cross-Site Scripting | loganalyzer | 6.1 | medium | 341266 |
| CVE-2023-36346 | POS Codekop v2.0 - Cross Site Scripting | codekop | 6.1 | medium | 341266 |
| CVE-2023-37580 | Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scripting | zimbra | 6.1 | medium | 347198 |
| CVE-2023-37728 | IceWarp Webmail Server v10.2.1 - Cross Site Scripting | icewarp | 6.1 | medium | 347198 |
| CVE-2023-37979 | Ninja Forms < 3.6.26 - Cross-Site Scripting | ninja_forms | 6.1 | MEDIUM | 377360 |
| CVE-2023-37988 | Contact Form Generator <= 2.5.5 - Cross-Site Scripting | contact-form-generator | 6.1 | medium | 341266 |
| CVE-2023-38040 | Revive Adserver 5.4.1 - Cross-Site Scripting | revive_adserver | 6.1 | MEDIUM | 341266 |
| CVE-2023-38192 | SuperWebMailer 9.00.0.01710 - Cross-Site Scripting | superwebmailer | 6.1 | medium | 340147 |
| CVE-2023-38194 | SuperWebMailer - Cross-Site Scripting | superwebmailer | 6.1 | medium | 347198 |
| CVE-2023-3843 | mooDating 1.2 - Cross-site scripting | moodating | 6.1 | medium | 347198 |
| CVE-2023-3844 | MooDating 1.2 - Cross-Site Scripting | moodating | 6.1 | medium | 347198 |
| CVE-2023-3845 | MooDating 1.2 - Cross-Site Scripting | moodating | 6.1 | medium | 347198 |
| CVE-2023-3846 | MooDating 1.2 - Cross-Site Scripting | moodating | 6.1 | medium | 347198 |
| CVE-2023-3847 | MooDating 1.2 - Cross-Site scripting | moodating | 6.1 | medium | 347198 |
| CVE-2023-3848 | MooDating 1.2 - Cross-site scripting | moodating | 6.1 | medium | 347198 |
| CVE-2023-3849 | mooDating 1.2 - Cross-site scripting | moodating | 6.1 | medium | 347198 |
| CVE-2023-38501 | CopyParty v1.8.6 - Cross Site Scripting | copyparty | 6.1 | medium | 347198 |
| CVE-2023-38875 | PHP Login System 2.0.1 - Cross-Site Scripting | php-login-system | 6.1 | medium | 341266 |
| CVE-2023-38910 | CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' ) | csz cms | 6.1 | MEDIUM | 333141 |
| CVE-2023-38964 | Academy LMS 6.0 - Cross-Site Scripting | academy_lms | 6.1 | medium | 347198 |
| CVE-2023-3936 | Blog2Social < 7.2.1 - Cross-Site Scripting | blog2social | 6.1 | medium | 347198 |
| CVE-2023-39598 | IceWarp Email Client - Cross Site Scripting | webclient | 6.1 | medium | 333141 |
| CVE-2023-39600 | IceWarp 11.4.6.0 - Cross-Site Scripting | icewarp | 6.1 | medium | 333141 |
| CVE-2023-39676 | PrestaShop fieldpopupnewsletter Module - Cross Site Scripting | fieldpopupnewsletter | 6.1 | medium | 341266 |
| CVE-2023-39700 | IceWarp Mail Server v10.4.5 - Cross-Site Scripting | mail_server | 6.1 | medium | 333140 |
| CVE-2023-3990 | Mingsoft MCMS < 5.3.1 - Cross-Site Scripting | mcms | 6.1 | MEDIUM | 342259 |
| CVE-2023-40750 | PHPJabbers Yacht Listing Script v1.0 - Cross-Site Scripting | yacht_listing_script | 6.1 | medium | 333141 |
| CVE-2023-40751 | PHPJabbers Fundraising Script v1.0 - Cross-Site Scripting | fundraising_script | 6.1 | medium | 333141 |
| CVE-2023-40752 | PHPJabbers Make an Offer Widget v1.0 - Cross-Site Scripting | make_an_offer_widget | 6.1 | medium | 333141 |
| CVE-2023-40755 | PHPJabbers Callback Widget v1.0 - Cross-Site Scripting | callback_widget | 6.1 | MEDIUM | 341266 |
| CVE-2023-4110 | PHPJabbers Availability Booking Calendar 5.0 - Cross-Site Scripting | availability_booking_calendar | 6.1 | medium | 341266 |
| CVE-2023-4111 | PHPJabbers Bus Reservation System 1.1 - Cross-Site Scripting | bus_reservation_system | 6.1 | medium | 341266 |
| CVE-2023-4112 | PHPJabbers Shuttle Booking Software 1.0 - Cross Site Scripting | shuttle_booking_software | 6.1 | medium | 341266 |
| CVE-2023-4113 | PHPJabbers Service Booking Script 1.0 - Cross Site Scripting | service_booking_script | 6.1 | medium | 341266 |
| CVE-2023-4114 | PHP Jabbers Night Club Booking 1.0 - Cross Site Scripting | night_club_booking_software | 6.1 | medium | 341266 |
| CVE-2023-4115 | PHPJabbers Cleaning Business 1.0 - Cross-Site Scripting | cleaning_business_software | 6.1 | medium | 341266 |
| CVE-2023-4116 | PHPJabbers Taxi Booking 2.0 - Cross Site Scripting | taxi_booking_script | 6.1 | medium | 341266 |
| CVE-2023-4136 | CrafterCMS Engine - Cross-Site Scripting | craftercms | 6.1 | medium | 341266 |
| CVE-2023-4148 | Ditty < 3.1.25 - Cross-Site Scripting | ditty | 6.1 | medium | 341266 |
| CVE-2023-4151 | Store Locator WordPress < 1.4.13 - Cross-Site Scripting | store_locator | 6.1 | MEDIUM | 377360 |
| CVE-2023-41538 | PHPJabbers PHP Forum Script 3.0 - Cross-Site Scripting | php_forum_script | 6.1 | medium | 341266 |
| CVE-2023-41597 | EyouCms v1.6.2 - Cross-Site Scripting | eyoucms | 6.1 | MEDIUM | 341266 |
| CVE-2023-41621 | Emlog Pro v2.1.14 - Cross-Site Scripting | emlog | 6.1 | medium | 350148 |
| CVE-2023-4173 | mooSocial 3.1.8 - Reflected XSS | moostore | 6.1 | medium | 347198 |
| CVE-2023-4174 | mooSocial 3.1.6 - Reflected Cross Site Scripting | moostore | 6.1 | medium | 347198 |
| CVE-2023-4284 | WordPress Post Timeline Plugin < 2.2.6 - Cross-Site Scripting | post-timeline | 6.1 | MEDIUM | 347198, 377360 |
| CVE-2023-43325 | MooSocial 3.1.8 - Cross-Site Scripting | moosocial | 6.1 | medium | 347198 |
| CVE-2023-43326 | MooSocial 3.1.8 - Cross-Site Scripting | moosocial | 6.1 | medium | 347198 |
| CVE-2023-44012 | mojoPortal v.2.7.0.0 - Cross-Site Scripting | mojoportal | 6.1 | medium | 347198 |
| CVE-2023-44352 | Adobe Coldfusion - Cross-Site Scripting | coldfusion | 6.1 | medium | 341266, 347198 |
| CVE-2023-44393 | Piwigo - Cross-Site Scripting | piwigo | 6.1 | medium | 341266 |
| CVE-2023-4451 | Cockpit - Cross-Site Scripting | cockpit | 6.1 | medium | 347198 |
| CVE-2023-44812 | mooSocial v.3.1.8 - Cross-Site Scripting | moosocial | 6.1 | MEDIUM | 341266 |
| CVE-2023-45136 | XWiki < 14.10.14 - Cross-Site Scripting | xwiki | 6.1 | medium | 341266 |
| CVE-2023-4547 | SPA-Cart eCommerce CMS 1.9.0.3 - Cross-Site Scripting | ecommerce_cms | 6.1 | medium | 341266 |
| CVE-2023-45542 | MooSocial 3.1.8 - Cross-Site Scripting | moosocial | 6.1 | medium | 341266 |
| CVE-2023-46020 | Blood Bank v1.0 - Stored Cross Site Scripting (XSS) | blood bank | 6.1 | MEDIUM | 333141 |
| CVE-2023-46732 | XWiki < 14.10.14 - Cross-Site Scripting | xwiki | 6.1 | medium | 341266 |
| CVE-2023-47684 | Essential Grid <= 3.1.0 - Cross-Site Scripting | essential_grid | 6.1 | medium | 341266 |
| CVE-2023-48728 | WWBN AVideo 11.6 - Cross-Site Scripting | avideo | 6.1 | medium | 341266 |
| CVE-2023-49293 | Vite dev server - Cross-Site Scripting | - | 6.1 | medium | 341266 |
| CVE-2023-49489 | KodeExplorer 4.51 - Reflective Cross Site Scripting (XSS) | kodexplorer | 6.1 | medium | 342259 |
| CVE-2023-49494 | DedeCMS v5.7.111 - Cross-Site Scripting | dedecms | 6.1 | medium | 340095 |
| CVE-2023-4973 | Academy LMS 6.2 - Cross-Site Scripting | academy_lms | 6.1 | medium | 340147 |
| CVE-2023-5244 | Microweber < V.2.0 - Cross-Site Scripting | microweber | 6.1 | medium | 393655 |
| CVE-2023-5558 | LearnPress < 4.2.5.5 - Cross-Site Scripting | learnpress | 6.1 | MEDIUM | 390722, 392301 |
| CVE-2023-5863 | phpMyFAQ < 3.2.0 - Cross-site Scripting | phpMyFAQ | 6.1 | medium | 333141 |
| CVE-2023-6275 | TOTVS Fluig Platform - Cross-Site Scripting | fluig | 6.1 | medium | 341266 |
| CVE-2023-6379 | OpenCMS 14 & 15 - Cross Site Scripting | opencms | 6.1 | medium | 341266 |
| CVE-2023-6568 | Mlflow - Cross-Site Scripting | mlflow | 6.1 | medium | 334168 |
| CVE-2023-6697 | WP Go Maps (formerly WP Google Maps) < 9.0.29 - Cross-Site Scripting | wp_go_maps | 6.1 | medium | 347198 |
| CVE-2024-11587 | idcCMS V1.60 - Cross-Site Scripting | idccms | 6.1 | medium | 341266 |
| CVE-2024-12732 | AffiliateImporterEb <= 1.0.6 - Reflected XSS | affiliateimportereb | 6.1 | MEDIUM | 377360 |
| CVE-2024-12734 | Advance Post Prefix WordPress plugin - Reflected XSS | advance_post_prefix | 6.1 | MEDIUM | 377360 |
| CVE-2024-12737 | WP BASE Booking - Reflected XSS | wp base booking of appointments, services and events | 6.1 | MEDIUM | 377360 |
