Selected CVE-related research notes documenting testing results, engineering observations, attack-pattern analysis, and WAF rule interactions.

These notes are not a CVE coverage matrix, completeness claim, certification list, or list of all vulnerabilities mitigated by Atomicorp products.

A published CVE research note documents a positive research finding for that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Last updated: 2026-09-12

CVEVulnerability NameProductCVSSSeverityRules Observed
CVE-2026-72710SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue InjectionSPIP9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-89249AVideo YPTWallet Stored XSS via CryptoWallet ConfigurationAVideo9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-89253AVideo Stored XSS via donationLink in watch page buttonAVideo9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-89254AVideo CustomizeUser Stored XSS via field_name ParameterAVideo9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 341256 , 342259 , 346755
CVE-2026-89255AVideo LoginControl Stored XSS via PGP Public KeyAVideo9.3 (v4.0)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-89256AVideo Bookmark Plugin Stored XSS via Chapter NamesAVideo9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-89243WWBN AVideo Stored XSS via UserGroups setGroup_nameAVideo9.2 (v4.0)Critical333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72708SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee ParameterSPIP8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-89250WWBN AVideo Unauthenticated File Read via getRecordedFile.phpAVideo8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-54166Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypassshelf.nu7.1 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-89242WWBN AVideo Unauthenticated SSRF via login.json.phpAVideo6.9 (v4.0)Medium337109 , 337110 , 398022
CVE-2026-89240WWBN AVideo Reflected XSS via confirmLivePassword.phpAVideo5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-89241WWBN AVideo Reflected XSS via confirmLivePassword.phpAVideo5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-89244WWBN AVideo Reflected XSS via Gallery Category getBackURLAVideo5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-89247WWBN AVideo XML Injection via plugin/AD_Server/VMAP.phpAVideo5.3 (v4.0)Medium330791 , 340152 , 341256 , 344360 , 344370 , 344372 , 344373 , 347009 , 350147 , 380018
CVE-2026-89148AVideo Open Redirect via playlistSort.php Referer HeaderAVideo5.1 (v4.0)Medium340162 , 340163 , 340165 , 344365
CVE-2026-88062OmniRoute ACP Custom-Agent Remote Code Execution (RCE)OmniRoute9.5 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-88866WWBN AVideo LoginControl Stored XSS via User-Agent HeaderAVideo9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-88867WWBN AVideo Stored XSS via Category Name and Icon ClassAVideo9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-88868AVideo LiveLinks Stored XSS via title and description fieldsAVideo9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-88869AVideo AD_Server Stored XSS via log.php label parameterAVideo9.3 (v4.0)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-84889A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitLangflow OSS8.8 (v3.1)High340007 , 344360 , 390709 , 390719
CVE-2026-64837ICEcoder through 8.1 OS Command Injection via lib/properties.phpICEcoder8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009
CVE-2026-64838ICEcoder through 8.1 Path Traversal via oldFileName ParameterICEcoder8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-79987Low-privilege RCE through element-search eager loadingcms8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-81213Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetchesLangflow OSS8.6 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-88937knowns through 0.33.0 Path Traversal via Template Engineknowns8.6 (v4.0)High344360 , 390709
CVE-2026-88890OpenPanel SQL Injection via unvalidated profile filter column identifieropenpanel8.4 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-57231Path Traversal in avatar attachments in Docmost v0.21.0 Vulnerability-7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-81265Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetchesLangflow OSS7.5 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-88938knowns through 0.33.0 Path Traversal via code.find MCP toolknowns7.1 (v4.0)High340007 , 344360 , 390709
CVE-2026-88940knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpointknowns6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-54054Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirectstransmute6.5 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-87870Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API ParameteNinja Forms - Scheduled Exports6.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-88055AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGeneratoranything-llm5.5 (v3.1)Medium333140 , 333141 , 340095 , 342259
CVE-2026-36392FairSketch Rise CRM Version 3.9.6 Cross-Site Scripting Vulnerability-5.4 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-88892OpenPanel SSRF via Unguarded Importer File URL Fetchopenpanel5.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-79723Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetchesLangflow OSS5.0 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-87926Rizwan17 inventory-management-system Login Page index.php cross site scriptinginventory-management-system2.1 (v4.0)Low333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-38626Garlic-Hub v1.0.1 SQL Injection Vulnerability-N/AN/A340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-71805Path Traversal-9.8 (v3.1)Critical351000
CVE-2026-54694NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeoverskills-service9.6 (v3.1)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-87930MaxSite CMS through 109.6 PHP Object Injection via ci_sessionMaxSite CMS9.2 (v4.0)Critical340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722
CVE-2026-86775knowns before 0.30.0 Path Traversal via Document APIknowns8.8 (v4.0)High340007 , 344360 , 390709
CVE-2026-87927MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcherMaxSite CMS8.8 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-87807siyuan before v3.8.2 SQL Injection via fullTextSearchBlocksiyuan8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-26212Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCERara One Click Demo Import8.6 (v4.0)High351000
CVE-2026-79322mageplaza blog SQL Injection Vulnerabilitymageplaza blog8.6 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-87811SiYuan before v3.8.2 Stored XSS via notebook template pathssiyuan8.4 (v4.0)High333140 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-87814SiYuan before v3.8.2 Stored XSS via Asset Previewsiyuan8.4 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86771Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_numsnipe-it8.3 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-18147Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted urlRed Hat Enterprise Linux 108.1 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-87812SiYuan before v3.8.2 Stored XSS via Bazaar iconURLsiyuan7.4 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-87821Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetchlaradashboard7.1 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchopen-webui7.1 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-75307zhitan-ems 1.0.0 Cross-Site Scripting Vulnerability-6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86756Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayStatesnipe-it5.3 (v4.0)Medium344365
CVE-2026-79569Movie_Recommend v1.0.0 SQL Injection VulnerabilityMovie Recommend v1.0.09.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79570mfish-nocode-pro v1.0.0 SQL Injection Vulnerabilitymfish-nocode-pro v1.0.09.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) Cross-Site Scripting VulnerabilityUC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314)9.3 (v3.1)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86738Snipe-IT before 8.7.0 CSS Injection via Custom CSSsnipe-it9.3 (v4.0)Critical333140 , 340095 , 342259
CVE-2026-53581ntp: write path traversalcore9.0 (v3.1)Critical340007 , 344360 , 390709
CVE-2026-78834Code Injection-8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-indexcms8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-61517Netis NX10 OS Command Injection via Ping Diagnostic HandlerNX108.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86733Snipe-IT before 8.7.0 Remote Code Execution via Backup Restoresnipe-it8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-58113Teamcenter V2412 Cross-site Scripting VulnerabilityTeamcenter V24128.5 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78837A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 Vulnerability-7.5 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86806opengeos GeoLibre _is_within_roots server-side request forgeryGeoLibre6.9 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 350591 , 390722 , 398021 , 398022
CVE-2026-78838AppNitro MachForm v30 Cross-Site Scripting VulnerabilityAppNitro MachForm v306.5 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86590Eclipse Che Server-Side Request Forgery VulnerabilityEclipse Che6.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-78738Silverpeas Core 6.4.6 Cross-Site Scripting Vulnerability-6.1 (v3.1)Medium340099 , 341099
CVE-2026-78742Silverpeas Core <=6.4.6 Cross-Site Scripting Vulnerability-6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86735snipe-it before 8.7.0 SSRF via IPv6 transition address bypasssnipe-it5.9 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-54611InstantCMS has Remote Code Execution in package installericms25.5 (v3.1)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-86666aircheng-org iWebShop-5 pic.php uploadFile unrestricted uploadiWebShop-55.5 (v4.0)Medium351000
CVE-2026-73319XenForo < 2.3.13 XSS via Dynamic Redirect Handlerxenforo5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48707InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanningicms23.1 (v3.1)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-86517itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86518code-projects Student Crud Operation edit.php sql injectionStudent Crud Operation2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86668aircheng-org iWebShop-5 pic.php uploadFile cross site scriptingiWebShop-52.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86675itsourcecode Sales and Inventory System us_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86644star7th showdoc API Page Save Endpoint editormd.js cross site scriptingshowdoc2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86667aircheng-org iWebShop-5 member.php member_list sql injectioniWebShop-52.0 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86542knowns before 0.30.0 Path Traversal via Import Nameknowns8.8 (v4.0)High340007 , 344360 , 390709
CVE-2026-86538knowns before 0.30.0 Path Traversal via templateFile parameterknowns8.7 (v4.0)High344360 , 390709
CVE-2026-86299Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injectionRE70008.6 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86437Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Uploadlaradashboard8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-86438Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Actionlaradashboard8.6 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86539knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpointknowns6.9 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-86237openagents-org openagents http.py test_default_model server-side request forgeryopenagents5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-86239liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted uploadFeehiCMS5.5 (v4.0)Medium351000
CVE-2026-86268itsourcecode School Management System User_Login.php sql injectionSchool Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86273projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-side request forgerysiga5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-86290SourceCodester Online Voting System ajax.php save_category sql injectionOnline Voting System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-86298SourceCodester Class and Exam Timetabling System delete_subject.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86305light0011 cms Upload.class.php upload unrestricted uploadcms5.5 (v4.0)Medium351000
CVE-2026-86233itsourcecode Sales and Inventory System us_del.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86234itsourcecode Sales and Inventory System cust_transac.php add sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86235itsourcecode Sales and Inventory System pos_transac.php add sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86236itsourcecode Sales and Inventory System pro_transac.php add sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86244FastAdmin User Controller User.php login cross site scriptingFastAdmin2.1 (v4.0)Low333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86245itsourcecode Sales and Inventory System sup_transac.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86265itsourcecode Sales and Inventory System us_transac.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86267itsourcecode Information System Society Membership System check_student.php sql injectionInformation System Society Membership System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86269itsourcecode Sales and Inventory System emp_edit1.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86270itsourcecode Sales and Inventory System settings_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86278SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.php cross site scriptingSyllabus-Aligned Learning Management & Examination System2.1 (v4.0)Low333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-86291itsourcecode Sales and Inventory System us_edit1.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86294SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scriptingSimple Traffic Offense System2.1 (v4.0)Low333140 , 333141 , 340095 , 342259
CVE-2026-86309itsourcecode Sales and Inventory System pro_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86310itsourcecode Sales and Inventory System cust_edit1.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86240liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgeryFeehiCMS2.0 (v4.0)Low337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-86301code-projects Hospital Information System Patient Management editPatient.php cross site scriptingHospital Information System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86259OpenMAIC before 1.0.1 SSRF via Environment-Gated URL ValidationOpenMAIC9.0 (v4.0)Critical337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022
CVE-2026-86159SourceCodester Online Voting System ajax.php save_user sql injectionOnline Voting System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-86160SourceCodester Online Voting System ajax.php delete_voting sql injectionOnline Voting System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-86161SourceCodester Online Voting System ajax.php delete_category sql injectionOnline Voting System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-86162SourceCodester Online Voting System ajax.php login sql injectionOnline Voting System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-86168code-projects Content Management System login.php sql injectionContent Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86180code-projects Task Management System In PHP Login index.php sql injectionTask Management System In PHP5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86208SourceCodester Class and Exam Timetabling System delete_teacher.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86209SourceCodester Class and Exam Timetabling System delete_user.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86210SourceCodester Class and Exam Timetabling System delete_user_account.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86211rabindralamsal inventory-management-system Login index.php sql injectioninventory-management-system5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86213Mstfakts College-Management-System Search university.php mysqli_query sql injectionCollege-Management-System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86220SourceCodester Class and Exam Timetabling System modal_add_course.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86221SourceCodester Class and Exam Timetabling System modal_add_course1.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86222SourceCodester Class and Exam Timetabling System modal_add_course2.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86223SourceCodester Class and Exam Timetabling System modal_add_coursea.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86224SourceCodester Class and Exam Timetabling System modal_add_product.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86225SourceCodester Class and Exam Timetabling System modal_add_room.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86205h3 before 2.0.1-rc.18 Open Redirect via redirectBack()h35.3 (v4.0)Medium344365
CVE-2026-86256wger before 2.6 Open Redirect via trainer-login next parameterwger5.1 (v4.0)Medium344365
CVE-2026-86163itsourcecode Sales and Inventory System pro_del.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86164itsourcecode Sales and Inventory System trans_view.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86170DefaultFuction CRM edit.php sql injectionCRM2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86171DefaultFuction CRM delete.php sql injectionCRM2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86172DefaultFuction CRM delete.php sql injectionCRM2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86216code-projects Hotel and Tourism Reservation in PHP details.php cross site scriptingHotel and Tourism Reservation in PHP2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86232itsourcecode Sales and Inventory System sup_del.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86181code-projects Task Management System User Profile Update UpdateUserProfile.php cross site scriptingTask Management System2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86123SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpointssqlchat9.4 (v4.0)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-86189WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.phpAVideo9.3 (v4.0)Critical340007 , 344360 , 390709
CVE-2026-86119Webstudio through 0.296.0 SSRF via /cgi proxy routeswebstudio9.2 (v4.0)Critical337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-52775YesWiki Authenticated SQL Injection in ReactionManageryeswiki8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-67281Unauthenticated file read in Mikrotik RouterOSRouterOS8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-52769YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyIdyeswiki8.3 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390719 , 390722 , 398001 , 398021 , 398022
CVE-2026-52771YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (ApiController::deletePage)yeswiki8.3 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86207N-able N-central - Authentication BypassN-central7.7 (v4.0)High344365
CVE-2026-52770Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswikiyeswiki7.5 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86188AVideo YPTSocket Plugin Unauthenticated Cross-Site ScriptingAVideo6.9 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86206N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header SpoofingN-central6.9 (v4.0)Medium344365
CVE-2026-52773YesWiki Archived Revision - Cross-Site Scriptingyeswiki6.1 (v3.1)Medium340147 , 340148
CVE-2026-52774YesWiki Bazar Widget - Reflected XSS via 'id' Parameteryeswiki6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 350148
CVE-2026-86197Grav before 2.0.20 Cross-Site Scripting via Assets Sandboxgrav5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-67066oasys sysoa version 1.0 Arbitrary Code Execution Vulnerabilityoasys sysoa version 1.09.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-50894easyadmin v2.0.2.2 Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical351000
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgiSNMP Web Pro9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-85614OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkeropenpanel9.2 (v4.0)Critical337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-79423seacms v13.6 Arbitrary Code Execution Vulnerabilityseacms v13.68.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-53758Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitizedemlog8.7 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-85604Grav before 2.0.19 Remote Code Execution via sort filtergrav8.7 (v4.0)High340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-85608Douyin_TikTok_Download_API 4.1.2 SSRF via url parameterDouyin TikTok Download API8.7 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulasopenpanel8.7 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-85612OpenPanel before 2.3.0 SSRF via favicon and og endpointsopenpanel8.7 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-85666ogx 1.3.1 Server-Side Request Forgery via MCP tool server_urlogx8.7 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-85673LLaMA-Factory SSRF Guard Bypass via Redirect and DNS RebindingLlamaFactory8.7 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-85685AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skillagentscope8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-85691MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/urlmegaparse8.7 (v4.0)High337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-50553Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)note-mark8.6 (v4.0)High340007 , 344360 , 390709
CVE-2026-85613OpenPanel Unauthenticated XSS via SVG Favicon Proxyopenpanel8.4 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-19303Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing clangflow8.1 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-63464Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_privatenebula-mesh7.7 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-61686SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context propSolidInvoice7.5 (v3.1)High340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2022-35499In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint Cross-Site Scripting Vulnerability-7.1 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-53757Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCEemlog6.9 (v4.0)Medium344360