| CVE-2024-12873 | Custom Field Manager WordPress - Cross-Site Scripting | custom_field_manager | 6.1 | MEDIUM | 377360 |
| CVE-2024-13112 | WP MediaTagger <= 4.1.1 - Cross-Site Scripting | wp_mediatagger | 6.1 | MEDIUM | 377360 |
| CVE-2024-13114 | WP Projects Portfolio <= 3.0 - Cross-Site Scripting | wp_projects_portfolio_with_client_testimonials | 6.1 | MEDIUM | 377360 |
| CVE-2024-13219 | Privacy Policy Genius - Cross-Site Scripting | privacy_policy_genius | 6.1 | MEDIUM | 377360 |
| CVE-2024-13220 | WordPress Google Map Professional - Cross-Site Scripting | google_map_professional | 6.1 | MEDIUM | 377360 |
| CVE-2024-13221 | Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scripting | fantastic_elasticsearch | 6.1 | MEDIUM | 377360 |
| CVE-2024-13224 | SlideDeck 1 Lite Content Slider - Cross-Site Scripting | slidedeck_1_lite_content_slider | 6.1 | MEDIUM | 377360 |
| CVE-2024-13225 | ECT Home Page Products - Reflected XSS | ect_home_page_products | 6.1 | MEDIUM | 377360 |
| CVE-2024-13226 | A5 Custom Login Page - Reflected XSS | a5 custom login page | 6.1 | MEDIUM | 377360 |
| CVE-2024-13325 | Glossy WordPress - Reflected XSS | glossy | 6.1 | MEDIUM | 377360 |
| CVE-2024-13326 | iBuildApp <= 0.2.0 - Reflected Cross-Site Scripting | ibuildapp | 6.1 | MEDIUM | 377360 |
| CVE-2024-13327 | Musicbox WordPress - Reflected XSS | musicbox | 6.1 | MEDIUM | 377360 |
| CVE-2024-13331 | WP Dream Carousel < 1.0.1b - Cross-Site Scripting | wp_dream_carousel | 6.1 | MEDIUM | 377360 |
| CVE-2024-13492 | Guten Free Options - Cross Site Scripting | guten_free_options | 6.1 | MEDIUM | 377360 |
| CVE-2024-13543 | Zarinpal Paid Download - Reflected XSS | zarinpal_paid_download | 6.1 | MEDIUM | 377360 |
| CVE-2024-13570 | WordPress Stray Random Quotes <= 1.9.9 - Cross-Site Scripting | stray_random_quotes | 6.1 | MEDIUM | 377360 |
| CVE-2024-13619 | LifterLMS < 8.0.1 - Cross-Site Scripting | lifterlms | 6.1 | MEDIUM | 377360 |
| CVE-2024-13628 | WP Pricing Table - Reflected XSS | wp pricing table | 6.1 | MEDIUM | 377360 |
| CVE-2024-13630 | NewsTicker <= 1.0 - Reflected Cross-Site Scripting | newsticker | 6.1 | MEDIUM | 377360 |
| CVE-2024-13634 | Post Sync Plugin <= 1.1 - Cross-Site Scripting | post_sync | 6.1 | MEDIUM | 377360 |
| CVE-2024-13727 | MemberSpace WordPress - Cross-Site Scripting | - | 6.1 | medium | 341266 |
| CVE-2024-13853 | WordPress SEO Tools Plugin 4.0.7 - Cross-Site Scripting | seo-automatic-seo-tools | 6.1 | MEDIUM | 341266 |
| CVE-2024-24131 | SuperWebMailer 9.31.0.01799 - Cross-Site Scripting | superwebmailer | 6.1 | medium | 341266 |
| CVE-2024-24494 | Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS) | daily habit tracker | 6.1 | MEDIUM | 340147 |
| CVE-2024-25669 | CaseAware a360inc - Cross-Site Scripting | caseaware | 6.1 | medium | 347198 |
| CVE-2024-29138 | WordPress Restrict User Access <= 2.5 - Cross-Site Scripting | restrict user access | 6.1 | MEDIUM | 377360 |
| CVE-2024-29792 | Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting | unlimited elements for elementor | 6.1 | MEDIUM | 377360 |
| CVE-2024-29931 | WP Go Maps <= 9.0.29 - Cross-Site Scripting | wp_go_maps | 6.1 | MEDIUM | 341266, 377360 |
| CVE-2024-30194 | Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting | sunshine-photo-cart | 6.1 | MEDIUM | 377360 |
| CVE-2024-3032 | WordPress Themify Builder < 7.5.8 - Open Redirect | builder | 6.1 | MEDIUM | 377360 |
| CVE-2024-3231 | Popup4Phone <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting | - | 6.1 | medium | 340147 |
| CVE-2024-3469 | GP Premium <= 2.4.0 - Cross-Site Scripting | gp-premium | 6.1 | medium | 341266 |
| CVE-2024-35693 | WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting | 12-step-meeting-list | 6.1 | medium | 347198 |
| CVE-2024-37259 | WP Extended < 3.0.0 - Stored Cross-Site Scripting | wp-extended | 6.1 | medium | 340147 |
| CVE-2024-37261 | WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting | wp-lister-lite-for-amazon | 6.1 | MEDIUM | 377360 |
| CVE-2024-39646 | WordPress Custom 404 Pro <= 3.11.1 - Reflected XSS | custom_404_pro | 6.1 | MEDIUM | 377360 |
| CVE-2024-41810 | Twisted - Open Redirect & XSS | twisted | 6.1 | MEDIUM | 341266 |
| CVE-2024-43971 | Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scripting | sunshine-photo-cart | 6.1 | MEDIUM | 377360 |
| CVE-2024-4439 | WordPress Core <6.5.2 - Cross-Site Scripting | wordpress | 6.1 | MEDIUM | 377360 |
| CVE-2024-4455 | YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting | yith-woocommerce-ajax-search | 6.1 | MEDIUM | 377360 |
| CVE-2024-47374 | LiteSpeed Cache <= 6.5.0.2 - Stored XSS | litespeed cache | 6.1 | MEDIUM | 377360 |
| CVE-2024-55218 | IceWarp Server 10.2.1 - Cross-Site Scripting | mail_server | 6.1 | medium | 333141 |
| CVE-2024-6651 | WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting | wp-file-upload | 6.1 | MEDIUM | 341266, 377360 |
| CVE-2024-6753 | Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting | social auto poster | 6.1 | MEDIUM | 377360 |
| CVE-2024-6892 | Journyx 11.5.4 - Reflected Cross Site Scripting | journyx | 6.1 | medium | 333141 |
| CVE-2024-7313 | Shield Security Plugin < 20.0.6 - Cross-Site Scripting | - | 6.1 | medium | 341266 |
| CVE-2024-7354 | Ninja Forms 3.8.6-3.8.10 - Cross-Site Scripting | ninja_forms | 6.1 | MEDIUM | 341266, 377360 |
| CVE-2024-9007 | 123Solar 1.8.4.5 - Cross-Site Scripting | 123solar | 6.1 | medium | 340147 |
| CVE-2025-25296 | Label Studio < 1.16.0 - Cross-Site Scripting | label-studio | 6.1 | MEDIUM | 347198 |
| CVE-2025-2709 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida_erp-nc | 6.1 | medium | 347198 |
| CVE-2025-2711 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida_erp-nc | 6.1 | medium | 347198 |
| CVE-2025-2712 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida_erp-nc | 6.1 | medium | 347198 |
| CVE-2025-34141 | ETQ Reliance - Reflected XSS via SQLConverterServlet | reliance | 6.1 | medium | 347198 |
| CVE-2025-41393 | Ricoh Web Image Monitor - Reflected XSS | - | 6.1 | medium | 341266 |
| CVE-2025-44136 | MapTiler Tileserver-php v2.0 - Unauthenticated XSS | - | 6.1 | medium | 342259 |
| CVE-2025-4576 | Liferay Portal & DXP - Cross-Site Scripting | - | 6.1 | medium | 341266 |
| CVE-2025-46349 | YesWiki Reflected XSS via File Upload | - | 6.1 | high | 347198 |
| CVE-2025-4652 | Broadstreet WordPress plugin - Reflected XSS | broadstreet | 6.1 | MEDIUM | 377360 |
| CVE-2025-5301 | ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting | - | 6.1 | medium | 341266 |
| CVE-2025-53533 | Pi-hole Reflected XSS in 404-Error Page | web_interface | 6.1 | medium | 347198 |
| CVE-2025-54597 | Heimdall Application Dashboard < 2.7.3 - Reflected XSS | heimdall | 6.1 | MEDIUM | 347198 |
| CVE-2025-6174 | WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected) | - | 6.1 | medium | 341266 |
| CVE-2026-1296 | Frontend Post Submission Manager Lite <= 1.2.7 - Open Redirect | - | 6.1 | MEDIUM | 377360 |
| CVE-2026-15094 | WP Hotel Booking <= 2.3.2 - Cross-Site Scripting | wp-hotel-booking | 6.1 | MEDIUM | 300002 |
| CVE-2026-24128 | XWiki Platform Distribution Flavor Main - Cross-Site Scripting | xwiki-platform-distribution-flavor-main | 6.1 | medium | 347198 |
| CVE-2026-25616 | Blesta <= 5.13.1 - Cross-Site Scripting | - | 6.1 | medium | 340112 |
| CVE-2026-27176 | MajorDoMo - Cross-Site Scripting | - | 6.1 | medium | 347198 |
| CVE-2026-29183 | SiYuan Note - Cross-Site Scripting | siyuan | 6.1 | medium | 341266, 347198 |
| CVE-2026-40105 | XWiki - Cross-Site Scripting | xwiki-platform | 6.1 | medium | 341266 |
| CVE-2026-50229 | Apache Tomcat - Cross-Site Scripting | tomcat | 6.1 | MEDIUM | 341266 |
| CVE-2026-52774 | YesWiki Bazar Widget - Reflected XSS via 'id' Parameter | yeswiki | 6.1 | medium | 333141 |
| CVE-2017-8295 | WordPress Core < 4.7.4 - Unauthorized Password Reset | wordpress | 5.9 | MEDIUM | 377360 |
| CVE-2018-1271 | Spring MVC Framework - Local File Inclusion | spring_framework | 5.9 | medium | 390716 |
| CVE-2021-40149 | Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure | e1_zoom | 5.9 | medium | 390716 |
| CVE-2024-13609 | WordPress 1 Click Migration Plugin < 2.3 - Information Exposure | 1-click-migration | 5.9 | medium | 350590 |
| CVE-2024-3753 | Hostel < 1.1.5.3 - Cross-Site Scripting | hostel | 5.9 | MEDIUM | 341266, 377360 |
| CVE-2025-24963 | Vitest Browser Mode - Local File Read | - | 5.9 | medium | 347009 |
| CVE-2025-28906 | Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting | Thiago S.F. Skitter Slideshow wp-skitter-slideshow | 5.9 | MEDIUM | 377360 |
| CVE-2025-41242 | Spring Framework - Path Traversal | - | 5.9 | medium | 347009 |
| CVE-2026-60137 | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query | WordPress | 5.9 | MEDIUM | 340156, 344370 |
| CVE-2010-0467 | Joomla! Component CCNewsLetter - Local File Inclusion | com_ccnewsletter | 5.8 | MEDIUM | 347009 |
| CVE-2012-4982 | Forescout CounterACT 6.3.4.1 - Open Redirect | counteract | 5.8 | medium | 340162 |
| CVE-2012-6499 | WordPress Plugin Age Verification v0.4 - Open Redirect | age_verification | 5.8 | medium | 392301 |
| CVE-2014-0867 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 5.8 | MEDIUM | 392301 |
| CVE-2017-9965 | Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal | pelco_videoxpert | 5.8 | medium | 390716 |
| CVE-2020-5775 | Canvas LMS v2020-07-29 - Blind Server-Side Request Forgery | canvas_learning_management_service | 5.8 | medium | 340162 |
| CVE-2023-47218 | QNAP QTS and QuTS Hero - OS Command Injection | qts | 5.8 | medium | 330791 |
| CVE-2024-20404 | Cisco Finesse - Server-Side Request Forgery (SSRF) | - | 5.8 | medium | 392301 |
| CVE-2024-6095 | LocalAI - Partial Local File Read | localai | 5.8 | MEDIUM | 344360 |
| CVE-2025-47423 | Personal Weather Station Dashboard 12 - Directory Traversal | - | 5.8 | MEDIUM | 340007 |
| CVE-2025-1035 | KLog Server - Path Traversal | klog_server | 5.7 | medium | 347009 |
| CVE-2018-13980 | Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion | zeta_producer | 5.5 | medium | 347009 |
| CVE-2018-15536 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 5.5 | MEDIUM | 347009, 390720, 390727, 392648 |
| CVE-2025-59342 | esm.sh <= v136 - Arbitrary File Write via Path Traversal | esm.sh | 5.5 | MEDIUM | 340162 |
| CVE-2014-8674 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.4 | MEDIUM | 340155, 390726, 392647 |
| CVE-2016-10993 | ScoreMe Theme - Cross-Site Scripting | scoreme | 5.4 | MEDIUM | 341266 |
| CVE-2017-12544 | HPE System Management - Cross-Site Scripting | system_management_homepage | 5.4 | medium | 344366 |
| CVE-2017-14186 | FortiGate FortiOS SSL VPN Web Portal - Cross-Site Scripting | fortios | 5.4 | medium | 350148 |
| CVE-2017-14725 | WordPress < 4.8.2 - Authenticated Open Redirect | wordpress | 5.4 | MEDIUM | 377360 |
| CVE-2017-17092 | WordPress < 4.9.1 - Authenticated JavaScript File Upload | wordpress | 5.4 | MEDIUM | 377360 |
| CVE-2017-3131 | Fortinet FortiOS < 5.6.0 - Cross-Site Scripting | fortios | 5.4 | MEDIUM | 340147, 341266, 347198, 390727, 392648 |
| CVE-2017-3528 | Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect | applications_framework | 5.4 | medium | 344365 |
| CVE-2017-6340 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities | interscan web security virtual appliance | 5.4 | MEDIUM | 340147, 390724 |
| CVE-2018-12095 | OEcms 3.1 - Cross-Site Scripting | oecms | 5.4 | medium | 341266 |
| CVE-2018-15917 | Jorani Leave Management System 0.6.5 - Cross-Site Scripting | jorani | 5.4 | medium | 341266 |
| CVE-2018-16363 | WordPress File Manager < 3.0 - Cross-Site Scripting | file manager | 5.4 | MEDIUM | 377360 |
| CVE-2018-16736 | Roundcube rcfilters plugin 2.1.6 - Cross-Site Scripting | rcfilters | 5.4 | MEDIUM | 340147 |
| CVE-2018-5405 | KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities | kace systems management appliance firmware | 5.4 | MEDIUM | 390727, 392301, 392648 |
| CVE-2019-11269 | Spring Security OAuth - Open Redirector | spring security oauth | 5.4 | MEDIUM | 390703, 390727, 392648 |
| CVE-2019-11370 | Carel pCOWeb <B1.2.4 - Cross-Site Scripting | pcoweb_card_firmware | 5.4 | medium | 342259 |
| CVE-2019-9556 | Fiberhome AN5506-04-F RP2669 - Persistent Cross-Site Scripting | an5506-04-f firmware | 5.4 | MEDIUM | 340147 |
| CVE-2020-11110 | Grafana <= 6.7.1 - Cross-Site Scripting | grafana | 5.4 | MEDIUM | 350148 |
| CVE-2020-11456 | LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting | limesurvey | 5.4 | MEDIUM | 333141 |
| CVE-2020-11457 | pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting | pfsense | 5.4 | MEDIUM | 333141 |
| CVE-2020-12256 | rConfig 3.9.4 - Cross-Site Scripting | rconfig | 5.4 | medium | 341266 |
| CVE-2020-12259 | rConfig 3.9.4 - Cross-Site Scripting | rconfig | 5.4 | medium | 341266 |
| CVE-2020-12262 | Intelbras TIP200/TIP200LITE/TIP300 - Cross-Site Scripting | tip300 | 5.4 | medium | 341266 |
| CVE-2020-12706 | php-fusion 9.03.50 - Persistent Cross-Site Scripting | php-fusion | 5.4 | MEDIUM | 340147 |
| CVE-2020-20285 | ZZcms - Cross-Site Scripting | zzcms | 5.4 | medium | 333141 |
| CVE-2020-20988 | DomainMOD 4.13.0 - Cross-Site Scripting | domainmod | 5.4 | medium | 340147 |
| CVE-2020-24963 | Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated) | best support system | 5.4 | MEDIUM | 333141 |
| CVE-2020-27533 | DedeCMS v.5.8 - keyword Cross-Site Scripting | dedecms | 5.4 | MEDIUM | 340147 |
| CVE-2020-35774 | twitter-server Cross-Site Scripting | twitter-server | 5.4 | medium | 341266 |
| CVE-2020-7108 | WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting | learndash | 5.4 | MEDIUM | 341266, 390727, 392648 |
| CVE-2021-25065 | Smash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site Scripting | smash_balloon_social_post_feed | 5.4 | medium | 347198 |
| CVE-2021-25067 | Landing Page Builder < 1.4.9.6 - Cross-Site Scripting | landing_page | 5.4 | medium | 347198 |
| CVE-2021-31250 | CHIYU TCP/IP Converter - Cross-Site Scripting | bf-430_firmware | 5.4 | medium | 341266 |
| CVE-2021-33851 | WordPress Customize Login Image <3.5.3 - Cross-Site Scripting | customize_login_image | 5.4 | MEDIUM | 377360 |
| CVE-2021-36873 | WordPress iQ Block Country <=1.2.11 - Cross-Site Scripting | iq_block_country | 5.4 | MEDIUM | 377360 |
| CVE-2021-3831 | Gnuboard 5 - Cross-Site Scripting | gnuboard5 | 5.4 | medium | 341266 |
| CVE-2021-46005 | Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scripting | car_rental_management_system | 5.4 | medium | 340147 |
| CVE-2022-0148 | WordPress All-in-one Floating Contact Form <2.0.4 - Cross-Site Scripting | mystickyelements | 5.4 | medium | 347198 |
| CVE-2022-0378 | Microweber Cross-Site Scripting | microweber | 5.4 | medium | 347198 |
| CVE-2022-0765 | WordPress Loco Translate < 2.6.1 - Cross-Site Scripting | loco translate | 5.4 | MEDIUM | 377360 |
| CVE-2022-0928 | Microweber < 1.2.12 - Stored Cross-Site Scripting | microweber | 5.4 | medium | 333141 |
| CVE-2022-0954 | Microweber <1.2.11 - Stored Cross-Site Scripting | microweber | 5.4 | medium | 333141 |
| CVE-2022-25489 | Atom CMS v2.0 - Cross-Site Scripting | atomcms | 5.4 | medium | 341266 |
| CVE-2022-3506 | WordPress Related Posts <2.1.3 - Stored Cross-Site Scripting | related_posts | 5.4 | MEDIUM | 377360 |
| CVE-2022-3933 | WordPress Essential Real Estate <3.9.6 - Authenticated Cross-Site Scripting | essential_real_estate | 5.4 | medium | 341266 |
| CVE-2022-3934 | WordPress FlatPM <3.0.13 - Cross-Site Scripting | flat_pm | 5.4 | medium | 347198 |
| CVE-2022-4306 | WordPress Panda Pods Repeater Field <1.5.4 - Cross-Site Scripting | panda_pods_repeater_field | 5.4 | medium | 350148 |
| CVE-2023-0902 | Employee Task Management System v1.0 - SQL Injection on edit-task.php | simple food ordering system | 5.4 | MEDIUM | 340016 |