CVE-2026-73848Emlog: Stored XSS via Tag Name in Article Editoremlog6.9 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-74235GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download HandlerGFI Exinda AI6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-85609Openpanel before 2.3.0 SSRF via Site Checker Endpointopenpanel6.9 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-85662Marqo 2.26.0 Server-Side Request Forgery via Media URLsmarqo6.9 (v4.0)Medium337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-14470Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componelangflow6.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-9138Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing clangflow6.5 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-75170the HubCore platform (version 14.1.1) Cross-Site Scripting Vulnerabilitythe HubCore platform (version 14.1.1)6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-8447Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrustelangflow6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85379light0011 cms Query Builder ChapterController.class.php searchChapter sql injectioncms5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85380light0011 cms UEditor controller.php catchimage server-side request forgerycms5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2026-85397code-projects Hospital Information System addReq.php findBySearch sql injectionHospital Information System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85398code-projects Hospital Information System viewReq.php viewReq sql injectionHospital Information System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85399code-projects Hospital Information System PrespController.php getSinglePresp sql injectionHospital Information System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85402code-projects Doctor Appointment System booking.php sql injectionDoctor Appointment System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85403code-projects Doctor Appointment System contactus.php sql injectionDoctor Appointment System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85512SourceCodester Class and Exam Timetabling System session.php authorizationClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85516code-projects Vehicle Management System busprofile.php sql injectionVehicle Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-17621Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componelangflow5.4 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-85577AVideo userLogin.php Reflected XSS via error parameterAVideo5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-85650Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channeltrigger.dev5.3 (v4.0)Medium334168 , 337109 , 337110 , 344360 , 390719 , 398001 , 398008 , 398021 , 398022
CVE-2026-85676Dub Open Redirect via Unrestricted redir_url Parameterdub5.3 (v4.0)Medium344365
CVE-2026-85593phpMyFAQ before 4.1.8 Stored XSS via html_entity_decodephpMyFAQ5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85600Grav Admin before 2.0.21 Stored XSS via usernamegrav-plugin-admin25.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2026-85601Grav Admin before 2.0.20 Cross-Site Scripting via marked.jsgrav5.1 (v4.0)Medium333140
CVE-2026-85382light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scriptingcms2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-85383itsourcecode Sales and Inventory System inv_del.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85643code-projects Online Shopping System adduser.php mysqli_query sql injectionOnline Shopping System2.0 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78849Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 Arbitrary Code Execution VulnerabilityNetgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1N/AN/A333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-82526R2R 3.6.6 SQL Injection via Vector Index Creation EndpointR2R9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formattercore-geonetwork9.1 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-85199Eclipse aeriOS Path Traversal VulnerabilityEclipse aeriOS8.8 (v4.0)High340007 , 344360 , 390709
CVE-2026-82527R2R 3.6.6 SQL Injection via Retrieval Search Filter KeyR2R8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85155WWBN AVideo SQL Injection via get.json.php APIName channelsAVideo8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85223D-Link DNS-340L CGI dropbox.cgi os command injectionDNS-340L8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-85222D-Link DNS-340L Add-On Center addon_center.cgi os command injectionDNS-340L8.5 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-85224D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injectionDNS-320 ShareCenter8.5 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-85160AVideo through c91b5975d CSRF and Path Traversal via stopLive.phpAVideo7.2 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-53728Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakagemedplum7.1 (v3.1)High340162 , 340163 , 344365
CVE-2026-85163AVideo Server-Side Request Forgery via epg_link parameterAVideo7.1 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-85164WWBN AVideo Server-Side Request Forgery via set_api_userImagesAVideo7.1 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-75602OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolOpenList6.5 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-85137SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injectionSeaCMS5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-85138SeaCMS WeChat index.php addslashes sql injectionSeaCMS5.5 (v4.0)Medium340156
CVE-2026-85187itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85208itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted uploadOnline Medicine Delivery System5.5 (v4.0)Medium351000
CVE-2026-85225code-projects Doctor Appointment System patient_login.php sql injectionDoctor Appointment System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85158AVideo Reflected XSS via videoEmbeded.php link parameterAVideo5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85159AVideo Reflected XSS via cancelUri in userLogin.phpAVideo5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85205itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injectionOnline Medicine Delivery System5.3 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-56126pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.phppfSense Plus5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-56127pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.phppfSense Plus5.1 (v4.0)Medium333140 , 333141 , 342259
CVE-2026-56128pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.phppfSense Plus5.1 (v4.0)Medium333140 , 333141 , 342259
CVE-2026-85021langgenius dify Splash Layout splash.tsx router.replace cross site scriptingdify2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85186itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted uploadOnline Medicine Delivery System2.1 (v4.0)Low351000
CVE-2026-85022langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scriptingdify2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85040ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injectionCRMEB2.0 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-85207itsourcecode Online Medicine Delivery System index.php cross site scriptingOnline Medicine Delivery System2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-9314Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File UploadThe Developer Tools WordPress plugin through 1.1.39.8 (v3.1)Critical351000
CVE-2026-53649Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEjoro9.6 (v3.1)Critical340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-79756Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platformnuclio8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-82524UnoPim File Upload RCE via TinyMCE Image Upload Endpointunopim8.6 (v4.0)High351000
CVE-2026-84803SiYuan before v3.8.2 Stored XSS via incomplete asset blocklistsiyuan8.6 (v4.0)High333140 , 333141
CVE-2026-52831Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCEnuclio8.0 (v3.1)High340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 390719
CVE-2026-79755Nuclio: Unauthenticated OS command injection via function namespace in docker ps –filter label (local Docker platform)nuclio8.0 (v3.1)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-55421Open edX Platform: SSRF in Studio Video Download Endpointopenedx-platform6.8 (v3.1)Medium337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-10821Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCEYoast SEO Premium6.6 (v3.1)Medium340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 360029 , 390904
CVE-2026-84441Piwigo Image Derivative i.php path traversalPiwigo5.5 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-84175Eclipse Ditto Uncontrolled Recursion VulnerabilityEclipse Ditto5.3 (v4.0)Medium337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-52832Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard containernuclio4.9 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-53683Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.htmlRed Hat Enterprise Linux 104.3 (v3.1)Medium340163 , 344365
CVE-2023-3360Weaver Show Posts < 1.8.1 - Admin+ PHP Object InjectionWeaver Show Posts3.3 (v3.1)Low340014 , 340023 , 344362 , 344363 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2026-84437OpenCart Autocomplete Workflow address.php cross site scriptingOpenCart2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 340247 , 340248 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-84438OpenCart Autocomplete Workflow edit.php cross site scriptingOpenCart2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-84372Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis9.8 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390722 , 393655
CVE-2026-84189LibreNMS before 26.7.0 Stored XSS via Oxidized APIlibrenms9.2 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-71981Cypht < 2.12.2 PHP Object Injection RCE via back_query Parametercypht8.7 (v4.0)High340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-84208AVideo User_Location Plugin Unauthenticated SQL InjectionAVideo8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-84194LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostnamelibrenms8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-84196Kyverno before 1.18.0 Server-Side Request Forgery via apiCallkyverno8.3 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19914Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' ParameterWelcart e-Commerce7.2 (v3.1)High333140 , 340095 , 340147 , 341256 , 342259 , 346755
CVE-2026-84192LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Datalibrenms7.1 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2026-84199Kyverno before 1.16.2 SSRF via APICall Featurekyverno6.9 (v4.0)Medium337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-8712Wyoming < 1.10.2 SSRF via uri Query Parameterwyoming6.9 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-84193LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMPlibrenms5.8 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-84111Chanjet CRM jxf_dump_table.php sql injectionCRM5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-84191LibreNMS before 26.5.0 Stored XSS via SNMP VRF fieldslibrenms5.3 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-84207Heym before 0.0.98 SSRF via WebSocket endpointsheym5.3 (v4.0)Medium337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-84477AVideo Stored XSS via Live Schedule Title DescriptionAVideo5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-84188librenms before 26.7.0 Stored XSS via graph_descr settingslibrenms4.8 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-83744invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgeryInvoice Ninja2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-84109Xinhu Rainrock RockOA webmainAction.php getOrder sql injectionRainrock RockOA2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-84153Xinhu Rainrock RockOA index.php toaddval sql injectionRainrock RockOA2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79408MetaGPT 0.8.1 Command Injection VulnerabilityMetaGPT 0.8.19.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-59111Command Injection vulnerability in eObčanka-IdentifikaceeObčanka-Identifikace9.3 (v3.1)Critical340014 , 347009 , 393655
CVE-2026-51152Server-Side Request Forgery-9.1 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-77956EEx template evaluation of prompt content in AshAi enables remote code executionash ai8.9 (v4.0)High340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-82866@pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetchcommon8.9 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82217Eclipse Theia Path Traversal VulnerabilityEclipse Theia8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-81889elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallbackelFinder8.6 (v3.1)High337109 , 337110 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-82692D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injectionDNS-340L8.6 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-61640Wallos: SSRF via OIDC Token/UserInfo URL ConfigurationWallos8.5 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-82690D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injectionDNS-327L8.5 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-82691D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injectionDNS-320L8.5 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-77850Stored XSS in AshAdmin relationship typeahead via unescaped label_field contentash admin8.4 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-82673Path traversal in AshAdmin file uploads via unsanitized client filenameash admin8.3 (v4.0)High340007 , 344360 , 390709
CVE-2026-61638Wallos: SSRF via Test Email Notification - unvalidated SMTP host/portWallos8.2 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-77348Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.phWallos8.2 (v3.1)High337109 , 337110 , 340790 , 340791 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-53553Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromisegoploy7.7 (v3.1)High340007 , 344360 , 390709
CVE-2026-79749MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validationmcphub7.6 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2026-79407the SPO extension of MetaGPT 0.8.1 Path Traversal Vulnerabilitythe SPO extension of MetaGPT 0.8.17.5 (v3.1)High340007 , 344360
CVE-2026-75132WAPT Server SQL Injection via /api/v3/hosts EndpointWAPT7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79747MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxymcphub7.1 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2026-82877ILIAS before 9.22 Arbitrary File Read via SOAP addFileILIAS7.1 (v4.0)High340007 , 344360 , 390709
CVE-2026-75592Kirby: Access to image files outside of the site root via path traversal in the media handlingkirby6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-79743MCPHub: Path Traversal via Malicious MCPB Manifest Namemcphub6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2025-63607TechStore 1.0 Cross-Site Scripting Vulnerability-6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82598SeaCMS Template search.php parseIf code injectionSeaCMS5.5 (v4.0)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-82600SeaCMS zyapi.php sql injectionSeaCMS5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82610itsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82611itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82612itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82613itsourcecode Online Medicine Delivery System Product Search index.php loadResultList sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82614itsourcecode Online Medicine Delivery System Product Category Filter index.php loadResultList sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82615itsourcecode Online Medicine Delivery System Password Recovery passwordrecover.php find_phone sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82630PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgeryPowerJob5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82701code-projects Online Shopping System Search Functionality action.php sql injectionOnline Shopping System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82801NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgeryearthdata-search5.5 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-82802NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgeryearthdata-search5.5 (v4.0)Medium337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82396Sulu: Stored XSS via media download inline-disposition overridesulu5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-77352Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)Wallos4.3 (v3.1)Medium337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-77351Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification SettingsWallos3.5 (v3.1)Low337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82599SeaCMS Avatar Upload member.php unlink path traversalSeaCMS2.1 (v4.0)Low340007 , 344360 , 347009 , 390709
CVE-2026-82601SeaCMS err.php cross site scriptingSeaCMS2.1 (v4.0)Low333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-82603SeaCMS Comment Cache member.php del_pl path traversalSeaCMS2.1 (v4.0)Low340007 , 344360 , 347009 , 390709
CVE-2026-82609itsourcecode Sales and Inventory System inv_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82625code-projects Simple Inventory System User Registration register.php cross site scriptingSimple Inventory System2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-82664yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scriptingGEOFlow2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82679diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted uploaddiem2.1 (v4.0)Low351000
CVE-2026-82696itsourcecode Sales and Inventory System inv_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82700code-projects Online Shopping System Newsletter Subscription offersmail.php cross site scriptingOnline Shopping System2.1 (v4.0)Low333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-82905sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgerychats2.1 (v4.0)Low337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82622code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scriptingEmployee Leave Managing System2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-82629jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted uploadjeewx-boot2.0 (v4.0)Low351000
CVE-2026-82665yaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversalGEOFlow2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82666yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injectionGEOFlow2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82667yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forgerGEOFlow2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82678diem-project diem Administrative Console actions.class.php executeCommand os command injectiondiem2.0 (v4.0)Low340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009
CVE-2026-82702Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injectionBR-6214K2.0 (v4.0)Low340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-82703Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injectionBR-6214K2.0 (v4.0)Low340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-82638jina-ai reader Server-Side Request Forgery via disabled private-address guardreader8.7 (v4.0)High344360 , 347009 , 390719 , 390722 , 398001 , 398021
CVE-2026-82655Admidio before 5.0.12 SQL Injection via relation_type_listadmidio8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82650SiYuan before v3.8.1 Path Traversal via /api/template/rendersiyuan5.9 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-82646WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.phpAVideo5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82484itsourcecode Sales and Inventory System emp_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82485itsourcecode Sales and Inventory System pro_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82540itsourcecode Sales and Inventory System cust_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82541itsourcecode Sales and Inventory System sup_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82545itsourcecode Sales and Inventory System sup_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82656Admidio before 5.0.12 Path Traversal via Photo ZIP Downloadadmidio2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2026-82483coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scriptingCoppermine Photo Gallery2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-82488Beetel 450TC3 User Management cross site scripting450TC32.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-16061Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}Rest Routes8.6 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82451Formwork through 2.3.14 Stored XSS via Referer HeaderFormwork5.3 (v4.0)Medium333140 , 333141 , 340003 , 340087 , 340095 , 340099 , 340147 , 340158 , 341099 , 341266 , 342259
CVE-2026-82421itsourcecode Sales and Inventory System emp_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82422itsourcecode Sales and Inventory System emp_del.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82424PHPGurukul Student Information System student_edit1.php sql injectionStudent Information System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-54745Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABpipelines10.0 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2026-55565Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression)yamcs9.9 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-55634Pimcore: Remote Code Execution via DataObject Class-Definition Field Namepimcore9.9 (v3.1)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-55559Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)yamcs9.8 (v3.1)Critical344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75337Yu AI Code Mother v4.3 is vulnerable to path traversal VulnerabilityYu AI Code Mother v4.3 is vulnerable to path traversal9.8 (v3.1)Critical340007 , 344360 , 347009 , 390709