| CVE-2023-1315 | osTicket < v1.16.6 - Cross-Site Scripting | osticket | 5.4 | MEDIUM | 341266 |
| CVE-2023-1318 | osTicket < v1.16.6 - Cross-Site Scripting | osticket | 5.4 | MEDIUM | 341266 |
| CVE-2023-26842 | ChurchCRM 4.5.3 - Cross-Site Scripting | churchcrm | 5.4 | medium | 333141 |
| CVE-2023-26843 | ChurchCRM 4.5.3 - Cross-Site Scripting | churchcrm | 5.4 | medium | 333141 |
| CVE-2023-2745 | WordPress Core <=6.2 - Directory Traversal | wordpress | 5.4 | MEDIUM | 344360 |
| CVE-2023-28665 | Woo Bulk Price Update <2.2.2 - Cross-Site Scripting | bulk_price_update_for_woocommerce | 5.4 | medium | 347198 |
| CVE-2023-31548 | ChurchCRM v4.5.3 - Cross-Site Scripting | churchcrm | 5.4 | medium | 333141 |
| CVE-2023-34537 | Hoteldruid 3.0.5 - Cross-Site Scripting | hoteldruid | 5.4 | medium | 340130, 340147 |
| CVE-2023-38911 | CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery') | csz cms | 5.4 | MEDIUM | 333141 |
| CVE-2023-40753 | PHPJabbers Ticket Support Script v3.2 - Cross-Site Scripting | ticket_support_script | 5.4 | medium | 341266 |
| CVE-2023-4382 | Hyip Rio 2.1 - Arbitrary File Upload | hyip rio | 5.4 | MEDIUM | 392301 |
| CVE-2023-6030 | LogDash Activity Log <= 1.1.3 - SQL Injection | logdash activity log | 5.4 | MEDIUM | 380122 |
| CVE-2023-7246 | System Dashboard < 2.8.10 - Cross-Site Scripting | system dashboard | 5.4 | MEDIUM | 377360 |
| CVE-2024-10146 | Simple File List < 6.1.13 - Reflected Cross-Site Scripting | simple_file_list | 5.4 | MEDIUM | 377360 |
| CVE-2024-13097 | WP Finance Plugin <= 1.3.6 - Cross-Site Scripting | wp_finance | 5.4 | MEDIUM | 377360 |
| CVE-2024-13098 | WordPress Email Newsletter - Reflected XSS | wordpress_email_newsletter | 5.4 | MEDIUM | 377360 |
| CVE-2024-13099 | Widget4Call WordPress - Cross-Site Scripting | widget4call | 5.4 | MEDIUM | 377360 |
| CVE-2024-21485 | Dash Framework - Cross-site Scripting | dash | 5.4 | MEDIUM | 350148 |
| CVE-2024-33326 | LumisXP - Cross-site Scripting | lumis_experience_platform | 5.4 | medium | 341266 |
| CVE-2024-48120 | X2CRM 8.5 - Stored Cross-Site Scripting (XSS) | x2crm | 5.4 | MEDIUM | 340147, 390726, 392647 |
| CVE-2024-52762 | Ganglia Web Interface (v3.7.3 - v3.7.6) - Cross-Site Scripting | ganglia-web | 5.4 | medium | 341266 |
| CVE-2024-52763 | Ganglia Web Interface (v3.7.3 - v3.7.5) - Cross-Site Scripting | ganglia-web | 5.4 | medium | 347198 |
| CVE-2025-27506 | NocoDB < 0.258.0 - Reflected XSS in Password Reset | - | 5.4 | medium | 347198 |
| CVE-2025-32970 | XWiki WYSIWYG API - Open Redirect | xwiki | 5.4 | medium | 340162 |
| CVE-2025-34032 | Moodle LMS Jmol Plugin <= 6.1 - Cross-Site Scripting | - | 5.4 | medium | 341266 |
| CVE-2025-44148 | MailEnable Mail Service < v10 - Cross-Site Scripting | - | 5.4 | medium | 344363 |
| CVE-2026-1207 | Django RasterField - SQL Injection | django | 5.4 | MEDIUM | 341245 |
| CVE-2013-2683 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 5.3 | MEDIUM | 392301 |
| CVE-2014-8676 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.3 | MEDIUM | 340155, 347009, 390726, 392647 |
| CVE-2014-8677 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.3 | MEDIUM | 340155, 390726, 392647 |
| CVE-2014-9609 | Netsweeper 4.0.8 - Directory Traversal | netsweeper | 5.3 | medium | 347009 |
| CVE-2015-2826 | WordPress Plugin Simple Ads Manager - Information Disclosure | simple ads manager | 5.3 | MEDIUM | 344370 |
| CVE-2015-5471 | Swim Team <= v1.44.10777 - Local File Inclusion | swim_team | 5.3 | medium | 347009 |
| CVE-2017-9978 | QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities | quantastor | 5.3 | MEDIUM | 392301 |
| CVE-2018-16059 | WirelessHART Fieldgate SWG70 3.0 - Local File Inclusion | wirelesshart_fieldgate_swg70_firmware | 5.3 | medium | 392301 |
| CVE-2018-3167 | Oracle E-Business Suite - Blind SSRF | application_management_pack | 5.3 | medium | 392301 |
| CVE-2019-17503 | Kirona Dynamic Resource Scheduler - Information Disclosure | dynamic_resource_scheduling | 5.3 | medium | 312863 |
| CVE-2019-18393 | Ignite Realtime Openfire <4.42 - Local File Inclusion | openfire | 5.3 | medium | 347019 |
| CVE-2019-8446 | Jira Improper Authorization | jira_server | 5.3 | medium | 392301 |
| CVE-2020-11798 | Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal | micollab_audio,web&_video_conferencing | 5.3 | medium | 347009 |
| CVE-2021-20150 | Trendnet AC2600 TEW-827DRU - Credentials Disclosure | tew-827dru_firmware | 5.3 | medium | 392301 |
| CVE-2021-23241 | MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusion | mercury_x18g_firmware | 5.3 | medium | 347009 |
| CVE-2021-26085 | Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read | confluence data center | 5.3 | MEDIUM | 390727, 392301, 392648 |
| CVE-2021-26086 | Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read | jira data center | 5.3 | MEDIUM | 345113, 390727, 392301, 392648 |
| CVE-2021-28377 | Joomla! ChronoForums 2.0.11 - Local File Inclusion | chronoforums | 5.3 | medium | 347009 |
| CVE-2021-34429 | Eclipse Jetty 11.0.5 - Sensitive File Disclosure | jetty | 5.3 | MEDIUM | 390703 |
| CVE-2021-4191 | GitLab GraphQL API User Enumeration | gitlab | 5.3 | MEDIUM | 344361 |
| CVE-2022-25356 | Alt-n/MDaemon Security Gateway <=8.5.0 - XML Injection | securitygateway | 5.3 | medium | 390716 |
| CVE-2022-25497 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 5.3 | MEDIUM | 344360 |
| CVE-2022-28666 | Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update | - | 5.3 | medium | 392301 |
| CVE-2022-31062 | GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion | glpi inventory | 5.3 | MEDIUM | 344360 |
| CVE-2023-2059 | DedeCMS 5.7.87 - Directory Traversal | dedecms | 5.3 | medium | 347019 |
| CVE-2023-30943 | Moodle - Cross-Site Scripting/Remote Code Execution | moodle | 5.3 | medium | 347198 |
| CVE-2023-41599 | JFinalCMS v5.0.0 - Directory Traversal | jfinalcms | 5.3 | medium | 347009 |
| CVE-2023-44982 | WordPress Perfect Images (WP Retina 2x) < 6.4.6 - Sensitive Information Exposure | perfect-images | 5.3 | medium | 390716 |
| CVE-2024-2473 | WPS Hide Login <= 1.9.15.2 - Login Page Disclosure | wps-hide-login | 5.3 | MEDIUM | 377360 |
| CVE-2024-28397 | pyload-ng js2py - Remote Code Execution | pyload | 5.3 | medium | 340014 |
| CVE-2024-53586 | WebFileSys 2.31.0 - Directory Path Traversal | - | 5.3 | MEDIUM | 340007, 390726, 392647 |
| CVE-2024-7339 | TVT DVR Sensitive Device - Information Disclosure | - | 5.3 | medium | 392301 |
| CVE-2024-8852 | All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure | all-in-one wp migration | 5.3 | MEDIUM | 390716 |
| CVE-2025-10493 | Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie | - | 5.3 | MEDIUM | 390726, 392647 |
| CVE-2025-11368 | LearnPress < 4.3.0 - Arbitrary Callback Execution to Information Exposure | learnpress | 5.3 | MEDIUM | 344365 |
| CVE-2025-14528 | D-Link DIR-803 - Authentication Bypass | - | 5.3 | high | 390722 |
| CVE-2025-1743 | Pichome 2.1.0 - Arbitrary File Read | Pichome | 5.3 | high | 347009 |
| CVE-2025-2710 | Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting | ufida_erp-nc | 5.3 | MEDIUM | 341266 |
| CVE-2025-31125 | Vite Development Server - Path Traversal | - | 5.3 | medium | 347009 |
| CVE-2025-31486 | Vite server.fs.deny Bypass - Local File Inclusion | - | 5.3 | medium | 347009 |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code Execution | endpoint_manager_mobile | 5.3 | critical | 393655 |
| CVE-2025-46550 | YesWiki < 4.5.4 - Cross-Site Scripting | yeswiki | 5.3 | medium | 341266 |
| CVE-2025-46565 | Vite Dev Server - Information Exposure | - | 5.3 | medium | 390709 |
| CVE-2025-5569 | IdeaCMS <= 1.7 - SQL Injection | IdeaCMS | 5.3 | MEDIUM | 341245 |
| CVE-2026-23483 | Blinko <= 1.8.3 - Path Traversal via /plugins | blinko | 5.3 | medium | 347009 |
| CVE-2026-8385 | WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosure | wp-google-maps | 5.3 | MEDIUM | 344365 |
| CVE-2026-50230 | Lyrion Music Server <= 9.2.0 - Cross-Site Scripting | the server.log endpoint that | 5.1 | MEDIUM | 341266 |
| CVE-2000-0114 | Microsoft FrontPage Extensions - Information Disclosure | internet_information_server | 5.0 | MEDIUM | 392301 |
| CVE-2006-3392 | Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure | webmin | 5.0 | MEDIUM | 347009 |
| CVE-2006-3835 | toutvirtual virtualiq pro 3.2 - Multiple Vulnerabilities | tomcat | 5.0 | MEDIUM | 392301 |
| CVE-2007-4504 | Joomla! RSfiles <=1.0.2 - Local File Inclusion | rsfiles | 5.0 | MEDIUM | 347009 |
| CVE-2008-4764 | Joomla! <=2.0.0 RC2 - Local File Inclusion | com_extplorer | 5.0 | MEDIUM | 347009 |
| CVE-2008-6080 | Joomla! ionFiles 4.4.2 - Local File Inclusion | com_ionfiles | 5.0 | MEDIUM | 347009 |
| CVE-2008-6222 | Joomla! ProDesk 1.0/1.2 - Local File Inclusion | pro_desk_support_center | 5.0 | MEDIUM | 347009 |
| CVE-2008-6668 | nweb2fax <=0.2.7 - Local File Inclusion | nweb2fax | 5.0 | MEDIUM | 347009 |
| CVE-2009-1496 | Joomla! Cmimarketplace 0.1 - Local File Inclusion | joomla | 5.0 | MEDIUM | 347009 |
| CVE-2009-2100 | Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion | joomla | 5.0 | MEDIUM | 347009 |
| CVE-2009-5114 | WebGlimpse 2.18.7 - Directory Traversal | webglimpse | 5.0 | MEDIUM | 347009 |
| CVE-2010-0696 | Joomla! Component Jw_allVideos - Arbitrary File Retrieval | jw_allvideos | 5.0 | MEDIUM | 347009 |
| CVE-2010-0942 | Joomla! Component com_jvideodirect - Directory Traversal | com_jvideodirect | 5.0 | MEDIUM | 347009 |
| CVE-2010-0943 | Joomla! Component com_jashowcase - Directory Traversal | com_jashowcase | 5.0 | MEDIUM | 347009 |
| CVE-2010-0944 | Joomla! Component com_jcollection - Directory Traversal | com_jcollection | 5.0 | MEDIUM | 347009 |
| CVE-2010-1081 | Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion | com_communitypolls | 5.0 | MEDIUM | 347009 |
| CVE-2010-1302 | Joomla! Component DW Graph - Local File Inclusion | com_dwgraphs | 5.0 | MEDIUM | 347009 |
| CVE-2010-1304 | Joomla! Component User Status - Local File Inclusion | com_userstatus | 5.0 | MEDIUM | 347009 |
| CVE-2010-1305 | Joomla! Component JInventory 1.23.02 - Local File Inclusion | com_jinventory | 5.0 | MEDIUM | 347009 |
| CVE-2010-1307 | Joomla! Component Magic Updater - Local File Inclusion | com_joomlaupdater | 5.0 | MEDIUM | 347009 |
| CVE-2010-1308 | Joomla! Component SVMap 1.1.1 - Local File Inclusion | com_svmap | 5.0 | MEDIUM | 347009 |
| CVE-2010-1312 | Joomla! Component News Portal 1.5.x - Local File Inclusion | com_news_portal | 5.0 | MEDIUM | 347009 |
| CVE-2010-1314 | Joomla! Component Highslide 1.5 - Local File Inclusion | com_hsconfig | 5.0 | MEDIUM | 347009 |
| CVE-2010-1315 | Joomla! Component webERPcustomer - Local File Inclusion | com_weberpcustomer | 5.0 | MEDIUM | 347009 |
| CVE-2010-1340 | Joomla! Component com_jresearch - 'Controller' Local File Inclusion | com_jresearch | 5.0 | MEDIUM | 347009 |
| CVE-2010-1345 | Joomla! Component Cookex Agency CKForms - Local File Inclusion | com_ckforms | 5.0 | MEDIUM | 347009 |
| CVE-2010-1352 | Joomla! Component Juke Box 1.7 - Local File Inclusion | com_jukebox | 5.0 | MEDIUM | 347009 |
| CVE-2010-1353 | Joomla! Component LoginBox - Local File Inclusion | com_loginbox | 5.0 | MEDIUM | 347009 |
| CVE-2010-1354 | Joomla! Component VJDEO 1.0 - Local File Inclusion | com_vjdeo | 5.0 | MEDIUM | 347009 |
| CVE-2010-1429 | Red Hat JBoss Enterprise Application Platform - Sensitive Information Disclosure | jboss_enterprise_application_platform | 5.0 | MEDIUM | 382240 |
| CVE-2010-1461 | Joomla! Component Photo Battle 1.0.1 - Local File Inclusion | com_photobattle | 5.0 | MEDIUM | 347009 |
| CVE-2010-1491 | Joomla! Component MMS Blog 2.3.0 - Local File Inclusion | com_mmsblog | 5.0 | MEDIUM | 347009 |
| CVE-2010-1494 | Joomla! Component AWDwall 1.5.4 - Local File Inclusion | com_awdwall | 5.0 | MEDIUM | 347009 |
| CVE-2010-1532 | Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion | com_powermail | 5.0 | MEDIUM | 347009 |
| CVE-2010-1534 | Joomla! Component Shoutbox Pro - Local File Inclusion | com_shoutbox | 5.0 | MEDIUM | 347009 |
| CVE-2010-1540 | Joomla! Component com_blog - Directory Traversal | com_myblog | 5.0 | MEDIUM | 347009 |
| CVE-2010-1601 | Joomla! Component JA Comment - Local File Inclusion | com_jacomment | 5.0 | MEDIUM | 347009 |
| CVE-2010-1657 | Joomla! Component SmartSite 1.0.0 - Local File Inclusion | com_smartsite | 5.0 | MEDIUM | 347009 |
| CVE-2010-1658 | Joomla! Component NoticeBoard 1.3 - Local File Inclusion | com_noticeboard | 5.0 | MEDIUM | 347009 |
| CVE-2010-1659 | Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusion | com_ultimateportfolio | 5.0 | MEDIUM | 347009 |
| CVE-2010-1714 | Joomla! Component Arcade Games 1.0 - Local File Inclusion | com_arcadegames | 5.0 | MEDIUM | 347009 |
| CVE-2010-1858 | Joomla! Component SMEStorage - Local File Inclusion | com_smestorage | 5.0 | MEDIUM | 347009 |
| CVE-2010-1982 | Joomla! Component JA Voice 2.0 - Local File Inclusion | com_javoice | 5.0 | MEDIUM | 347009 |
| CVE-2010-2018 | Lokomedia CMS - Local File Inclusion | lokomedia cms | 5.0 | MEDIUM | 347009 |
| CVE-2010-2307 | Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal | surfboard_sbv6120e | 5.0 | MEDIUM | 347009 |
| CVE-2010-3203 | Joomla! Component PicSell 1.0 - Arbitrary File Retrieval | com_picsell | 5.0 | MEDIUM | 344360 |
| CVE-2011-0049 | Majordomo2 - SMTP/HTTP Directory Traversal | majordomo_2 | 5.0 | medium | 347009 |
| CVE-2011-1669 | WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI) | wp_custom_pages | 5.0 | medium | 347009 |
| CVE-2011-2780 | Chyrp 2.x - Local File Inclusion | chyrp | 5.0 | medium | 347009 |
| CVE-2011-4804 | Joomla! Component com_kp - 'Controller' Local File Inclusion | com_obsuggest | 5.0 | medium | 347009 |
| CVE-2011-4898 | WordPress Core 3.3.1 - Multiple Vulnerabilities | wordpress | 5.0 | MEDIUM | 340147, 390727, 392301, 392648 |
| CVE-2012-0896 | Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access | count_per_day | 5.0 | medium | 347009 |
| CVE-2012-0981 | phpShowtime 2.0 - Directory Traversal | phpshowtime | 5.0 | medium | 347009 |
| CVE-2012-0996 | 11in1 CMS 1.2.1 - Local File Inclusion (LFI) | 11in1 | 5.0 | medium | 347009 |
| CVE-2012-5192 | Bitweaver 2.8.1 - Multiple Vulnerabilities | bitweaver | 5.0 | MEDIUM | 340147, 380026 |
| CVE-2012-5451 | TVMOBiLi 2.1.0.3557 - Denial of Service | tvmobili | 5.0 | MEDIUM | 390727, 392301, 392648 |
| CVE-2012-5875 | FireFly Mediaserver 1.0.0.1359 - Null Pointer Dereference | firefly media server | 5.0 | MEDIUM | 390727, 392301, 392648 |
| CVE-2012-5876 | Nero MediaHome 4.5.8.0 - Denial of Service | mediahome | 5.0 | MEDIUM | 390726, 390727, 392301, 392647, 392648 |
| CVE-2012-5877 | Nero MediaHome 4.5.8.0 - Denial of Service | mediahome | 5.0 | MEDIUM | 390726, 390727, 392301, 392647, 392648 |
| CVE-2013-5979 | Xibo 1.2.2/1.4.1 - Directory Traversal | xibo | 5.0 | medium | 347009 |
| CVE-2013-6043 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 5.0 | MEDIUM | 333140, 344360, 390726, 392647 |
| CVE-2013-7091 | Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion | zimbra_collaboration_suite | 5.0 | medium | 347009, 390614 |
| CVE-2013-7240 | WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversal | advanced_dewplayer | 5.0 | medium | 344360 |
| CVE-2014-4577 | WP AmASIN – The Amazon Affiliate Shop - Local File Inclusion | wp_amasin_-_the_amazon_affiliate_shop | 5.0 | MEDIUM | 347009 |
| CVE-2014-4940 | WordPress Plugin Tera Charts - Local File Inclusion | tera-charts | 5.0 | medium | 347009 |
| CVE-2014-4941 | Cross RSS 1.7 - Local File Inclusion | wp-cross-rss | 5.0 | MEDIUM | 347009 |
| CVE-2014-5111 | Fonality trixbox - Local File Inclusion | trixbox | 5.0 | medium | 347009 |
| CVE-2014-5181 | Last.fm Rotation 1.0 - Path Traversal | lastfm-rotation_plugin | 5.0 | MEDIUM | 347009 |