CVE-2026-82329JFrog Artifactory Access Blank Join Key Authentication Bypassartifactory9.8 (v3.1)Critical300022
CVE-2026-82244Budibase before 3.41.3 Remote Code Execution via Plugin eval()server9.4 (v4.0)Critical340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390719 , 393655
CVE-2026-55511Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSqlyamcs9.1 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-55509WsgiDAV: Blind SQL injection in the MySQL providerwsgidav8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82286gpt-crawler Arbitrary File Write via outputFileName Parametergpt-crawler8.8 (v4.0)High340007 , 344360 , 390709
CVE-2026-55245Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURLbifrost8.7 (v4.0)High337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-76060OS Command Injection in PayRange APIZoneminder8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-82270Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/*gateway8.7 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398001 , 398021 , 398022
CVE-2026-82278BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_oncebisheng8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75121PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postPLANET GS-4210-16P2S V38.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75122PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgiPLANET GS-4210-16P2S V38.6 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V38.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-82243Budibase Server before 3.41.3 SSRF with Credential Leakageserver8.3 (v4.0)High337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82262Logto Server-Side Request Forgery via webhook test endpointlogto8.2 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-54083Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletionwazuh8.1 (v3.1)High340007 , 344360 , 390709
CVE-2026-55552Yamcs: Unauthenticated Directory Traversalyamcs7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-77939Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpointflextype7.1 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-82241Budibase backend-core SSRF via incomplete default blacklistserver7.1 (v4.0)High337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-82246Budibase Server before 3.41.3 SSRF via Query Importserver7.1 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-82233SiYuan before v3.8.1 Path Traversal via asset.uploadsiyuan6.9 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-55549Yamcs: Reflected XSS in the URL of the Authorize Endpointyamcs6.5 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-82081wallabag Server-Side Request Forgery Vulnerabilitywallabag6.4 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-38725xipblog module 2.0.1 and Earlier for PrestaShop Cross-Site Scripting Vulnerability-5.4 (v3.1)Medium346755
CVE-2026-82274Twenty Open Redirect via OAuth Propagator Callbacktwenty5.3 (v4.0)Medium340162 , 340163 , 340165 , 344365
CVE-2026-82112houtini-ai houtini-lm code_task_files index.ts path traversalhoutini-lm5.1 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-55566Yamcs: DOM XSS in Extension Routingyamcs4.3 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-55834Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=nonepocket-id4.3 (v3.1)Medium340162 , 340163 , 340165 , 344365
CVE-2026-81845arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversalmcp-sequential-thinking2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2026-81835RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injectionRoo-Code2.0 (v4.0)Low340014 , 344360 , 347009 , 393655
CVE-2026-81847MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversalMaaMCP2.0 (v4.0)Low340007 , 344360 , 390709
CVE-2026-81735UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command ExecutiUI-TARS-desktop10.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-81672Multiple Vulnerabilities in TOOOLS' iSquadiSquad9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81673Multiple Vulnerabilities in TOOOLS' iSquadiSquad9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81674Multiple Vulnerabilities in TOOOLS' iSquadiSquad9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81675Multiple Vulnerabilities in TOOOLS' iSquadiSquad9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)core9.1 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-26899OS Command Injection-8.8 (v3.1)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-81676Multiple Vulnerabilities in TOOOLS' iSquadiSquad8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81677Multiple Vulnerabilities in TOOOLS' iSquadiSquad8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81730Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filenamedolibarr erp/crm8.8 (v4.0)High340007 , 344360 , 390709
CVE-2026-81093Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeletonactors-mcp-server8.7 (v4.0)High340162 , 340165 , 347009 , 390722
CVE-2026-81728Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keysdolibarr erp/crm8.6 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-53580Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download featureTrilium8.1 (v3.1)High340007 , 347009
CVE-2026-40526Volmarg Personal Management System Path Traversal via get-file Endpointpersonal-management-system7.1 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-81678AVideo SSRF Guard Bypass via IPv6 Transition AddressesAVideo6.9 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-79653Eclipse SW360 Path Traversal VulnerabilityEclipse SW3606.0 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-81421ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgerysentry-selfhosted-mcp5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-81486bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversalmcp-file-context-server5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-81491boxpositron with-context-mcp index.ts project_folder path traversalwith-context-mcp5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-81931Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scriptingProspero Flow CRM4.8 (v4.0)Medium351000
CVE-2026-60004Gitea <= 1.27.0 - Pre-Auth Remote Code Executiongitea9.8 (v3.1)Critical330907 , 330908 , 330909
CVE-2026-68000MCMS <=6.2.0 is vulnerable to SQL injection VulnerabilityMCMS <=6.2.0 is vulnerable to SQL injection9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75327In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java Arbitrary File Upload VulnerabilityIn DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java9.8 (v3.1)Critical351000
CVE-2026-75330super-diamond-server <= 1.3.3 is vulnerable to SQL injection Vulnerabilitysuper-diamond-server <= 1.3.3 is vulnerable to SQL injection9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75336Funiture 1.0.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340145 , 380122
CVE-2026-75411JeecgBoot v3.9.2 Code Injection Vulnerability-9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75414In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability-9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75332Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability-9.1 (v3.1)Critical337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2020-15874Command Injection-8.8 (v3.1)High340014 , 340023 , 340029 , 340193 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2020-15876SQL Injection-8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2020-15878SQL Injection-8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-56798Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier Cross-Site Request Forgery VulnerabilityLime Technology, Inc.'s Unraid OS version 6.12.14 and earlier8.8 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 393655
CVE-2026-47665Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTMLpenpot8.7 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-55182LibreNMS: Remote Code Execution by Signal Alert Transportation Modulelibrenms8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-80214LibreNMS Virtualisation Discovery Module RCElibrenms8.6 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-81029OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URIOpenMetadata8.5 (v4.0)High344365
CVE-2026-81036Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uristalwart8.5 (v4.0)High344365
CVE-2026-15973LimeSurvey 7.0.5 - Stored XSS in Survey Menu EntriesLimeSurvey8.4 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-36851UnPoller 2.33.0 password field Path Traversal VulnerabilityUnPoller 2.33.0 password field7.5 (v3.1)High340007 , 344360 , 390709
CVE-2026-75328In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal VulnerabilityIn DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-75333yx-image-recognition v1.0 Path Traversal Vulnerability-7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-16809LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message renderingLimeSurvey7.2 (v4.0)High333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-80350OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URLOneUptime7.1 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-81030Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpointmage-ai7.1 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-80426FiftyOne before 1.21.0 Stored Cross-Site Scripting via Unescaped Field Descriptionfiftyone7.0 (v4.0)High333140 , 333141
CVE-2026-39275Cockpit CMS v.2.13.5 and before Arbitrary Code Execution VulnerabilityCockpit CMS v.2.13.5 and before6.1 (v3.1)Medium340099 , 341099
CVE-2026-81203SourceCodester Simple Online Food Ordering System ajax.php login2 sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-45694LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameterslibrenms5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-80200Kimai before 2.53.0 Open Redirect via RelayStatekimai5.3 (v4.0)Medium344365
CVE-2026-65930LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fieldsLimeSurvey4.8 (v4.0)Medium333140 , 333141 , 340095 , 342259
CVE-2026-75331tamguo 1.5.3 Cross-Site Scripting Vulnerability-4.6 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19912Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution VulnerabilityKaltura HTML5 Video Player, html5 library9.8 (v3.1)Critical340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-45018Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code executionchainlit9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-80104DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload FilenameDB-GPT9.3 (v4.0)Critical340007 , 344360 , 390709
CVE-2026-80138ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameterclipbucket-v59.2 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-55585QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr()qwed-verification8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-79662Ech0 before 4.7.3 OAuth Redirect URI Validation BypassEch08.8 (v4.0)High340162 , 340163 , 340165 , 344365
CVE-2026-57863Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpointcrater8.7 (v4.0)High340007 , 344360 , 390709
CVE-2026-62865TypeBot: Arbitrary server file read via Send Email block attachment pathtypebot.io8.7 (v4.0)High340007 , 344360 , 390709
CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twiggrav8.7 (v4.0)High340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTOadminer8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655
CVE-2026-79659Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfoEch08.3 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19913Kaltura HTML5 Video Player, html5lib library Improper Input Validation VulnerabilityKaltura HTML5 Video Player, html5lib library7.5 (v3.1)High340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-34968Adminer before 5.4.3 Arbitrary File Deletion via SQLite Dropadminer7.2 (v4.0)High340007 , 344360 , 390709
CVE-2026-45019Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network accesschainlit7.2 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-55537PraisonAI: Webhook SSRF via DNS fail-open in JobSubmitRequest.validate_webhook_url() — bypass of CVE-2026-40114PraisonAI7.1 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-56702Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUploadadminer7.1 (v4.0)High351000
CVE-2026-72695Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFilegrav7.1 (v4.0)High344360
CVE-2026-79788Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via Unrestricted AI Provider Addressdradis-ce7.1 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-79786Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registrationcoroot7.0 (v4.0)High344365
CVE-2026-34964Adminer before 5.5.0 SSRF via PDO DSN Injectionadminer6.9 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-79773Winter CMS before 1.2.13 Local File Inclusion via JavaScriptwinter6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-79781rclone serve s3 Path Traversal via dot-dot object keysrclone6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-79717Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restrictionRed Hat Ansible Automation Platform 26.4 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-78886liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversalTREK6.3 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-38472forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 Cross-Site Scripting Vulnerabilityforum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d184464496.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-79804SililaWijesinghe Food Ordering System search.php sql injectionFood Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79845code-projects Simple Inventory System edit.php sql injectionSimple Inventory System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-38467the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerabilitythe tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d184464495.4 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-38473the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 Cross-Site Scripting Vulnerabilitythe subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d184464495.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34959Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefixadminer5.3 (v4.0)Medium340165 , 344365
CVE-2026-34967Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Writeadminer5.3 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-55419Reachy Mini: Unrestricted Upload of File with Dangerous Typereachy mini5.3 (v3.1)Medium351000
CVE-2026-78864liketrek TREK Journey Entry Update journey.controller.t journeyService.updateEntry sql injectionTREK5.3 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79671Ech0 before 4.4.3 SSRF via DNS Resolution BypassEch05.1 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-26211Ekushey Project Manager CRM 5.0 Stored XSS via System Name FieldEkushey Project Manager CRM4.8 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-79663Ech0 before 4.7.3 Stored XSS via RSS feed tag namesEch04.8 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-79670Ech0 before 4.4.3 Stored XSS via SVG UploadEch04.8 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-38468the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerabilitythe country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d184464494.3 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16434Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypassadminer2.3 (v4.0)Low340007 , 344360 , 347009 , 390709 , 390719
CVE-2026-66882Reflected XSS in AshAuthentication confirmation and magic link interaction formsash authentication2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78656itsourcecode Sales and Inventory System cust_del.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79793code-projects Online Shopping System sumit_form.php cross site scriptingOnline Shopping System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgiVigorSwitch G2540xs9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-76070Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password ParameterNC639.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76071Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost ParameterNC639.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76842Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clientsmercadopago8.8 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-76836AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group BypassAzuraCast8.7 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-78416Authenticated RCE via condition.config JSON cleanse bypasscms8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71906DrayTek VigorAP Multiple Models OS Command Injection via setLanVigorAP 918R8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71907DrayTek VigorAP Multiple Models OS Command Injection via setcamsetVigorAP 918R8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71908DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_testVigorAP 918R8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71913DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgiVigorAP 918R8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71915DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatusVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupActionVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysrebootVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-71923DrayTek VigorSwitch Multiple Models OS Command Injection via auth_setVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71924DrayTek VigorSwitch Multiple Models OS Command Injection via getVidVigorSwitch G2540xs8.6 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71925DrayTek VigorSwitch Multiple Models OS Command Injection via getDetailVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71926DrayTek VigorSwitch Multiple Models OS Command Injection via setDeviceVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71927DrayTek VigorSwitch Multiple Models OS Command Injection via rebDeviceVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71928DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDeviceVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71929DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProtoVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71930DrayTek VigorSwitch Multiple Models OS Command Injection via setTimeVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71931DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeVigorSwitch G2540xs8.6 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71943DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNetVigorSwitch G2540xs8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76844webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPathwebpack-dev-middleware8.3 (v4.0)High347009
CVE-2026-71932DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFileVigorSwitch G2540xs6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2022-30983Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 Cross-Site Scripting VulnerabilitySupport chatbot in Nopaperforms Niaa-Chatbot through 2022-05-176.1 (v3.1)Medium333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-78171itsourcecode Sales and Inventory System processlogin.php sql injectionSales and Inventory System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78197SourceCodester Simple Online Food Ordering System ajax.php save_user sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-78198SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-78199SourceCodester Simple Online Food Ordering System view_prod.php sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78201itsourcecode Payroll System admin_class.php login sql injectionPayroll System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78202itsourcecode Payroll System admin_class.php save_settings unrestricted uploadPayroll System5.5 (v4.0)Medium351000
CVE-2026-78244itsourcecode Real Estate Management System search.php sql injectionReal Estate Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78245itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted uploadOnline Pharmacy System5.5 (v4.0)Medium351000
CVE-2026-78246itsourcecode Online Clinic Management System Admin Login login.php sql injectionOnline Clinic Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78247SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-78248SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-76837Baserow before 2.3.0 Stored Cross-Site Scripting via Rich Text Mention Display NameBaserow5.3 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-71503Dolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Templatedolibarr5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78337Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVGProspero Flow CRM4.8 (v4.0)Medium351000
CVE-2026-78166provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injectionkafka-ui2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-78185itsourcecode Sales and Inventory System cust_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78200itsourcecode Library Management System editbooks.php sql injectionLibrary Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78435Faveo Helpdesk Logo SettingsController.php unlink path traversalHelpdesk2.0 (v4.0)Low340007 , 344360 , 347009
CVE-2026-78187Piwigo Public Authentication cross site scriptingPiwigo1.3 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78143code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injectionBarangay Resident Profiling Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78054SourceCodester Class and Exam Timetabling System BSIS1.php cross site scriptingClass and Exam Timetabling System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78055SourceCodester Class and Exam Timetabling System BSIT2.php cross site scriptingClass and Exam Timetabling System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78056sambitraj Student-Management-System Dashboard sql injectionStudent-Management-System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78057sambitraj Student-Management-System Management Mutation sql injectionStudent-Management-System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78059SourceCodester Stock Management System printOrder.php cross site scriptingStock Management System2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-78060SourceCodester Stock Management System getOrderReport.php cross site scriptingStock Management System2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-78112itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injectionHospital Management System Project in PHP2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78140Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engineUJCMS2.0 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-59809SiYuan before v3.8.0 Secret Exfiltration via http_request URLsiyuan6.9 (v4.0)Medium337109 , 347009 , 390722
CVE-2026-77806SPIP < 4.4.22 - Unauthenticated RCESPIP9.8 (v3.1)Critical380018 , 380026
CVE-2026-77086SiYuan before v3.7.4 Path Traversal via packageNamesiyuan9.4 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-49849xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Executionxshop9.1 (v3.1)Critical351000
CVE-2026-62674Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEomnigent9.0 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-62675Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Toolsomnigent8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-62677Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNomnigent8.8 (v3.1)High340007 , 344360 , 390709
CVE-2026-75933Jet Admin Stored XSSJet Admin8.5 (v4.0)High333140 , 333141 , 340095 , 342259
CVE-2026-22681OpenViking < 0.3.4 SSRF via /api/v1/resourcesOpenViking8.3 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-48105Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide patharc8.3 (v4.0)High340007 , 344360 , 390709
CVE-2026-63135YOURLS: Stored XSS in referrer statistics chart via crafted Referer headerYOURLS8.2 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-64679Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creationatlantis8.1 (v3.1)High340007 , 344360 , 390709
CVE-2026-77775Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address ValidationHeadroom7.7 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398021 , 398022
CVE-2026-30819Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameteriTop7.3 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-47735Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksarc7.1 (v4.0)High340007 , 344360 , 390709 , 390719
CVE-2026-54134OctoPrint: File exfiltration possible via query parameters on upload endpointsOctoPrint7.0 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-43980Malla: Stored XSS via Meshtastic node names in multiple frontend pagesmalla6.3 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-55185Miniflux 2: Open Redirect Bypassv25.1 (v4.0)Medium344365
CVE-2026-53468Typemill has Stored HTML Attribute Injection in Metadata Fieldstypemill4.6 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-77681CodeAstro Online Job Portal update-profile.php unrestricted uploadOnline Job Portal2.1 (v4.0)Low351000
CVE-2026-18482neo-mjs Command Injection Vulnerabilityneo-mjs9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gatewayser7212pc firmware9.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-53804OTRS Community Edition OS Command Injection via PGP ConfigurationOTRS Community Edition8.6 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-76635baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.phpbasercms8.6 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-77072n8n before 1.123.69 Stored XSS via Form Completion Pagen8n8.4 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-15686Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution VulnerabilityAdminer7.2 (v3.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-18274Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution VulnerabilityDatabase Proxy7.2 (v3.0)High340007 , 344360 , 390709
CVE-2026-73255Mongoose: Path traversal in SSI #include directives enables arbitrary file readmongoose6.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-728609router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unre9router6.3 (v4.0)Medium337109 , 337110 , 344360 , 390719 , 398021 , 398022
CVE-2026-49244SFTPGo: Path confinement bypass in public browsable share partial ZIP downloadsftpgo5.9 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-75628Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa-5.7 (v3.1)Medium344365
CVE-2026-76762code-projects Assessment Management welcome.php sql injectionAssessment Management5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76764code-projects Employee Management System Admin Login Endpoint aprocess.php sql injectionEmployee Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76795AeternaLabsHQ PullMD REST API Endpoint api server-side request forgeryPullMD5.5 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-76990code-projects Simple Inventory System delete.php sql injectionSimple Inventory System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76996SourceCodester Simple Online Food Ordering System view_order.php sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76998SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-77019CodeAstro Apartment Visitor Management System forgotpw.php sql injectionApartment Visitor Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-77020CodeAstro Apartment Visitor Management System password-recovery.php sql injectionApartment Visitor Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-54508TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolutionTREK5.3 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-72846Lightdash Scheduled Delivery Webhook URLs Are Not Validated, Allowing Server-Side Request Forgerylightdash5.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-77067Omnivore Stored Server-Side Request Forgery via the setWebhook Mutationomnivore5.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-77648Glance Server-Side Request Forgery VulnerabilityGlance2.2 (v3.1)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-76785amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injectionMini-Inventory-and-Sales-Management-System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76991itsourcecode Hospital Management System viewappointmentapproved.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76997SourceCodester Simple Online Food Ordering System ajax.php save_category sql injectionSimple Online Food Ordering System2.1 (v4.0)Low340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-77025itsourcecode Hospital Management System viewappointmentpending.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76995SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted uploadSimple Online Food Ordering System2.0 (v4.0)Low351000
CVE-2026-51366Bottinelli Informatica Vedo Suite v.1.2.5 Arbitrary Code Execution VulnerabilityBottinelli Informatica Vedo Suite v.1.2.59.9 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-53545Termix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionTermix9.8 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-55085Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-liteetherpad9.6 (v3.1)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45272MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config Filetalebook9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-62668Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocolsgrav9.4 (v4.0)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-66794Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public routemulticluster engine for Kubernetes 2.19.3 (v3.1)Critical337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-48024Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh managerwazuh9.1 (v3.1)Critical340007 , 344360 , 390709
CVE-2026-48162Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pawazuh9.1 (v3.1)Critical340007 , 344360 , 350591 , 390709
CVE-2026-32475Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerElementor Pro9.0 (v3.1)Critical398001
CVE-2026-44829Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filenamegotenberg8.8 (v3.1)High340007 , 344360 , 390709
CVE-2026-61518ISPConfig Authenticated SQL Injection via Remote API primary_id Parameterispconfig38.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63722ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpICEcoder8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()grav8.7 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655
CVE-2026-68899Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallbackwekan8.7 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-76205phpMyFAQ before 4.1.7 SQL Injection via Glossaryphpmyfaq8.6 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-64851Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlersgrav-plugin-shortcode-core8.5 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-68558Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)wekan8.5 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-76225ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSVarcadedb8.3 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 390109 , 398021 , 398022
CVE-2026-53549Termix: Server-Side Request Forgery via Proxy Connectivity TestTermix7.7 (v3.1)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-18430HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reasonHumHub7.2 (v4.0)High333140 , 333141 , 340147 , 340148 , 346755
CVE-2026-18756HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button renderingHumHub7.2 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-76210phpMyFAQ before v4.1.6 Local File Disclosure via PDF Exportphpmyfaq7.1 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-55087Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (opeetherpad6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-75986code-projects Online Job Portal System Password Recovery ForPass.php sql injectionOnline Job Portal System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76048SourceCodester Simple Online Food Ordering System ajax.php login sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-76049SourceCodester Simple Online Food Ordering System ajax.php save_menu sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-76574code-projects Hospital Information System User Login UsersController.php login sql injectionHospital Information System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76760chenhg5 cc-connect webhook.go authenticate code injectioncc-connect5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76761chenhg5 cc-connect Management API engine.go shellExecCommand os command injectioncc-connect5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-53452Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPathground-station5.3 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-76239Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_addressstigmem-node5.3 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-76614OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restoreopenemr5.3 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-40507OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portalopenemr5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-40508OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handleropenemr5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-76203CSS sanitizer bypass in Pentestify report themes allows forced outbound requestsPentestify5.1 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-76576yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversalRuoYi-Vue2.1 (v4.0)Low340007 , 344360 , 347009 , 390709
CVE-2026-55166Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and crlemur9.9 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-12564Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credentiRed Hat Ansible Automation Platform 29.6 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-45118MyBB: Contact page reflected XSSmybb9.3 (v3.1)Critical333140 , 333141 , 340003 , 340087 , 340095 , 340099 , 340147 , 340148 , 340158 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-74902SiYuan before v3.7.4 XSS-to-RCE via malicious filename uploadsiyuan9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-52610reportico-web <= 8.1.0 Path Traversal Vulnerabilityreportico-web <= 8.1.09.1 (v3.1)Critical340007 , 344360 , 347009 , 390709
CVE-2026-501864gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export4gaBoards8.8 (v3.1)High344360 , 347009 , 390709
CVE-2026-45115MyBB: Buddy/ignore list username XSSmybb8.7 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45116MyBB: Profile field type confusion XSSmybb8.7 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-54347Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeoverfroxlor8.7 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-75914CodeWhale before 0.8.64 Path Traversal via image_analyze symlinkCodeWhale8.7 (v4.0)High340007 , 344360 , 390709
CVE-2026-75833Grav API Plugin Open Redirect via Backslash Bypassgrav8.6 (v4.0)High344365
CVE-2026-75855ArcadeDB before 26.8.1 Path Traversal via create/drop databasearcadedb8.4 (v4.0)High340007 , 344360 , 390709
CVE-2026-75898RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Componentragflow8.4 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-75842ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSVarcadedb8.3 (v4.0)High340007 , 340029 , 344360 , 344370 , 390109 , 390709
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.phpgrav8.2 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-50143Actor MCP path authority injection leaks Apify tokenapify-mcp-server8.1 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-71303Lemur: Incomplete fix for CVE-2026-55166 – ACME authority update endpoint allows non-admin to replace acme_url with ilemur7.7 (v3.1)High337109 , 337110 , 340163 , 344360 , 398021 , 398022
CVE-2026-71365Awx: webhook status callback ssrf leaks the git patRed Hat Ansible Automation Platform 2.5 for RHEL 87.7 (v3.1)High337109 , 337110 , 344360 , 390719 , 398021 , 398022
CVE-2026-70666Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLslemur7.4 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-75830grav-plugin-api before 1.0.15 Path Traversal via batchCopygrav7.1 (v4.0)High340007 , 344360
CVE-2026-75844ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypassarcadedb7.1 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-74038Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollmentwazuh-manager7.0 (v4.0)High340007 , 344360
CVE-2026-52607reportico-web <= 8.1.0 Path Traversal Vulnerabilityreportico-web <= 8.1.06.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-63643MagicMirror: ssrf calendar .jsMagicMirror6.3 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-70667Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete filemur6.3 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-68922MobSF: Arbitrary File Read via Path Traversal in ZIP UploadsMobile-Security-Framework-MobSF5.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-75079SourceCodester Class and Exam Timetabling System edit_subject2.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75080SourceCodester Class and Exam Timetabling System edit_subject1.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75089PHPGurukul Complaint Management System check_availability.php sql injectionComplaint Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-75778code-projects Task Management System Login Form index.php select_with_multiple_condition sql injectionTask Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-54543Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fieldsfroxlor5.4 (v3.1)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-47720FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdStringFUXA5.3 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-74908Grav plugin-api before 1.0.15 Script Injection via SVGgrav5.1 (v4.0)Medium351000
CVE-2026-75831Grav before 2.0.15 Stored XSS via audio/video source URLgrav5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-68927MobSF: SSRF port restriction bypass in assetlinks_checkMobile-Security-Framework-MobSF3.0 (v3.1)Low337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2024-14046OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted uploadOpenBoxes2.1 (v4.0)Low351000
CVE-2026-75086itsourcecode Hospital Management System viewroom.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75087itsourcecode Hospital Management System viewdepartment.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75088itsourcecode Hospital Management System viewbilling.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75876xianrendzw EasyReport Move Operations ModuleController.java sql injectionEasyReport2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-67678RainyGao-Hithub DocSys v.2.02.80 Arbitrary Code Execution VulnerabilityRainyGao-Hithub DocSys v.2.02.809.8 (v3.1)Critical351000
CVE-2026-67919Halo 2.25.4 Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-67926JeecgBoot v.3.9.2 Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-15623Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query ServiceGoogle SecOps (Chronicle SOAR)9.4 (v4.0)Critical341245 , 344367
CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirectmlflow9.3 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-74798SiYuan kernel Path Traversal via database_clean MCP toolsiyuan9.3 (v4.0)Critical340007 , 344360 , 390709
CVE-2026-75111Evidently UI Path Traversal via Dataset Materialization Filenameevidently8.7 (v4.0)High344360 , 347009 , 390709
CVE-2026-75482SWE-agent Trajectory Inspector Path Traversal File DisclosureSWE-agent8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-566779Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint9router8.6 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-64657Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQLbudibase8.4 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-33437Stirling PDF: Stored XSS in Info SummaryStirling-PDF8.1 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2025-27621UpTrain has a Constant Default API Keyuptrain7.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-50776Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution VulnerabilityPronis Loisirs Billetterie CSE - < 04/20267.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-40506OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.phpopenemr7.0 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-19983GL.iNet XE3000 NAS Command Service gl_nas_sys os command injectionA13006.9 (v4.0)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-63667ApostropheCMS: Arbitrary file read via import-export attachment-name path traversalapostrophe6.5 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-48053Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewsetkolibri5.8 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-75014SourceCodester Pet Grooming Management Software get_barcode_data.php sql injectionPet Grooming Management Software5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-74858jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgeryfetcher-mcp5.3 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19972itsourcecode Hospital Management System viewpatient.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19973itsourcecode Hospital Management System viewpaymentreport.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19984jkawamoto mcp-florence2 init.py get_images server-side request forgerymcp-florence22.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19998code-projects Online Shopping System offersmail.php cross site scriptingOnline Shopping System2.1 (v4.0)Low333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-20000itsourcecode Hospital Management System viewprescriptionrecord.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-74842Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgeryPromptShopMCP2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-75077SourceCodester Class and Exam Timetabling System BSCE2.php cross site scriptingClass and Exam Timetabling System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-75078SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scriptingClass and Exam Timetabling System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-19964Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injectionJij-MCP-Server2.0 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73058stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypassstoatchat6.9 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19919code-projects Online Shopping System Login login.php sql injectionOnline Shopping System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19926Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injectionEvergreen5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19956gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-side request forgeryfacebook-ads-mcp-server5.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19920code-projects Online Shopping System action.php sql injectionOnline Shopping System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19921code-projects Online Shopping System homeaction.php sql injectionOnline Shopping System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19923code-projects Online Shopping System checkout_process.php sql injectionOnline Shopping System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19927OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgeryOpenBoxes2.1 (v4.0)Low337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19932DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injectionNotice-System-Managent2.1 (v4.0)Low340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-19934itsourcecode Hospital Management System vieworder.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19958iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injectionpptr-mcp2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-19922code-projects Online Shopping System checkout.php cross site scriptingOnline Shopping System2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19925SourceCodester Stock Management System Master.php delete_supplier sql injectionStock Management System2.0 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19598Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Routerpods9.8 (v3.1)Critical377360
CVE-2026-73041SiYuan before v3.7.4 Remote Code Execution via PDF Annotationssiyuan9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73042SiYuan before v3.7.4 Remote Code Execution via Menu Metadatasiyuan9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-73043SiYuan before v3.7.4 Remote Code Execution via Template Calculationsiyuan9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73044SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Widthsiyuan9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73050SiYuan before v3.7.4 Stored XSS via select option colorsiyuan9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73052SiYuan before v3.7.4 Stored XSS via Attribute-View Field Namessiyuan9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73053SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emojisiyuan9.4 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19900LB-LINK Routers - Unauthenticated Command Injectionbl-wr9000 firmware8.2 (v4.0)High390904