| CVE-2014-5187 | Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversal | tom-m8te_plugin | 5.0 | MEDIUM | 347009 |
| CVE-2014-5368 | WordPress Plugin WP Content Source Control - Directory Traversal | wp_content_source_control | 5.0 | medium | 344360 |
| CVE-2014-6308 | Osclass Security Advisory 3.4.1 - Local File Inclusion | osclass | 5.0 | medium | 347009 |
| CVE-2014-8799 | WordPress Plugin DukaPress 2.5.2 - Directory Traversal | dukapress | 5.0 | medium | 344360 |
| CVE-2014-9119 | WordPress DB Backup <=4.5 - Local File Inclusion | db_backup | 5.0 | medium | 344360 |
| CVE-2015-1579 | WordPress Slider Revolution - Local File Disclosure | divi | 5.0 | medium | 344360 |
| CVE-2015-2067 | Magento Server MAGMI - Directory Traversal | magmi | 5.0 | medium | 347009 |
| CVE-2015-2166 | Ericsson Drutt MSDP - Local File Inclusion | drutt_mobile_service_delivery_platform | 5.0 | medium | 347009 |
| CVE-2015-3897 | Bonita BPM Portal <6.5.3 - Local File Inclusion | bonita_bpm_portal | 5.0 | medium | 340007, 344360 |
| CVE-2015-4414 | WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversal | se_html5_album_audio_player | 5.0 | medium | 347009 |
| CVE-2015-4666 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 5.0 | MEDIUM | 344360, 347009, 347198, 390726, 392647 |
| CVE-2015-5285 | Kallithea 0.2.9 - 'came_from' HTTP Response Splitting | kallithea | 5.0 | MEDIUM | 390722, 390727, 392648 |
| CVE-2015-5531 | ElasticSearch <1.6.1 - Local File Inclusion | elasticsearch | 5.0 | medium | 347009, 392301 |
| CVE-2015-5688 | Geddy <13.0.8 - Local File Inclusion | geddy | 5.0 | medium | 347009 |
| CVE-2014-0865 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.9 | MEDIUM | 392301 |
| CVE-2014-0868 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.9 | MEDIUM | 392301 |
| CVE-2015-4425 | Pimcore CMS Build 3450 - Directory Traversal | pimcore | 4.9 | MEDIUM | 390726, 392647 |
| CVE-2019-2588 | Oracle Business Intelligence - Path Traversal | business_intelligence_publisher | 4.9 | medium | 347019 |
| CVE-2021-24966 | WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated) | error log viewer | 4.9 | MEDIUM | 344360 |
| CVE-2022-2863 | WordPress WPvivid Backup <0.9.76 - Local File Inclusion | migration,_backup,_staging | 4.9 | MEDIUM | 377360 |
| CVE-2022-40843 | Tenda AC1200 V-W15Ev2 - Authentication Bypass | ac1200_v-w15ev2 | 4.9 | medium | 390716 |
| CVE-2023-34259 | Kyocera TASKalfa printer - Path Traversal | d-copia253mf_plus_firmware | 4.9 | medium | 347009 |
| CVE-2024-10708 | System Dashboard < 2.8.15 - Admin+ Path Traversal | system_dashboard | 4.9 | MEDIUM | 377360 |
| CVE-2016-4807 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 4.8 | MEDIUM | 344360 |
| CVE-2017-14651 | WSO2 Data Analytics Server 3.1.0 - Cross-Site Scripting | api_manager | 4.8 | medium | 347198 |
| CVE-2018-1000856 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-1002001 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-1002002 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-1002003 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-1002004 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-1002005 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-1002006 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-1002007 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-1002008 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-1002009 | WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting | arigato autoresponder and newsletter | 4.8 | MEDIUM | 380122, 390726, 392647 |
| CVE-2018-19749 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-19751 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-19752 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-19892 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-19914 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-19915 | DomainMOD <=4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-20009 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-20010 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2018-20011 | DomainMOD 4.11.01 - Cross-Site Scripting | domainmod | 4.8 | medium | 340147 |
| CVE-2019-15829 | Gallery Photoblocks < 1.1.43 - Cross-Site Scripting | gallery_photoblocks | 4.8 | medium | 347198 |
| CVE-2020-29240 | LEPTON CMS 4.7.0 - 'URL' Persistent Cross-Site Scripting | leptoncms | 4.8 | MEDIUM | 333141 |
| CVE-2020-29470 | OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting | opencart | 4.8 | MEDIUM | 342259 |
| CVE-2020-29477 | Invision Community 4.5.4 - 'Field Name' Stored Cross-Site Scripting | community | 4.8 | MEDIUM | 340147 |
| CVE-2020-35241 | Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting | flatpress | 4.8 | MEDIUM | 344370, 390724 |
| CVE-2020-9314 | Oracle iPlanet Web Server 7.0.x - Image Injection | iplanet_web_server | 4.8 | medium | 340162 |
| CVE-2021-24681 | Duplicate Page WordPress - Stored Cross-Site Scripting | duplicate_page | 4.8 | MEDIUM | 377360 |
| CVE-2021-24991 | WooCommerce PDF Invoices & Packing Slips WordPress Plugin < 2.10.5 - Cross-Site Scripting | woocommerce_pdf_invoices&_packing_slips | 4.8 | medium | 347198 |
| CVE-2021-46068 | Vehicle Service Management System - Stored Cross-Site Scripting | vehicle_service_management_system | 4.8 | medium | 340147 |
| CVE-2021-46069 | Vehicle Service Management System 1.0 - Stored Cross Site Scripting | vehicle_service_management_system | 4.8 | medium | 340147 |
| CVE-2021-46071 | ehicle Service Management System 1.0 - Cross-Site Scripting | vehicle_service_management_system | 4.8 | medium | 340147 |
| CVE-2021-46072 | Vehicle Service Management System 1.0 - Stored Cross Site Scripting | vehicle_service_management_system | 4.8 | medium | 340147 |
| CVE-2021-46073 | Vehicle Service Management System 1.0 - Cross Site Scripting | vehicle_service_management_system | 4.8 | medium | 340147 |
| CVE-2022-0535 | WordPress E2Pdf <1.16.45 - Cross-Site Scripting | e2pdf | 4.8 | MEDIUM | 377360 |
| CVE-2022-0873 | WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scripting | gmedia_gallery | 4.8 | MEDIUM | 377360 |
| CVE-2022-1029 | Limit Login Attempts - Stored Cross-Site Scripting | limit login attempts | 4.8 | MEDIUM | 377360 |
| CVE-2022-4260 | WordPress WP-Ban <1.69.1 - Stored Cross-Site Scripting | wp-ban | 4.8 | MEDIUM | 377360 |
| CVE-2023-0563 | Bank Locker Management System - Cross-Site Scripting | bank_locker_management_system | 4.8 | medium | 340147 |
| CVE-2023-2009 | Pretty Url <= 1.5.4 - Cross-Site Scripting | pretty_url | 4.8 | MEDIUM | 377360 |
| CVE-2023-2178 | Aajoda Testimonials < 2.2.2 - Cross-Site Scripting | aajoda_testimonials | 4.8 | MEDIUM | 377360 |
| CVE-2023-2224 | Seo By 10Web < 1.2.7 - Cross-Site Scripting | seo | 4.8 | MEDIUM | 377360 |
| CVE-2022-2546 | WordPress All-in-One WP Migration <=7.62 - Cross-Site Scripting | all-in-one_wp_migration | 4.7 | MEDIUM | 377360 |
| CVE-2023-45671 | Frigate < 0.13.0 Beta 3 - Cross-Site Scripting | frigate | 4.7 | medium | 347198 |
| CVE-2024-0986 | Issabel Authenticated - Remote Code Execution | pbx | 4.7 | medium | 344362 |
| CVE-2024-13627 | OWL Carousel Slider - Cross-Site Scripting | owl_carousel_slider | 4.7 | MEDIUM | 377360 |
| CVE-2024-24050 | Workout Journal App 1.0 - Stored XSS | workout journal app | 4.7 | MEDIUM | 380026, 390727, 392301, 392648 |
| CVE-2005-3128 | SquirrelMail Address Add 1.4.2 - Cross-Site Scripting | address add plugin | 4.3 | MEDIUM | 341266 |
| CVE-2005-4385 | Cofax <=2.0RC3 - Cross-Site Scripting | cofax | 4.3 | MEDIUM | 341266 |
| CVE-2006-1681 | Cherokee HTTPD <=0.5 - Cross-Site Scripting | cherokee_httpd | 4.3 | MEDIUM | 341266 |
| CVE-2007-2449 | Apache Tomcat 4.x-7.x - Cross-Site Scripting | tomcat | 4.3 | MEDIUM | 341266 |
| CVE-2007-3385 | Apache Tomcat 6.0.15 - Cookie Quote Handling Remote Information Disclosure | tomcat | 4.3 | MEDIUM | 390727, 392301, 392648 |