CVE-2026-16007Authenticated SQL Injection in AppFlowyAppFlowy-Cloud7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19899SourceCodester Class and Exam Timetabling System edit_teacher.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19894itsourcecode Hospital Management System viewmedicine.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19917code-projects Online Food Order System delete_food_items1.php sql injectionOnline Food Order System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19188Haiwell IoT Cloud HMI Gateway OS Command InjectionHaiwell IoT Cloud HMI Gateway10.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-48528Metacat has an unauthenticated SQL injection vulnerabilitymetacat9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Uploadgrav8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72827Grav CMS before 2.0.13 Remote Code Execution via Twiggrav8.7 (v4.0)High340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypassgrav8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73680Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg FilenameCockpit CMS8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73850Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Functionemlog8.6 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63361LimeSurvey Community Edition 7.0.5+260623 - Reflected XSS in HTML editor popupLimeSurvey8.5 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-69101Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpointtis8.3 (v4.0)High330791 , 340152 , 344360 , 344370 , 344372 , 344373 , 398008
CVE-2026-19771Baicells EG3661M LuCI Web luci os command injectionEG3661M7.3 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-74247Quay: ssrf via build archive_url in quay build apiopenshift update service7.1 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-72814actix-web before 0.6.10 Information Disclosure via Filesactix-web6.3 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-18403LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDBLimeSurvey6.0 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19758dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversallamp-cloud5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-19762DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversalTaier5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-19827alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversalalldata5.5 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-19785francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injectionRosarioSIS5.3 (v4.0)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-73845CKAN MCP Server: MQA server allowlist bypass via unanchored regex (isValidMqaServer)ckan-mcp-server5.3 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19761DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversalTaier5.1 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-19763DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversalTaier5.1 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-72821Grav Form Plugin before 9.1.15 Stored XSS via Radio Togglegrav5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72832Grav before 2.0.12 Stored XSS via quoted-attribute bypassgrav5.1 (v4.0)Medium333140 , 333141
CVE-2026-19767itsourcecode Hospital Management System viewdoctortimings.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19828648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversalwvp-GB28181-pro2.1 (v4.0)Low340007 , 344360 , 347009 , 390709
CVE-2026-19829648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversalwvp-GB28181-pro2.1 (v4.0)Low344360 , 347009 , 390709
CVE-2026-19787SourceCodester Air Cargo Management System Master.php save_cargo_type sql injectionAir Cargo Management System2.0 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19839SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted uploadSimple Doctors Appointment System2.0 (v4.0)Low351000
CVE-2026-49819UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdUpSnap9.8 (v3.1)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-49827WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)WebErpMesv29.8 (v3.1)Critical351000
CVE-2026-72850Budibase before 3.40.0 Arbitrary File Write via Path Traversalserver9.4 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-73483Flowise before 3.1.3 Sandbox Escape via Puppeteerflowise9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72851Budibase before 3.40.0 SQL Injection via Unauthenticated Webhookserver9.0 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-73485Flowise before 3.1.3 Remote Code Execution via Airtable Agentflowise9.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73486Flowise before 3.1.3 Code Injection via CSV Agent customReadCSVflowise9.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73487Flowise before 3.1.3 Prompt Injection RCE via CSV Agentflowise9.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73570zimbra collaboration suite Arbitrary Code Execution Vulnerabilityzimbra collaboration suite8.9 (v3.1)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2019-25765ASP-CMS SQL Injection via commentList.asp id ParameterASP-CMS8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2024-58374Hongjing e-HR Unauthenticated SQL Injection via getSdutyTreee-HR8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-49864wetty vulnerable to DOM XSS via file-download filenamewetty8.6 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 344365 , 346755 , 350147 , 350148
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Modulebackup8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73670CMS Admin SQL Injection via db_data.php table_name ParameterSaurus CMS Community Edition8.6 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 380026 , 380122 , 390572
CVE-2026-57894Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository ExfilGitea Open Source Git Server8.5 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-72855Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and RESTserver8.4 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-73629Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addressesSerendipity8.4 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-73658Trigger.dev: Cross-tenant object store read and write via URL path traversaltrigger.dev8.2 (v3.1)High347009
CVE-2026-61979WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerabilitySAML SP Single Sign On8.1 (v3.1)High300022
CVE-2026-73659Trigger.dev: Cross-tenant object read/write via path traversal in packet presign APItrigger.dev8.1 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-58314Two SSRF findings in Gitea 1.26.2Gitea Open Source Git Server7.7 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataGitea Open Source Git Server7.5 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-49857auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopbackauth-fetch-mcp7.4 (v3.1)High337109 , 337110 , 344360 , 398004 , 398021 , 398022
CVE-2026-45725compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversalcompliance-trestle7.1 (v4.0)High347009
CVE-2026-45774compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversalcompliance-trestle6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypassGitea Open Source Git Server6.5 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-73573zimbra collaboration suite Path Traversal Vulnerabilityzimbra collaboration suite6.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-73574zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerabilityzimbra collaboration suite6.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-73530Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip()flyto-core6.3 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19710SourceCodester Simple Student Information System view_department.php sql injectionSimple Student Information System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19753Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgerymcp-rdf-explorer5.5 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-73038NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.nameNodeBB5.3 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73628Serendipity 2.3.5 Reflected XSS via search clean-URL routeSerendipity5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-19716Stored Cross-site Scripting in Pentestify user account deletion via unescaped usernamePentestify5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73671Saurus CMS Unauthenticated Open Redirect via logout url parameterSaurus CMS Community Edition5.1 (v4.0)Medium344365
CVE-2026-49856@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorizationjshookmcp4.3 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-73657Trigger.dev: Cross-tenant payload poisoning via packet write + replaytrigger.dev4.2 (v3.1)Medium347009
CVE-2026-23603Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claimGitea Open Source Git Server3.1 (v3.1)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19752EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgerymcp-dominican-layer2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19756Dromara lamp-cloud Code Generator DefGenProjectController.java path traversallamp-cloud2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configurationlxd9.9 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-66898Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCElxd9.9 (v3.1)Critical390719
CVE-2026-73263Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-pathprowler9.9 (v3.1)Critical340014 , 340023 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73294Semaphore U: OS Command Injectionsemaphore9.9 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-57858Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking IDCal.com Self-Hosted (Cal.diy)9.3 (v4.0)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-44741Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Paramepimcore8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-15217Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab8.7 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-16033Arbitrary file read+write on host via templates/ symlink in malicious imagelxd8.5 (v3.1)High344360 , 390709
CVE-2026-65937WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UIwhatsup gold8.0 (v3.1)High340147 , 340148 , 340149
CVE-2026-73498MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_atmcp-atlassian7.7 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-64826rConfig < 8.2.13 Path Traversal File Read via FileDownloadControllerrConfig7.1 (v4.0)High344360 , 347009 , 390709
CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation propertiesastro5.3 (v4.0)Medium333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2026-48552Nagios Core / XI DOM-based XSS via jsonquery.jsNagios Core5.1 (v4.0)Medium333140 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-70560Ultimate POS Stored XSS via First Name Field in Leave NotificationsUltimate POS (Stock Management & Point of Sale)4.8 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-49262Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxypagible3.0 (v3.1)Low337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-46670YesWiki: Unauthenticated SQL Injectionyeswiki9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-31114Fooocus webui vulnerable to Remote Code ExecutionFooocus9.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73069Twenty: SQL Injection in the searchVector Field Settings Allows Arbitrary PostgreSQL Executiontwenty9.1 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-55676Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload componentMalcolm8.8 (v3.1)High351000
CVE-2026-72557Cockpit CMS Cockpit CMS - Unrestricted File UploadCockpit CMS8.8 (v3.1)High351000
CVE-2026-73222Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio)claude-code-templates8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2016-20097Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoadE-cology 8.08.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2022-50997Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jspE-cology 9.08.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72713XAgent Path Traversal Arbitrary File Read via /workspace/fileXAgent8.7 (v4.0)High340007 , 344360 , 390709
CVE-2026-5917libgit2 Shell Command Injection via ssh_libssh2 Backendlibgit28.6 (v4.0)High340014 , 347009 , 393655
CVE-2026-51583usememos through v0.30.0 Server-Side Request Forgery Vulnerability-8.5 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-73079Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstreasub2api8.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-67179Genkit improper host header validationgenkit7.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72607Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by AgeKoha7.1 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72609Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.plKoha7.1 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-71475Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url pathadvanced cluster management for kubernetes6.8 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-72608Koha Community Koha - Stored SQL Injection via Patron Card Layout image_nameKoha6.5 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-73084Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpointactivepieces6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-73243kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypasskkFileView5.8 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-48483TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot servertypebot.io5.4 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-48762TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handlertypebot.io5.4 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-73082Activepieces: Server-side request forgery in MCP tool validation endpointactivepieces5.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-73244kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listingkkFileView5.3 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-19434Stored Cross-site Scripting in Pentestify finding severity fieldPentestify5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72747AVideo Stored Cross-Site Scripting via Unauthenticated RegistrationAVideo5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72610Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip GenerationKoha4.3 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-73087Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcherdozzle2.3 (v4.0)Low337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-72899Metabase SQL injection via public card or dashboardMetabase10.0 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72738Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameterdokploy9.9 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-72740Dokploy: OS Command Injection via SSH-form customGitUrl domain in ssh-keyscandokploy9.9 (v3.1)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72865Dokploy: OS Command Injection via compose composePathdokploy9.9 (v3.1)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72868Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injectiondokploy9.9 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEdokploy9.9 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-72872Dokploy: OS Command Injection via Bitbucket owner/repository in git clonedokploy9.9 (v3.1)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokploy9.9 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed serversdokploy9.9 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72902Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIddokploy9.9 (v3.1)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72592dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Uploadphpfm9.8 (v3.1)Critical340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsdokploy9.6 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72879Dokploy: Command Injection via Registry Credentials in Swarm Uploaddokploy9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-47754unauthenticated path traversal in Metacat 2.xmetacat9.3 (v3.1)Critical340007 , 344360 , 347009 , 390709
CVE-2026-63106ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.phpReady eCommerce9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFiledokploy8.8 (v3.1)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfercyberpanel8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72870Dokploy: Command Injection via Docker Credentials in buildRemoteDockerdokploy8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72874Dokploy: Command Injection via Unescaped Git URL in Clone Commandsdokploy8.7 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-66738SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLiteSPIP7.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009
CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Uploadcyberpanel7.1 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73033Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.phpsucuri-wordpress-plugin7.0 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-15047s2Member < 260805 - Contributor+ Stored XSS via Shortcodes2Member6.8 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-72739Dokploy: Command Injection via Compose Shell Executiondokploy6.5 (v3.1)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-16949Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookupTerm Pages5.8 (v3.1)Medium340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionipTIME AX8004M5.5 (v4.0)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-19384SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injectionSimple Doctors Appointment System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-17010Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post MetaSaitama Addon Pack5.4 (v3.1)Medium346755
CVE-2026-72570cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filenamedirectory-serve5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-72583fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Uploadfastschema5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-14860Podcast Player < 8.3.1 - Unauthenticated Server-Side Request ForgeryPodcast Player5.3 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-69116FlyEnv < 4.18.0 Cross-Site Scripting via v-htmlFlyEnv5.3 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72743SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-htmlSQLBot5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-14238Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-reportvitepos4.1 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19375dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgeryarticle-scraper-mcp2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19378code-projects Task Management System CommentSave.php cross site scriptingTask Management System2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19383saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted uploadSaiAdmin2.0 (v4.0)Low351000
CVE-2026-71984MSI Radix AXE6600 v781521 Command Injection via urlfilterRadix AXE66009.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71992MSI Radix AXE6600 v781521 Command Injection via macfilterRadix AXE66009.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-19343code-projects Task Management System AdminLogin.php sql injectionTask Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19344code-projects Task Management System comment_count_user.php sql injectionTask Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19374adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgeryapi-mcp5.5 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-17011Nexter Blocks < 5.0.2 - Contributor+ Stored CSS InjectionNexter Blocks3.8 (v3.1)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19340anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgeryProjectHub-Mcp2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19347itsourcecode Hospital Management System viewdoctor.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19364itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19369KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgeryjira-mcp-server1.9 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19373PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgeryKoboldCPP-MCP-Server1.9 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19353DedeCMS Installation Wizard index.php _4_Setup file inclusionDedeCMS1.3 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-71944D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectelDWR-M9619.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71945D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocomDWR-M9619.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71946D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRunDWR-M9619.3 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71947D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRunDWR-M9619.3 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71948D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRunDWR-M9619.3 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71949D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetupDWR-M9619.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71950D-Link DWR-M961 Command Injection via /boafrm/formSmsManageDWR-M9619.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71951D-Link DWR-M961 Command Injection via /boafrm/formIMEISetupDWR-M9619.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71952D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetupDWR-M9619.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71953D-Link DWR-M961 Command Injection via /boafrm/formNtpDWR-M9619.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71954D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetupDWR-M9619.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71955D-Link DWR-M961 Command Injection via /boafrm/formWscDWR-M9619.3 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71956D-Link DWR-M961 Command Injection via app.cgiDWR-M9619.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-16559YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon UploadYMC Filter6.8 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-67620Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-Listflowise6.3 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-16558YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder SchemaYMC Filter5.4 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-16955AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio TranscriptionAI Engine5.0 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-64637All Plesk Versions below 18.0.79.5 Reseller Privilege Escalation to RootPlesk9.9 (v3.0)Critical341245 , 344366
CVE-2022-4995Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jspE-cology 9.09.3 (v4.0)Critical351000
CVE-2026-64638WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell)WordPress8.9 (v4.0)High344370
CVE-2026-47659Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}pathling8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-47661Pathling has path traversal in $result endpoint that allows arbitrary warehouse file readpathling8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-48026lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTMLlakeFS8.7 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-64636Plesk 18.0.51 up to 18.0.79.4 Blind SQL InjectionPlesk7.7 (v3.1)High341245
CVE-2026-48093Code Embed - Contributor Stored Cross-Site Scripting via Remote URL Embedcode-embed6.5 (v3.1)Medium333140
CVE-2026-19196SourceCodester Photo Share Website ajax.php login sql injectionPhoto Share Website5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-19211SourceCodester Photo Share Website ajax.php signup sql injectionPhoto Share Website5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-15245BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider ShortcodeBNE Testimonials5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48094ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Outputshareopenly5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-17597Nexus Repository 3 - Server-Side Request Forgery via Email Configuration VerificationNexus Repository 35.1 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19210SourceCodester Photo Share Website ajax.php save_upload unrestricted uploadPhoto Share Website2.1 (v4.0)Low351000
CVE-2026-19246HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgerynanobot2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19209SourceCodester Photo Share Website index.php home cross site scriptingPhoto Share Website2.0 (v4.0)Low333140 , 333141 , 340147 , 340148 , 342259 , 350147 , 350148
CVE-2026-19207PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scriptingCompany Visitor Management System1.9 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-15732WGDashboard Server-Side Request Forgery VulnerabilityWGDashboard9.8 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-15733WGDashboard <= 4.3.2 - Authenticated OS Command Injection /etc/passwd ReadWGDashboard9.8 (v3.1)Critical344360 , 393655
CVE-2026-67688ICS-Park Smart Park Management System v2.0 Arbitrary Code Execution VulnerabilityICS-Park Smart Park Management System v2.09.8 (v3.1)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-67689FineAdmin V1.0 Arbitrary Code Execution VulnerabilityFineAdmin V1.09.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-12605glassfish Server-Side Request Forgery Vulnerabilityglassfish9.6 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-53975OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/execOpenChamber9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-53976OpenChamber <1.13.0 - Unauthenticated Arbitrary File ReadOpenChamber9.3 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-70558Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default TokenDinky9.3 (v4.0)Critical351000
CVE-2024-39024In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability-8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-62857Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resourcesfedify8.8 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-3430Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLiCreative Mail8.6 (v3.1)High340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-63725sysPass FileBackupService Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-16268Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce HandlerNewsletters8.2 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-48081OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footerappointment-booking-software8.1 (v3.1)High333140 , 333141 , 340095 , 342259
CVE-2026-16065Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV ImportWelcart e-Commerce6.5 (v3.1)Medium340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-45573Decidim: Push subscriptions can be abused for server-side requestsdecidim6.4 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-11588EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post CreationEONSR AEO Agent6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-18973heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgerysuper-agent-party5.5 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19000JeecgBoot Anonymous Chat Attachment send server-side request forgeryJeecgBoot5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19021SourceCodester Computer Repair Shop Management System Master.php delete_product sql injectionComputer Repair Shop Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16537Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery ShortcodeSlick Slider5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-18395Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode AttributesChild Pages Card5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-18968ttttonyhe OBlog tags.php cross site scriptingOBlog2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-19020itsourcecode Hospital Management System servicetype.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19040MissionSquad mcp-api dcrClients.ts server-side request forgerymcp-api2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19067itsourcecode Hospital Management System treatment.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19068itsourcecode Hospital Management System treatmentdetail.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19069itsourcecode Hospital Management System treatmentrecord.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19070itsourcecode Hospital Management System viewadmin.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19071itsourcecode Hospital Management System viewappointment.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19110DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scriptingDataGear1.9 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-15360Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_argsAjax Load More9.1 (v3.1)Critical340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-17623Langflow is affected OS Command Injection in Model Context Protocol featureslangflow8.8 (v3.1)High344360 , 347009 , 390709
CVE-2026-17625Langflow is affected by OS Command Injection in Model Context Protocol featureslangflow8.8 (v3.1)High344360 , 347009 , 390709
CVE-2026-60009theia Arbitrary Code Execution Vulnerabilitytheia8.8 (v3.1)High351000
CVE-2026-34966Gitea prior to 1.27.0 SSRF via Migration URI Fetch BypassGitea8.3 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-71320Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Propsnuxt8.1 (v3.1)High340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8183Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow7.7 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-10716Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creationDirectus7.5 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16573Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature UploadBit Form7.5 (v3.1)High346755
CVE-2026-46581mojarra Path Traversal Vulnerabilitymojarra7.5 (v3.1)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-61891theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerabilitytheia7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-71209audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traveaudiobookshelf7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-18900H3C NX15 Backend RPC esps file.exec os command injectionNX157.3 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-71284Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filenamefledge7.2 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-7646Langflow is affected by security vulnerabilities in Model Context Protocol featureslangflow6.5 (v3.1)Medium344360 , 347009 , 390709
CVE-2026-7658Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow6.5 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-17505WordPress TranslatePress < 3.2.6 - Cross-Site Scriptingtranslatepress-multilingual6.1 (v3.1)Medium333141 , 341256 , 346755 , 347198 , 350148
CVE-2026-17532Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site ScriptingSeraphinite Accelerator6.1 (v3.1)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-7869Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow5.4 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-53992Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date ParametersProjectSend5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-71283Fledge IoT Gateway Backup Restore Tar Path Traversalfledge4.9 (v3.1)Medium344360 , 390709
CVE-2025-15677GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place CategoriesGeoDirectory3.5 (v3.1)Low346755
CVE-2026-18896lavkush-maurya Student-Registration-System changepass.php sql injectionStudent-Registration-System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-18959yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversalInnoShop2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2026-18856Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgeryRhymix CMS2.0 (v4.0)Low337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-70477Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerabilityflowise9.5 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgentFlowise9.4 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-69110OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/musicopencode-studio9.3 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-70553MaxSite CMS Unauthenticated RCE via Install EndpointMaxSite CMS9.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-69251Flowise RCE via TypeORM DataSourceFlowise9.0 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-70369Koha - SQL Injection in reports/acquisitions_stats.plKoha8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-70370Koha - SQL Injection in reports/catalogue_stats.plKoha8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-70373Koha - SQL Injection in reports/issues_stats.plKoha8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-67200Perspective 5.0.0 Path Traversal via cwd_static_file_handlerperspective8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-69100LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Executionlamp-cloud8.7 (v4.0)High340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-70492Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messagesopen-webui8.7 (v3.1)High333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-65986CVAT has stored XSS via annotation guide assetscvat8.5 (v4.0)High333140 , 333141 , 340095 , 341256 , 342259 , 350147 , 350148
CVE-2026-69250Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret ExfiltrationFlowise8.5 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-69704Atals-Livre SQL Injection via Unsanitized GET Parameter in supp()Atals-Livre7.0 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-14872Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id ParameterDatabase for Contact Form 7, WPforms, Elementor forms6.8 (v3.1)Medium340017 , 340144 , 340156 , 340157 , 380122
CVE-2026-16069Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal PointBrizy6.8 (v3.1)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-16548Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response EndpointChat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat6.5 (v3.1)Medium351000
CVE-2026-54020Open WebUI: DNS Rebinding SSRF Bypassopen-webui6.3 (v3.1)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-70620Odysseus SSRF via Embedding Endpoint Configurationodysseus6.1 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-10526EmbedPress < 4.6.1 - Unauthenticated Blind SSRFEmbedPress5.8 (v3.1)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-18788Trippo ResponsiveFilemanager dialog.php unrestricted uploadResponsiveFilemanager5.5 (v4.0)Medium351000
CVE-2026-16536Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_idSimple Google Calendar Outlook Events Widget5.3 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-15233Nested Pages < 3.2.15 - Editor+ Stored XSS via Post TitleNested Pages4.8 (v3.1)Medium340087 , 340099 , 341099 , 341266
CVE-2026-66300SNOMED International Snowstorm reflected XSSSnowstorm2.3 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-18766chetans9 core-php-admin-panel customers.php sql injectioncore-php-admin-panel2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-18774NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgeryhermes-agent2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-69083SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContentsiyuan9.9 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69084SiYuan - SQL Executionsiyuan9.9 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 344366 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69085SiYuan before v3.7.3 SQL Injection via searchDocssiyuan9.9 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-51775Fastadmin v.1.6.1.20250430 SQL Injection VulnerabilityFastadmin v.1.6.1.202504309.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69240Sequelize: SQL Injection (Oracle DB)sequelize9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39932OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injectionopenemr9.4 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-16532Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission FormLink Library9.1 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-41453Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameterlaravel-crm8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermarkgrav8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-69095OpenWrt luci-app-bmx7 Path Traversal via bmx7-infoluci8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-69096OpenWrt luci-app-dockerman Read ACL Remote Code Executionluci8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 350147 , 390904 , 393655
CVE-2026-39931OpenEMR Authenticated SQL Injection via backup.php Import Featureopenemr8.6 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-61523WebsiteBaker CMS < 2.13.10 Code Injection via Droplets EditorWebsiteBaker CMS8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-67599ClearOS 7.9 OS Command Injection via Log Viewer filter parameterClearOS8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-67608Telenia TVox 26.5.3 OS Command Injection via action_audio.phpTVox8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprintgrav8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-69086SiYuan before v3.7.3 Path Traversal via unvalidated avIDsiyuan8.3 (v4.0)High340007 , 344360 , 390709
CVE-2026-69192ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trusip-address7.7 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-18737Shlink Blind SQL Injection via tags/stats orderBy ParameterShlink7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69092Admidio before 5.0.11 Reflected XSS via SSO/SAML Endpointadmidio6.9 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-38444osTicket v1.18.3 Cross-Site Scripting Vulnerability-6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266
CVE-2026-38446Cross-Site Scripting-6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-18641Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginCOperation and Maintenance Security Management System5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-18646danpros HTMLy Author Name htmly.php path traversalHTMLy5.5 (v4.0)Medium340007 , 344360 , 347009
CVE-2026-49131OPNsense < 26.1.9 Stored XSS via Firewall Rule Description FieldOPNsense5.1 (v4.0)Medium333140 , 333141
CVE-2026-49132OPNsense < 26.1.9 Stored XSS via Certificate Description FieldOPNsense5.1 (v4.0)Medium333140 , 333141
CVE-2026-66296Reflected XSS in oaskit's default HTML error handleroaskit5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-15673Import and export users and customers < 2.4.3 - Admin+ Arbitrary File ReadImport and export users and customers4.9 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-67612OpenEMR 8.2.0 Stored XSS via import_template.php Template Managementopenemr4.8 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-67617Microweber CMS 2.0.20 Stored XSS via tag_names Parametermicroweber4.8 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16297Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings ImportClearfy Cache4.1 (v3.1)Medium340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390904 , 398008
CVE-2026-18644danpros HTMLy Delete Username Endpoint htmly.php unlink path traversalHTMLy2.1 (v4.0)Low344360
CVE-2026-18645danpros HTMLy Admin Content Endpoint admin.php add_content path traversalHTMLy2.1 (v4.0)Low344360
CVE-2026-14920AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] ParameterAcyMailing8.2 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 380026 , 380122 , 390572
CVE-2026-14817Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data AttributesElement Pack Addons for Elementor6.8 (v3.1)Medium333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-14841King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid WidgetKing Addons for Elementor6.1 (v3.1)Medium346755
CVE-2026-14864JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine ShortcodeJetEngine5.4 (v3.1)Medium333140 , 340095 , 340147 , 342259 , 346755
CVE-2026-16063Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline ContentEvent Booking Manager for WooCommerce5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-68583luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.nameluci5.1 (v4.0)Medium333140 , 333141 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-16273Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post MetaNarrative Publisher4.6 (v3.1)Medium333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 346755 , 350147 , 350148
CVE-2026-67308Wazuh GitHub Actions Shell Injection via Fork Pull Requestwazuh9.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-67328@better-auth/sso before 1.6.21 Account Takeover via SSOsso8.6 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-67309Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypasstraefik7.8 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-13157Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File UploadTheme Demo Import7.2 (v3.1)High351000
CVE-2026-13158Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File UploadEverest Toolkit7.2 (v3.1)High351000 , 382238 , 390501
CVE-2026-15244HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter searchHUSKY7.2 (v3.1)High340748 , 344360 , 347006 , 390709
CVE-2026-13725Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjaxDynamic Pricing With Discount Rules for WooCommerce7.1 (v3.1)High346755
CVE-2026-67352luci-app-https-dns-proxy Stored XSS via resolver_urlluci6.8 (v4.0)Medium333140 , 333141 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-15234Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode AttributeCodeless Page Builder5.4 (v3.1)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-15262Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value ColumnAdmin Columns for ACF Fields5.4 (v3.1)Medium333141 , 340087 , 340095 , 340099 , 341099 , 341266
CVE-2026-15932Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path TraversalSupport Genix5.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2025-71404better-auth before 1.1.16 Reflected XSS via error parameterbetter-auth5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-67333better-auth before 1.6.13 Stored XSS via javascript redirect_uribetter-auth5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-15669Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress LabelBit Form4.8 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-10827Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block AttributesSpectra Legacy3.5 (v3.1)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 346755 , 350147 , 350148
CVE-2025-69946SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69948SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-12721Kirki < 6.0.13 - Unauthenticated SQL InjectionKirki8.6 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-56670ComfyUI: Stored XSS via SVG file upload on the /view endpointComfyUI8.2 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-15258Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed FilterProduct Feed Manager For WooCommerce8.1 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-12720Kirki < 6.0.13 - Unauthenticated PHP Object InjectionKirki7.5 (v3.1)High340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocore7.5 (v3.1)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655
CVE-2026-56671ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file readComfyUI7.5 (v3.1)High344360 , 347009 , 390709
CVE-2026-13392ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)ElementsKit Elementor Addons7.2 (v3.1)High340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-14833Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption AttributeLightbox with PhotoSwipe6.8 (v3.1)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-14554Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s ParametersCheck & Log Email6.5 (v3.1)Medium340017 , 340144 , 340156 , 340157 , 380122
CVE-2026-52371xxl-job v3.4.0 Server-Side Request Forgery Vulnerabilityxxl-job v3.4.06.5 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-14845NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post WidgetNewStatPress6.1 (v3.1)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-14921Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons ShortcodeUltimate Addons for WPBakery Page Builder6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 346755
CVE-2026-52232FS Inc S3150-8T2F Switch 2.2.0D Build 118101 Cross-Site Scripting VulnerabilityFS Inc S3150-8T2F Switch 2.2.0D Build 1181016.1 (v3.1)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-45376Decidim: Admin user search allows SQL injection through similarity-based sortingdecidim5.5 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-59231Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLsPentestify5.3 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-59232Stored Cross-site Scripting in Prospero Flow CRM lead name fieldProspero Flow CRM5.3 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-55495Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Accountcloudreve4.3 (v3.1)Medium340007 , 344360 , 347009 , 390709 , 390719