| CVE-2007-5728 | phpPgAdmin <=4.1.1 - Cross-Site Scripting | phppgadmin | 4.3 | MEDIUM | 341266 |
| CVE-2008-1061 | WordPress Sniplets <=1.2.2 - Cross-Site Scripting | sniplets_plugin | 4.3 | MEDIUM | 341266 |
| CVE-2008-1547 | Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection | exchange_server | 4.3 | MEDIUM | 390716 |
| CVE-2008-2398 | AppServ Open Project <=2.5.10 - Cross-Site Scripting | appserv | 4.3 | MEDIUM | 333141 |
| CVE-2008-2938 | toutvirtual virtualiq pro 3.2 - Multiple Vulnerabilities | tomcat | 4.3 | MEDIUM | 392301 |
| CVE-2008-5587 | phpPgAdmin <=4.2.1 - Local File Inclusion | phppgadmin | 4.3 | MEDIUM | 347009 |
| CVE-2008-6465 | Parallels H-Sphere 3.0.0 P9/3.1 P1 - Cross-Site Scripting | h-sphere | 4.3 | MEDIUM | 347198 |
| CVE-2008-6982 | Devalcms 1.4a - Cross-Site Scripting | devalcms | 4.3 | MEDIUM | 341266 |
| CVE-2009-1872 | Adobe Coldfusion <=8.0.1 - Cross-Site Scripting | coldfusion | 4.3 | MEDIUM | 341266 |
| CVE-2010-0982 | Joomla! Component com_cartweberp - Local File Inclusion | com_cartweberp | 4.3 | MEDIUM | 347009 |
| CVE-2010-1217 | Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion | je_form_creator | 4.3 | MEDIUM | 347009 |
| CVE-2010-1313 | Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion | com_sebercart | 4.3 | MEDIUM | 347009 |
| CVE-2010-5278 | MODx manager - Local File Inclusion | modx_revolution | 4.3 | medium | 390614 |
| CVE-2011-4451 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 4.3 | MEDIUM | 344360, 390715, 390726, 392647 |
| CVE-2011-4618 | Advanced Text Widget < 2.0.2 - Cross-Site Scripting | advanced_text_widget_plugin | 4.3 | medium | 341266 |
| CVE-2011-4624 | GRAND FlAGallery 1.57 - Cross-Site Scripting | grand_flagallery | 4.3 | MEDIUM | 341266 |
| CVE-2011-4926 | Adminimize 1.7.22 - Cross-Site Scripting | adminimize | 4.3 | MEDIUM | 341266 |
| CVE-2011-5106 | WordPress Plugin Flexible Custom Post Type < 0.1.7 - Cross-Site Scripting | flexible_custom_post_type | 4.3 | medium | 341266 |
| CVE-2011-5107 | Alert Before Your Post <= 0.1.1 - Cross-Site Scripting | alert_before_you_post | 4.3 | MEDIUM | 341266 |
| CVE-2011-5179 | Skysa App Bar 1.04 - Cross-Site Scripting | skysa_app_bar_integration_plugin | 4.3 | MEDIUM | 341266 |
| CVE-2011-5181 | ClickDesk Live Support Live Chat 2.0 - Cross-Site Scripting | clickdesk_live_support-live_chat_plugin | 4.3 | MEDIUM | 341266 |
| CVE-2011-5265 | Featurific For WordPress 1.6.2 - Cross-Site Scripting | featurific-for-wordpress | 4.3 | MEDIUM | 341266 |
| CVE-2012-0285 | stoneware webnetwork6 - Multiple Vulnerabilities | webnetwork | 4.3 | MEDIUM | 390726, 392301, 392647 |
| CVE-2012-0782 | WordPress Core 3.3.1 - Multiple Vulnerabilities | wordpress | 4.3 | MEDIUM | 340147, 390727, 392301, 392648 |
| CVE-2012-0901 | YouSayToo auto-publishing 1.0 - Cross-Site Scripting | yousaytoo | 4.3 | MEDIUM | 341266 |
| CVE-2012-1835 | WordPress Plugin All-in-One Event Calendar 1.4 - Cross-Site Scripting | all-in-one_event_calendar | 4.3 | MEDIUM | 341266 |
| CVE-2012-2371 | WP-FaceThumb 0.1 - Cross-Site Scripting | wp-facethumb | 4.3 | MEDIUM | 341266 |
| CVE-2012-4242 | WordPress Plugin MF Gig Calendar 0.9.2 - Cross-Site Scripting | mf_gig_calendar | 4.3 | MEDIUM | 341266 |
| CVE-2012-4253 | MySQLDumper 1.24.4 - Directory Traversal | mysqldumper | 4.3 | medium | 347009 |
| CVE-2012-4273 | 2 Click Socialmedia Buttons < 0.34 - Cross-Site Scripting | 2-click-social-media-buttons | 4.3 | MEDIUM | 341266 |
| CVE-2012-4547 | AWStats 6.95/7.0 - 'awredir.pl' Cross-Site Scripting | awstats | 4.3 | medium | 341266 |
| CVE-2012-4768 | WordPress Plugin Download Monitor < 3.3.5.9 - Cross-Site Scripting | download_monitor | 4.3 | MEDIUM | 341266 |
| CVE-2012-4889 | ManageEngine Firewall Analyzer 7.2 - Cross-Site Scripting | firewall_analyzer | 4.3 | medium | 341266 |
| CVE-2012-5913 | WordPress Integrator 1.32 - Cross-Site Scripting | wordpress_integrator | 4.3 | MEDIUM | 341266 |
| CVE-2013-2287 | WordPress Plugin Uploader 1.0.4 - Cross-Site Scripting | uploader | 4.3 | MEDIUM | 341266 |
| CVE-2013-2682 | Cisco Linksys E4200 - Multiple Vulnerabilities | linksys e4200 firmware | 4.3 | MEDIUM | 392301 |
| CVE-2013-3526 | WordPress Plugin Traffic Analyzer - 'aoid' Cross-Site Scripting | trafficanalyzer | 4.3 | MEDIUM | 341266 |
| CVE-2013-4117 | WordPress Plugin Category Grid View Gallery 2.3.1 - Cross-Site Scripting | category-grid-view-gallery | 4.3 | MEDIUM | 341266 |
| CVE-2013-4625 | WordPress Plugin Duplicator < 0.4.5 - Cross-Site Scripting | duplicator | 4.3 | MEDIUM | 341266 |
| CVE-2013-6042 | Webuzo 2.1.3 - Multiple Vulnerabilities | webuzo | 4.3 | MEDIUM | 333140, 344360, 390726, 392647 |
| CVE-2013-6281 | WordPress Spreadsheet - Cross-Site Scripting | dhtmlxspreadsheet | 4.3 | medium | 341266 |
| CVE-2014-0191 | eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injection | fusion middleware | 4.3 | MEDIUM | 390727, 392301, 392648 |
| CVE-2014-0866 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.3 | MEDIUM | 392301 |
| CVE-2014-0869 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.3 | MEDIUM | 392301 |
| CVE-2014-0870 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.3 | MEDIUM | 392301 |
| CVE-2014-0871 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 4.3 | MEDIUM | 392301 |
| CVE-2014-1944 | Ilch CMS 2.0 - Persistent Cross-Site Scripting | ilch cms | 4.3 | MEDIUM | 344370 |
| CVE-2014-2908 | Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting | simatic_s7_cpu_1200_firmware | 4.3 | medium | 341266 |
| CVE-2014-4513 | ActiveHelper LiveHelp Server 3.1.0 - Cross-Site Scripting | activehelper_livehelp_live_chat | 4.3 | MEDIUM | 341266 |
| CVE-2014-9094 | WordPress DZS-VideoGallery Plugin Cross-Site Scripting | video_gallery | 4.3 | MEDIUM | 341266 |
| CVE-2014-9146 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 4.3 | MEDIUM | 344360, 390720, 390726, 392647 |
| CVE-2014-9444 | Frontend Uploader <= 0.9.2 - Cross-Site Scripting | frontend_uploader | 4.3 | medium | 341266 |
| CVE-2015-1389 | Aruba ClearPass Policy Manager - Persistent Cross-Site Scripting | clearpass policy manager | 4.3 | MEDIUM | 333141 |
| CVE-2015-1880 | Fortinet FortiOS <=5.2.3 - Cross-Site Scripting | fortios | 4.3 | medium | 341266 |
| CVE-2015-2068 | Magento Server Mass Importer - Cross-Site Scripting | magmi | 4.3 | medium | 341266 |
| CVE-2015-2275 | WoltLab Community Gallery - Persistent Cross-Site Scripting | community gallery | 4.3 | MEDIUM | 340147, 390726, 392647 |
| CVE-2015-2807 | Navis DocumentCloud <0.1.1 - Cross-Site Scripting | navis_documentcloud | 4.3 | MEDIUM | 341266 |
| CVE-2015-3337 | Elasticsearch - Local File Inclusion | elasticsearch | 4.3 | medium | 347009 |
| CVE-2015-4127 | WordPress Church Admin <0.810 - Cross-Site Scripting | church_admin | 4.3 | MEDIUM | 341266 |
| CVE-2015-4665 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 4.3 | MEDIUM | 344360, 347198, 390726, 392647 |
| CVE-2015-6402 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter | 4.3 | MEDIUM | 333141, 340147, 344363, 390726, 392301, 392647 |
| CVE-2015-6477 | Nordex NC2 - Cross-Site Scripting | nordex_control_2_scada | 4.3 | medium | 340147 |
| CVE-2015-6920 | WordPress sourceAFRICA <=0.1.3 - Cross-Site Scripting | sourceafrica | 4.3 | MEDIUM | 341266 |
| CVE-2018-18777 | Microstrategy Web 7 - Local File Inclusion | microstrategy_web | 4.3 | medium | 347009 |
| CVE-2020-7318 | McAfee ePolicy Orchestrator <5.10.9 Update 9 - Cross-Site Scripting | epolicy_orchestrator | 4.3 | medium | 347198 |
| CVE-2021-42663 | Sourcecodester Online Event Booking and Reservation System 2.3.0 - Cross-Site Scripting | online_event_booking_and_reservation_system | 4.3 | medium | 341266 |
| CVE-2022-0377 | WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming | learnpress | 4.3 | MEDIUM | 340007 |
| CVE-2022-29495 | WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery | popup builder | 4.3 | MEDIUM | 377360 |
| CVE-2024-34061 | Changedetection.io <=v0.45.21 - Cross-Site Scripting | - | 4.3 | medium | 333141 |
| CVE-2024-4348 | osCommerce v4.0 - Cross-site Scripting | oscommerce | 4.3 | medium | 340147 |
| CVE-2024-7928 | FastAdmin < V1.3.4.20220530 - Path Traversal | fastadmin | 4.3 | medium | 340007 |
| CVE-2025-2127 | JoomlaUX JUX Real Estate 3.4.0 - Reflected XSS | jux_real_estate | 4.3 | medium | 341266 |
| CVE-2025-41228 | VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS) | - | 4.3 | MEDIUM | 341266, 390727, 392648 |
| CVE-2011-4640 | WebTitan < 3.60 - Local File Inclusion | webtitan | 4.0 | medium | 347009 |
| CVE-2013-5528 | Cisco Unified Communications Manager 7/8/9 - Directory Traversal | unified_communications_manager | 4.0 | medium | 347009 |
| CVE-2014-1222 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | vtiger crm | 4.0 | MEDIUM | 344360, 390720, 390726, 392647 |
| CVE-2014-5258 | webEdition 6.3.8.0 - Directory Traversal | webedition_cms | 4.0 | medium | 347009 |
| CVE-2026-55592 | Dashy <= 4.3.6 - Reflected XSS via Workspace | dashy | 3.9 | LOW | 340112 |
| CVE-2019-19411 | Huawei Firewall - Local File Inclusion | usg9500 | 3.7 | low | 347009 |
| CVE-2012-0991 | OpenEMR 4.1 - Local File Inclusion | openemr | 3.5 | low | 347009 |
| CVE-2014-0894 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | 3.5 | LOW | 392301 |
| CVE-2015-4063 | NewStatPress <0.9.9 - Cross-Site Scripting | newstatpress | 3.5 | low | 341266 |
| CVE-2021-25075 | WordPress Duplicate Page or Post <1.5.1 - Cross-Site Scripting | duplicate_page_or_post | 3.5 | LOW | 377360 |
| CVE-2024-4841 | LoLLMS WebUI - Subfolder Prediction via Path Traversal | lollms-webui | 3.3 | LOW | 344365 |
| CVE-2023-2252 | Directorist < 7.5.4 - Local File Inclusion | directorist | 2.7 | low | 347009 |
| CVE-2013-5759 | Yealink VoIP Phone SIP-T38G - Privilege Escalation | - | N/A | info | 344360, 390726, 392647 |
| CVE-2018-10818 | LG NAS Devices - Remote Code Execution | - | N/A | critical | 340014 |
| CVE-2018-25114 | osCommerce 2.3.4.1 - Remote Code Execution | - | N/A | critical | 344360 |
| CVE-2020-26073 | Cisco SD-WAN vManage Software - Local File Inclusion | - | N/A | high | 347009 |
| CVE-2021-40272 | IRTS OP5 Monitor - Cross-Site Scripting | monitor | N/A | medium | 347198 |
| CVE-2021-41691 | openSIS Student Information System 8.0 SQL Injection | - | N/A | high | 340159 |
| CVE-2022-29299 | SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting | solarview_compact_firmware | N/A | medium | 341266 |
| CVE-2022-29301 | SolarView Compact 6.00 - 'pow' Cross-Site Scripting | - | N/A | high | 341266 |
| CVE-2022-3254 | AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injection | - | N/A | critical | 340016 |
| CVE-2022-38322 | Temenos Transact - Cross-Site Scripting | - | N/A | high | 333141 |
| CVE-2022-43128 | Dreamer CMS v4.0.0 - SQL Injection | - | N/A | info | 380122 |
| CVE-2022-45836 | WordPress Download Manager <= 3.2.59 - Reflected XSS | - | N/A | high | 333141 |
| CVE-2023-1434 | Odoo - Cross-Site Scripting | odoo | N/A | medium | 341266 |
| CVE-2023-40600 | EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure | - | N/A | medium | 390716 |
| CVE-2023-42343 | OpenCMS - Cross-Site Scripting | opencms | N/A | medium | 347198 |
| CVE-2023-46391 | WEBIGniter v28.7.23 - Stored Cross Site Scripting (XSS) | - | N/A | info | 340147 |
| CVE-2023-52163 | Digiever DS-2105 Pro - Command Injection | - | N/A | high | 390709 |
| CVE-2024-0250 | Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect | - | N/A | medium | 340162 |
| CVE-2024-12585 | PropertyHive < 2.1.1 - Cross-Site Scripting | - | N/A | medium | 341266 |
| CVE-2024-14015 | Studiocart <= 2.9.0 - Cross-Site Scripting | - | N/A | medium | 341266 |
| CVE-2024-22024 | Ivanti Connect Secure - XXE | connect_secure | N/A | high | 380019 |
| CVE-2024-24497 | Employee Management System 1.0 - txtusername and txtpassword SQL Injection (Admin Login) | - | N/A | info | 340156 |
| CVE-2024-27564 | ChatGPT个人专用版 - Server Side Request Forgery | chatgpt_web | N/A | high | 347009 |
| CVE-2024-28734 | Coda v.2024Q1 - Cross-Site Scripting | Unit4 Financials by Coda prior to 2023Q4 | N/A | medium | 340112 |
| CVE-2024-2876 | Wordpress Email Subscribers by Icegram Express - SQL Injection | - | N/A | critical | 380122 |
| CVE-2024-30490 | ProfileGrid <= 5.7.8 - SQL Injection | ProfileGrid | N/A | critical | 380122 |
| CVE-2024-31750 | F-logic DataCube3 - SQL Injection | f-logic datacube3 v.1.0 | N/A | high | 340016 |
| CVE-2024-33113 | D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure | dir-845l | N/A | medium | 390722 |
| CVE-2024-33724 | SOPlanning 1.52.00 Cross Site Scripting | soplanning | N/A | medium | 341266 |
| CVE-2024-34257 | TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection | a3700r_firmware | N/A | high | 392301 |
| CVE-2024-36527 | Puppeteer Renderer - Directory Traversal | - | N/A | medium | 347009 |
| CVE-2024-36837 | CRMEB v.5.2.2 - SQL Injection | crmeb | N/A | high | 340156 |
| CVE-2024-38289 | TurboMeeting - Boolean-based SQL Injection | turbomeeting | N/A | critical | 340016 |
| CVE-2024-4879 | ServiceNow UI Macros - Template Injection | servicenow | N/A | critical | 342259 |
| CVE-2024-51483 | Changedetection.io <= 0.47.4 - Path Traversal | changedetection | N/A | medium | 340130 |
| CVE-2024-51977 | Brother MFC-L9570CDW - Information Disclosure | - | N/A | medium | 390709 |
| CVE-2024-5217 | ServiceNow - Incomplete Input Validation | servicenow | N/A | critical | 340159 |
| CVE-2024-52875 | Kerio Control v9.2.5 - CRLF Injection | - | N/A | high | 390716 |
| CVE-2024-6265 | UsersWP <= 1.2.10 - Unauthenticated SQL Injection | - | N/A | critical | 380122 |
| CVE-2024-9166 | TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution | - | N/A | critical | 340014 |
| CVE-2025-0133 | PAN-OS - Reflected Cross-Site Scripting | pan-os | N/A | medium | 341266 |
| CVE-2025-1303 | Plugin Oficial – Getnet para WooCommerce <= 1.8.0 - Cross-Site Scripting | - | N/A | medium | 341266 |
| CVE-2025-13138 | WP Directory Kit <= 1.4.3 - Unauthenticated SQL Injection | - | N/A | high | 380122 |
| CVE-2025-22214 | Landray EIS SQL注入漏洞 | - | N/A | critical | 340155 |
| CVE-2025-22785 | Course Booking System <= 6.0.6 - SQL Injection | ComMotion Course Booking System course-booking-system | N/A | critical | 380122 |
| CVE-2025-25231 | Omnissa Workspace ONE UEM - Path Traversal | workspace_one_uem_console | N/A | high | 340007 |
| CVE-2025-27222 | TRUfusion Enterprise <= 7.10.4.0 - Path Traversal | - | N/A | critical | 344360 |
| CVE-2025-32101 | UNA CMS <= 14.0.0-RC4 - PHP Object Injection | - | N/A | critical | 390501, 390614 |
| CVE-2025-32257 | 1 Click WordPress Migration <= 2.2 - Unauthenticated Information Disclsoure | 1-click-migration | N/A | medium | 390716 |
| CVE-2025-34073 | Maltrail <=0.54 Username Parameter - Remote Command Execution | - | N/A | critical | 340014 |
| CVE-2025-34152 | Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via time Parameter | - | N/A | critical | 393655 |
| CVE-2025-4078 | Wangshen SecGate 3600 Path Traversal Vulnerability | - | N/A | medium | 347009 |
| CVE-2025-46549 | YesWiki <= 4.5.1 - Cross-Site Scripting | - | N/A | medium | 341266 |
| CVE-2025-47204 | Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting | - | N/A | medium | 340147 |
| CVE-2025-55169 | WeGIA - Directory Traversal | - | N/A | critical | 344360 |
| CVE-2025-61666 | Traccar(Windows) 6.1- 6.8.1 - Local File Inclusion | - | N/A | high | 347019 |
| CVE-2025-8266 | ChanCMS <= 3.1. - Remote Code Execution | - | N/A | critical | 380026 |
| CVE-2025-9985 | Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File | - | N/A | medium | 390716 |
| CVE-2026-35616 | FortiClient EMS - Authentication Bypass | forticlient_ems | N/A | high | 392301 |