CVE-2026-15381WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filterWP Go Maps3.7 (v3.1)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-13393ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)ElementsKit Elementor Addons3.5 (v3.1)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-55825Contao: Possible path traversal in job download URIscontao3.1 (v3.1)Low340007 , 344360 , 347009 , 390709
CVE-2026-67350Serendipity < 2.6.1 Open Redirect via exit.phpSerendipity2.1 (v4.0)Low344365
CVE-2025-65336Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69930CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69931CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69933CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69934CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69935SQL Injection-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69936CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69937CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69938CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69941SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69947SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointlangflow9.8 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-35847the CheckUils.php file Arbitrary Code Execution Vulnerabilitythe CheckUils.php file9.8 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-66418OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Fieldopenclaw agent dashboard9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-14602Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query ParameterRemote API9.0 (v3.1)Critical340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Uploadwolfcms8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655
CVE-2026-57862Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP NotationKanboard8.4 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-67346Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypassswarms7.7 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-16969DFIR-IRIS Stored XSS in Assetsiris-web7.6 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-18360DFIR-IRIS Stored XSS in Custom Attributesiris-web7.6 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-18361DFIR-IRIS Stored XSS in Datastore Uploadiris-web7.6 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-14239Tourmaster < 5.4.8 - Stored XSS via CSRFtourmaster7.1 (v3.1)High333141 , 340087 , 340095 , 340099 , 340148 , 341099 , 341266 , 346755
CVE-2026-54885Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetchingboruta6.9 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-15153WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List SearchWP Hotel Booking6.8 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-15974sglang Server-Side Request Forgery Vulnerabilitysglang6.5 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2025-65341Ecommerce Fruits Bazar 1.0 Cross-Site Scripting Vulnerability-6.1 (v3.1)Medium333140 , 333141 , 340095 , 342259
CVE-2026-11881Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time FieldFluent Forms6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-13330Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG UploadAnimation Addons for Elementor6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-14207LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing InformationLifterLMS6.1 (v3.1)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-61526AdonisJS HTTP Server is vulnerable to reflected XSS through its exception handlerhttp-server6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16531Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servletRed Hat Enterprise Linux 105.3 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-64870MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validationMaxKB5.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-66414Leantime Open Redirect in Login Controller via redirectUrl ParameterLeantime5.1 (v4.0)Medium344365
CVE-2025-65340kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67403Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67404Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69942kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69943SQL Injection-9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-41939Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFlyCare Everywhere Gateway9.3 (v4.0)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-67426Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationflyto-core9.3 (v3.1)Critical337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-11974Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Downloadwp-media-folder-addon8.6 (v3.1)High340748 , 344360 , 347006 , 390709
CVE-2026-67424Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationflyto-core8.5 (v3.1)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-67428Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRFflyto-core8.5 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-5487DriveLock Directory Traversal Information Disclosure VulnerabilityDriveLock7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2026-5491DriveLock Directory Traversal Information Disclosure VulnerabilityDriveLock7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2025-67405Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-7.3 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67406Advocate office management system Arbitrary Code Execution VulnerabilityAdvocate office management system7.3 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67407Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-7.3 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67408Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-7.3 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69944kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-7.3 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69945kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-7.3 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69949kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-7.3 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-14234WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRFWOLF7.1 (v3.1)High340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-13605Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title AttributePhotoSwipe6.8 (v3.1)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-18266Dify AI Workflow oauth_redirect_url Open Redirect VulnerabilityDify5.4 (v3.0)Medium344365
CVE-2026-3093Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab4.7 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-17524zip-lib Path Traversal Vulnerabilityzip-lib8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-54650openhole-server vulnerable to path traversal via URL-decoded request pathopenhole8.6 (v3.1)High347009
CVE-2026-43910Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutorjava-client8.2 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-54691datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirectsdatamodel-code-generator8.2 (v3.1)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-48060Litestar: HTML Injection Through CSRF Tokenlitestar8.1 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-14870Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_idDatabase for Contact Form 7, WPforms, Elementor forms7.1 (v3.1)High340087 , 340099 , 341099 , 341266
CVE-2026-56722Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URIdompdf6.3 (v4.0)Medium344360 , 390709
CVE-2026-63302Local File Inclusion in Quick.CMSQuick.CMS5.1 (v4.0)Medium344360 , 347009
CVE-2026-55554Dompdf: Chroot Validation Bypassdompdf2.3 (v4.0)Low344360 , 390709
CVE-2026-48030Pheditor 2.0.1-2.0.3 - OS Command Injectionpheditor9.9 (v3.1)Critical320008 , 320019 , 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-66395SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocolsiyuan9.4 (v4.0)Critical333140 , 340095 , 341266
CVE-2026-66398phpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIphpMyFAQ9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-61511vBulletin 6.x - Remote Code ExecutionvBulletin9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 360151 , 393655
CVE-2026-66394SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypasssiyuan9.3 (v4.0)Critical300013 , 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-66396SiYuan before v3.7.2 Stored XSS to RCE via title-img IALsiyuan9.3 (v4.0)Critical333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2025-50455the CodeIgniter Query Builder Arbitrary Code Execution Vulnerabilitythe CodeIgniter Query Builder9.1 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-17552Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenPlack::App::Prerender9.1 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022
CVE-2026-59239Stored XSS in Prospero Flow CRM email body allows administrator account takeoverProspero Flow CRM8.6 (v4.0)High333140 , 333141 , 340095
CVE-2026-66397phpMyFAQ before 4.1.6 Path Traversal via category image deletionphpMyFAQ8.6 (v4.0)High344360 , 390109
CVE-2026-51077Dede CMS v.5.7.118 SQL Injection VulnerabilityDede CMS v.5.7.1187.5 (v3.1)High340145 , 380122
CVE-2026-51078Dede CMS v.5.7.118 Information Disclosure Vulnerability-7.5 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-14827Calendar < 1.3.18 - Contributor+ Stored XSS via event_link ParameterCalendar6.8 (v3.1)Medium333140 , 333141 , 340095 , 342259
CVE-2026-12982Document Gallery < 5.1.1 - Reflected XSS via dg_generate_galleryDocument Gallery6.1 (v3.1)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-13400Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer InformationSimply Schedule Appointments6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-14190Sina Extension for Elementor < 3.10.2 - Reflected XSSSina Extension for Elementor6.1 (v3.1)Medium346755
CVE-2026-51565Modules/Docs/DocsController.php in Milk admin <=0.9.8 Cross-Site Scripting VulnerabilityModules/Docs/DocsController.php in Milk admin <=0.9.86.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-51564the redirect parameter in Milk admin <=0.9.8 Open Redirect Vulnerability-4.9 (v3.1)Medium344365
CVE-2026-14203Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post TitleSmart Manager4.8 (v3.1)Medium340087 , 340099 , 341099 , 341266
CVE-2026-14236Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open RedirectContact Form 74.7 (v3.1)Medium344365
CVE-2026-14189WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fieldsWPBot3.8 (v3.1)Low340017 , 340144 , 340156 , 340157 , 380122
CVE-2026-48051Papra: SSRF via HTTP redirect bypass in webhook deliverypapra3.5 (v3.1)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islandsastro2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-17458mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgeryopenclaw-cn2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-12496Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA serverLIP-ME20xC8.7 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-65693Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templatesmicroweber8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-65711sysPass 3.2.11 Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-65707Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpointlikeshop8.5 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-66004BlenderMCP Path Traversal via download_polyhaven_asset APIblender-mcp6.0 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-16910Quay: ssrf in red hat quay notification webhooks (slack/generic)Red Hat OpenShift Update Service5.5 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-47668DbGate - Remote Code Execution via Anonymous JWTdbgate10.0 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 360151 , 380026
CVE-2026-47670DbGate - Remote Code Execution via Dynamic Import Bypassdbgate9.4 (v4.0)Critical340014 , 340023 , 340029 , 340149 , 340162 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 346755 , 380026 , 393655
CVE-2026-637329router before 0.4.60 Remote Code Execution via default password9router9.4 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2024-58355Cal.com through 4.7.15 Cross-Site Scripting via booking questionscal.diy9.3 (v4.0)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-47669DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCEdbgate9.3 (v4.0)Critical340007 , 344360 , 390709
CVE-2026-65700h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files APIh2ogpt9.3 (v4.0)Critical340007 , 344360 , 347009 , 390709 , 390719
CVE-2026-65701SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Routeso-vits-svc9.3 (v4.0)Critical340007 , 344360 , 390709
CVE-2026-65761Joomla Easy Store - SQL InjectionEasy Store9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0Easy Store extension for Joomla9.2 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-65702Vanna 2.0.2 Path Traversal via FileSystemConversationStorevanna8.8 (v4.0)High340007 , 344360 , 390709
CVE-2026-47722nebula-mesh: Host advanced overrides allow YAML injection into agent config.ymlnebula-mesh8.7 (v4.0)High340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2026-47743Shopper: Multiple data integrity and disclosure issues in admin Livewire componentsshopper8.7 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-65694Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Readmicroweber8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-65759Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1Easy Store extension for Joomla8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-65919Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownloadmeshery8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-633139Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch9router8.3 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-65695Office-Word-MCP-Server 1.1.11 Path Traversal via document toolsOffice-Word-MCP-Server7.6 (v4.0)High344360 , 390709
CVE-2026-65698Void 1.3.4 Path Traversal via AI Agent File-Reading Toolsvoid6.0 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-16765CodeAstro Online Classroom loginlinkadmin.php sql injectionOnline Classroom5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48530GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48531GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48532GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48534GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48535GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48536GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48537GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48538GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-48539GFI Archiver < 15.13 Stored XSS via MailInsights.aspxGFI Archiver5.1 (v4.0)Medium333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-65697Fathom Lite 1.3.1 Stored XSS via /collect Endpointfathom5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9577Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod ParameterPost Status Notifier Lite4.8 (v3.1)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-48012Shopware SSO referer trust leading to an arbitrary redirect targetshopware4.3 (v3.1)Medium344365
CVE-2026-48013Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validationshopware4.1 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-12968Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG UploadProduct Addons and Product Options With Custom Fields8.8 (v3.1)High333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-65600Traefik before v2.11.52 Authentication Bypass via ReplacePathRegextraefik7.8 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-12987Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking RegistrationEvents Manager7.5 (v3.1)High340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-65012InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folderInvokeAI6.3 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-65593n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parametersn8n6.3 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-8984Unauthenticated RCEmaxicharger single charger firmware10.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8985Unauthenticated Command Injectionmaxicharger single charger firmware10.0 (v4.0)Critical340014 , 340023 , 344360 , 344361 , 344362 , 344363 , 344364 , 344366 , 344370
CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool executionPraisonAI9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-52472Wgcloud 3.6.4 SQL Injection VulnerabilityWgcloud 3.6.49.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-8986Command Injection via Malicious OCPP Servermaxicharger single charger firmware9.5 (v4.0)Critical340014 , 340023 , 340193 , 344360 , 344361 , 344362 , 344363 , 344364 , 344366 , 344370
CVE-2016-20096Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jspLinknat VOS30009.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreHome Assistant Core9.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicDatagrav9.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655
CVE-2026-65057Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheckkeep9.2 (v4.0)Critical337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-65317Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware BypassVerba9.2 (v4.0)Critical337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-65318Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReaderVerba9.2 (v4.0)Critical337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-47731NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by uAIT-Core9.1 (v3.1)Critical340007 , 344360 , 390709
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXA8.9 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-55084SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Readdhis2-core8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-47394PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validatePraisonAI8.7 (v4.0)High340007 , 344360 , 390709
CVE-2026-65056mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filteringmcp-webresearch8.3 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-47398PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20PraisonAI8.1 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-50758DayuanJiang next-ai-draw-io 0.4.13 Arbitrary Code Execution VulnerabilityDayuanJiang next-ai-draw-io 0.4.138.1 (v3.1)High333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-63764LMDeploy Server-Side Request Forgery via HTTP Redirect Bypasslmdeploy7.7 (v4.0)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-52476aiflowy <= 2.1.2 SQL Injection Vulnerabilityaiflowy <= 2.1.27.5 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63080Aptabase SQL Injection via ClickHouse query backendaptabase7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-46556FlaskBB: SSRF in get_image_info() via unrestricted avatar URLflaskbb6.5 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-52475aiflowy <= 2.1.2 Cross-Site Scripting Vulnerabilityaiflowy <= 2.1.26.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-13693Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path TraversalBit Form5.9 (v3.1)Medium340748 , 344360 , 347006 , 390709
CVE-2026-16484SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16336trinodb trino OAuth2/OIDC ExternalUriInfo.java redirecttrino5.3 (v4.0)Medium340165 , 344365
CVE-2026-64628Grav Stored Cross-Site Scripting via Shortcode Attribute Handlersgrav5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-16334itsourcecode Hospital Management System prescriptionorder.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16449zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injectionZS-Admin2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16451zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted uploadZS-Admin2.1 (v4.0)Low351000
CVE-2026-16485SourceCodester Class and Exam Timetabling System class.php cross site scriptingClass and Exam Timetabling System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16486SourceCodester Class and Exam Timetabling System BSIS.php cross site scriptingClass and Exam Timetabling System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-51027FileThingie v.2.5.7 Information Disclosure Vulnerability-9.9 (v3.1)Critical340007 , 344360 , 390709
CVE-2026-35048Piwigo RCE via PHP Code Injection into Config File in InstallerPiwigo9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-63766GPT-SoVITS 20250606v2pro OS Command Injection via webui.pyGPT-SoVITS9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-64625AVideo before 29.0 OS Command Injection via execAsyncAVideo9.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-13147WordPress Kirki < 6.0.12 - Server-Side Request Forgerykirki9.1 (v3.1)Critical320010 , 337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-35198HeyForm vulnerable to stored XSS via form field titlesheyform9.0 (v3.1)Critical333140 , 333141 , 340095 , 342259 , 350147 , 350148
CVE-2026-45270CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Ruleci4ms8.7 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-11349Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_moreModern Event Calendar Pro8.6 (v3.1)High340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-40187Authenticated RCE via Malicious eTemplate Upload in EGroupwareegroupware8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-63429HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form contextheyform8.6 (v3.1)High351000
CVE-2026-45711Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDsmailpit8.2 (v3.1)High340007 , 344360 , 390709
CVE-2026-54910FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesfilebrowser7.7 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-12592SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry HeaderSlimStat Analytics7.5 (v3.1)High333141 , 334168 , 340003 , 340099 , 340158 , 341099 , 342259
CVE-2026-32820dataCycle Public Markdown Path Traversal Via /docs/*pathdataCycle-CORE7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-34239Chamilo Authenticated Remote Code Executionchamilo-lms7.5 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-12970LearnPress < 4.4.1 - Reflected XSS via c_searchLearnPress7.1 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-46555WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationwhatsapp mcp server7.1 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-9833Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' ParameterTag Groups is the Advanced Way to Display Your Taxonomy Terms7.1 (v3.1)High340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-59238Stored XSS in Pentestify via unsanitized finding images and report client logoPentestify6.9 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-12898All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Writeall-in-one-wp-migration6.5 (v3.1)Medium330791 , 340152 , 340748 , 344360 , 347006 , 390709 , 390716
CVE-2026-45797HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Uploadheyform6.4 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-63107LimeSurvey SSRF via REST API Survey Template Host HeaderLimeSurvey6.3 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-63731HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpointhyperdx6.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-63769Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Methodhuginn6.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-26483Mettle SendPortal 3.0.1 and earlier Cross-Site Scripting VulnerabilityMettle SendPortal 3.0.1 and earlier6.1 (v3.1)Medium333140
CVE-2026-45709Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filtemailpit5.8 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-63428HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's decheyform5.8 (v3.1)Medium333140 , 333141 , 340095 , 342259 , 350147 , 350148
CVE-2026-16252Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injectionMultimedia Integrated Business Display System5.5 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-45138CI4MS: Stored XSS in Blog Content via Broken html_purify Validation Ruleci4ms5.4 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-44583Paymenter: Blind Unauthenticated SSRF on the Paypal gateway modulePaymenter5.3 (v3.1)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398021 , 398022
CVE-2026-63730HyperDX < 2.31.0 SSRF via Webhook Test Endpointhyperdx5.3 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-63768cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned Statecal.diy5.3 (v4.0)Medium340162 , 340163 , 340165 , 344365
CVE-2026-64626AVideo Encoder downloadURL SSRF via unpinned retry fallbackAVideo5.3 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-53594FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Pathfreescout4.9 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-46516Frogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments)frogman4.8 (v4.0)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-12724Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-passwordKirki4.3 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-16244itsourcecode Hospital Management System prescriptionorderreport.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16227SourceCodester Class and Exam Timetabling System edit_subject.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16228SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16219Croogo CMS Admin File Manager FileManager.php isEditable path traversalCMS2.1 (v4.0)Low344360 , 347009
CVE-2026-16220code-projects Online Examination System account.php cross site scriptingOnline Examination System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-162221Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgeryCordysCRM2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-162231Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgeryCordysCRM2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-16229itsourcecode Courier Management System index.php cross site scriptingCourier Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-16202SourceCodester Class and Exam Timetabling System CYS.php cross site scriptingClass and Exam Timetabling System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16203SourceCodester Class and Exam Timetabling System forCYS.php cross site scriptingClass and Exam Timetabling System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16205Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scriptingCMS1.9 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-16125zevorn rt-claw http_request net.c claw_net_post server-side request forgeryrt-claw5.5 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-16127zevorn rt-claw http_request tool_net.c claw_net_post server-side request forgeryrt-claw5.5 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-16128zevorn rt-claw http_request swarm.c receiver_thread server-side request forgeryrt-claw5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-16152SourceCodester Class and Exam Timetabling System edit_rooma.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16154SourceCodester Class and Exam Timetabling System edit_room1.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-57857Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_message ParameterFlow Payment5.1 (v4.0)Medium333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 346755
CVE-2026-16124nextlevelbuilder GoClaw web_fetch web_shared.go isPrivateIP server-side request forgeryGoClaw2.1 (v4.0)Low334168 , 390719
CVE-2026-16131itsourcecode Hospital Management System prescriptionrecord.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16194zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgeryCowAgent2.1 (v4.0)Low337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-16088halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversalhalo2.0 (v4.0)Low340007 , 344360 , 347009 , 390709
CVE-2026-16155SourceCodester Class and Exam Timetabling System schoolyr.php cross site scriptingClass and Exam Timetabling System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16156SourceCodester Class and Exam Timetabling System forexam.php cross site scriptingClass and Exam Timetabling System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16129princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklistSafestClaw1.9 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8481Remote Code Execution via Code Validation Endpointlangflow9.9 (v3.1)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-36669ck_upload_handler.php in Feng Office 3.11.13.11 Arbitrary File Upload Vulnerabilityck upload handler.php in Feng Office 3.11.13.119.8 (v3.1)Critical351000
CVE-2026-52348cool-admin-java 8.0.0 SQL Injection Vulnerabilitycool-admin-java 8.0.09.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionWordPress9.8 (v3.1)Critical340156 , 344370
CVE-2026-9198IBM Langflow - Remote Code Executionlangflow9.8 (v3.1)Critical300008 , 340095
CVE-2026-9586Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injectionswitchvox9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-58195Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into exagentic-flow8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-44739Pimcore: SQL Injection in Custom Reports Column Configurationpimcore8.7 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-62234Grav < 2.0.4 SSRF via Unrestricted cURL Protocolsgrav8.4 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-63094SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theftsignoz7.6 (v4.0)High344365
CVE-2026-39359Wazuh: Unauthenticated Path Traversal in authd via Agent Group Namewazuh7.5 (v3.1)High340007 , 344360 , 390709
CVE-2026-50151oras-go: credential forwarding via unvalidated Location header in blob uploadoras7.5 (v3.1)High390719
CVE-2026-15094WP Hotel Booking <= 2.3.2 - Cross-Site Scriptingwp-hotel-booking6.1 (v3.1)Medium300002
CVE-2026-60137WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryWordPress5.9 (v3.1)Medium340156 , 344370
CVE-2026-16074AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgeryAstrBot2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-44181Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionenterprise gateway10.0 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-44182Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Renderingenterprise gateway10.0 (v4.0)Critical340014 , 344362 , 344363 , 344364 , 344366
CVE-2026-45695Kopia Server 0.23.0 - Remote Code Executionkopia9.8 (v3.1)Critical393655
CVE-2026-46562Yamcs: Remote Code Execution via Mission Database algorithm overrideyamcs9.8 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-63304AVideo through 29.0 OS Command Injection via listFFmpegProcessesAVideo9.2 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-63305AVideo through 29.0 OS Command Injection via ffmpeg.json.phpAVideo9.2 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-46621Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionyamcs9.1 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-45868LogicalDOC Enterprise up to and for v9.1.1 SQL Injection Vulnerability-8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-45870LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability-6.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-30623LiteLLM 1.18.10 - Command InjectionLiteLLM 1.18.109.8 (v3.1)Critical320009
CVE-2026-53513Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationbetter-auth/sso9.6 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-45806Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-urlpenpot7.7 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-61835Directus: SSRF Protection Bypass via 0.0.0.0 in File Importdirectus7.7 (v3.1)High337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprisesplunk7.2 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-33213Redash: Open redirect vulnerability in post-login redirect handlingredash6.1 (v3.1)Medium344365
CVE-2026-41580Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author)stirling pdf6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-36214osTicket Cross-Site Scripting VulnerabilityosTicket6.4 (v3.1)Medium333140 , 342259
CVE-2026-6875ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCEservicenow9.5 (v4.0)Critical380026
CVE-2026-60121Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.phpflamingo9.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-61498Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.phpflamingo9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-58411ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and valuesCRM7.0 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-57827Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12rsfiles!10.0 (v4.0)Critical351000
CVE-2026-9282W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File ReadW3 Total Cache7.5 (v3.1)High336461 , 344360
CVE-2026-3576Planyo Online Reservation System <= 3.0 - Arbitrary File ReadPlanyo online reservation system7.2 (v3.1)High340165 , 344360 , 347009
CVE-2026-14894WordPress Super Forms <= 6.3.313 - Arbitrary File Uploadsuper-forms9.8 (v3.1)Critical340748
CVE-2025-30007HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Managementcontrol panel8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-56292AcyMailing < 10.11.1 - Unauthenticated SQL Injectionacymailing9.2 (v4.0)Critical340157 , 360147 , 360148
CVE-2026-58192Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-pluginappium/storage-plugin10.0 (v3.1)Critical340007 , 344360
CVE-2026-41042Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Executiongravitino9.1 (v3.1)Critical344370
CVE-2026-6854My Calendar < 3.7.9 - Unauthenticated SQL InjectionMy Calendar – Accessible Event Manager7.5 (v3.1)High341245 , 380026 , 380122
CVE-2026-49471Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEserena8.3 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-55592Dashy <= 4.3.6 - Reflected XSS via Workspacedashy3.9 (v3.1)Low340112 , 346755 , 350148
CVE-2026-58455Dockwatch <= 0.6.567 - OS Command Injectiondockwatch9.2 (v4.0)Critical344361 , 344363
CVE-2026-11387SMS Alert – SMS & OTP for WooCommerce - Privilege Escalationsms-alert9.8 (v3.1)Critical377360
CVE-2026-34100Guardian Language-System SQL Injection via id Parameter in media.phplanguage-system8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34101Guardian Language-System SQL Injection via id Parameter in text_file.phplanguage-system8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34102Guardian Language-System SQL Injection via id Parameter in job_info_get.phplanguage-system8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34103Guardian Language-System SQL Injection via id Parameter in subtitles.phplanguage-system8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34104Guardian Language-System SQL Injection via name Parameter in designer.phplanguage-system8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34105Guardian Language-System SQL Injection via id Parameter in translate_text.phplanguage-system8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-13731WPBot <= 8.4.9 - Cross-Site Scriptingchatbot7.2 (v3.1)High346755
CVE-2026-58138Orkes Conductor 3.21.21-3.30.1 - Remote Code Executionconductor9.3 (v4.0)Critical337209 , 337211 , 344366 , 380026 , 393655
CVE-2026-56782Gorse < 0.5.10 - Unauthenticated Database Dumpgorse9.3 (v4.0)Critical301007
CVE-2026-50229Apache Tomcat - Cross-Site Scriptingtomcat6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2026-49869Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilterkestra10.0 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-53576Kestra <= 1.3.20 - Remote Code Executionkestra10.0 (v3.1)Critical391213
CVE-2025-71334Flowise - Path Traversalflowise9.3 (v4.0)Critical340007
CVE-2026-54836YMC Filter - SQL InjectionYMC Filter9.3 (v3.1)Critical341245 , 380026 , 380122
CVE-2025-71324Flowise - Path Traversalflowise8.7 (v4.0)High340007
CVE-2026-53753Crawl4AI <= 0.8.6 - Remote Code Executioncrawl4ai10.0 (v3.1)Critical350147 , 360151 , 380026 , 393655
CVE-2026-28496FOSSBilling - Server-Side Template InjectionFOSSBilling9.4 (v4.0)Critical340130 , 340155 , 341155
CVE-2026-54157LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgerylobe-chat9.0 (v3.1)Critical392301
CVE-2026-54293NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Readnltk7.5 (v3.1)High347009
CVE-2026-6858Transbank Webpay < 1.14.0 - Unauthenticated Stored XSSTransbank Webpay7.1 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-8713Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletionfusion-builder9.1 (v3.1)Critical344360
CVE-2017-20260Joomla! Component Price Alert 3.0.2 SQL Injectionprice alert8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20261Joomla! Component Bargain Product VM3 1.0 SQL Injectionbargain product vm38.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20263Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via locationfocalpoint8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20266Joomla SP Movie Database 1.3 SQL Injection via searchwordstandard pro movie database8.8 (v4.0)High340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20267Joomla! Component Calendar Planner 1.0.1 SQL Injectioncalendar planner8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20268Joomla! Component Zap Calendar Lite 4.3.4 SQL Injectionzap calendar lite8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20269Joomla! Component KissGallery 1.0.0 SQL Injectionkissgallery8.8 (v4.0)High340145 , 380122
CVE-2017-20271Joomla StreetGuessr Game 1.1.8 SQL Injection via catidstreetguessr game8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20272Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_idultimate property listing8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20273Joomla Event Registration Pro Calendar 4.1.3 SQL Injectionevent registration pro calendar8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20274Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpathlearning management system king8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20275Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameterbridge8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20276Joomla! Component SIMGenealogy 2.1.5 SQL Injectionsimgenealogy8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20277Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_authorjoomla joomrecipe8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20278Joomla JoomRecipe 1.0.3 SQL Injection via category parameterjoomrecipe8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20279Joomla Payage 2.05 SQL Injection via aid Parameterjoomla payage8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20280Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parametermyportfolio8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20281Joomla! Component Extra Search 2.2.8 SQL Injectionextra search8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20282Joomla! Component jCart for OpenCart 2.0 SQL Injectionjcart for opencart8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25748Joomla JHotelReservation 6.0.7 SQL Injection via search-hotelsjhotelreservation8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25750Joomla J-MultipleHotelReservation 6.0.7 SQL Injectionmultiplehotelreservation8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25751Joomla J-ClassifiedsManager 3.0.5 SQL Injectionclassifiedsmanager8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25752Joomla! Component J-BusinessDirectory 4.9.7 SQL Injectionj-businessdirectory8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25756Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboardvaccount8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25749Joomla J-CruisePortal 6.0.4 SQL Injection via cruisesj-cruiseportal7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25761Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_idjoomcrm7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25760Joomla! Component Easy Shop 1.2.3 Local File Inclusioneasy shop6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-55746Cotonti stored XSS via PFS folder titleCotonti7.0 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48017DbGate: Remote Code Execution via functionName injection in loadReader endpointdbgate8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9278Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structureForm Builder CP5.4 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-8385WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosurewp-google-maps5.3 (v3.1)Medium344365
CVE-2026-12210universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgerypython-utcp2.1 (v4.0)Low337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-12211Intelbras iNVU 7016 FT Web syslog path traversaliNVU 7016 FT2.0 (v4.0)Low340007 , 344360 , 347009 , 390709
CVE-2026-11442Allegra exportReport Directory Traversal Information Disclosure VulnerabilityAllegra6.5 (v3.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-6428Koha SQL Injection in reports/catalogue_out.pl via Filter URL ParameterKoha5.6 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9061Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_nameStore Locator WordPress3.5 (v3.1)Low340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-9062Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path TraversalStore Locator WordPress3.4 (v3.1)Low340748 , 344360 , 347006 , 390709
CVE-2026-35273Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCEpeoplesoft enterprise peopletools9.8 (v3.1)Critical331032
CVE-2026-42647JoomSport <= 5.7.7 - SQL Injectionjoomsport-sports-league-results-management9.3 (v3.1)Critical341245 , 344366 , 380122
CVE-2026-8071Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode BypassAnti-Spam by CleanTalk. Spam protection8.8 (v3.1)High331702 , 333140 , 333141 , 344370 , 346755
CVE-2026-46518OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographicsopenemr8.7 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-3326XStore Theme < 9.7.3 - SQL InjectionXstore8.6 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-46491SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditisimplesamlphp-module-casserver8.6 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-3018WordPress Newsletters <= 4.13 - Unauthenticated SQL InjectionNewsletters7.5 (v3.1)High340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 380026 , 380122
CVE-2026-49069WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)WPZOOM Portfolio7.1 (v3.1)High300026
CVE-2026-9060Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_styleStore Locator WordPress3.5 (v3.1)Low346755
CVE-2017-20251WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST APIWoody Code Snippets9.3 (v4.0)Critical340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2016-20062Simply Poll 1.4.1 Plugin for WordPress SQL InjectionSimply Poll8.8 (v4.0)High340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2017-20243WordPress Car Park Booking Plugin SQL Injection via space_idCar Park Booking System8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20247WordPress Plugin PICA Photo Gallery 1.0 SQL InjectionPICA Photo Gallery8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20249WordPress Plugin Apptha Slider Gallery 1.0 SQL InjectionApptha Slider Gallery8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-36723bookcars v8.3 Arbitrary Code Execution Vulnerabilitybookcars v8.38.8 (v3.1)High340007 , 344360 , 390109 , 390709
CVE-2017-20248WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File DownloadApptha Slider Gallery8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2017-20250WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File DownloadMac Photo Gallery8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-46746sinec ins OS Command Injection Vulnerabilitysinec ins8.7 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-50636LimeSurvey RemoteControl invite_participants/remind_participants SQL InjectionLimeSurvey8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-36783Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability-7.5 (v3.1)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-36796Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability-7.5 (v3.1)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-36725FastapiAdmin v2.2.0 Cross-Site Scripting VulnerabilityFastapiAdmin v2.2.06.1 (v3.1)Medium333140
CVE-2026-36722bookcars v8.3 Arbitrary Code Execution Vulnerabilitybookcars v8.35.4 (v3.1)Medium351000
CVE-2026-25860OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload HandlerOpenClinic GA5.3 (v4.0)Medium333140 , 333141
CVE-2026-36726bookcars v8.3 Path Traversal Vulnerabilitybookcars v8.35.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-25557Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameterPHP Directory Listing Script5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-32856Ellucian Banner Self-Service Reflected XSS via dateConverterBanner Self-Service5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34416OSCAL-GUI Reflected XSS via project parameter in oscal.phpOSCAL-GUI5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34417OSCAL-GUI Reflected XSS via project parameter in oscal-forms.phpOSCAL-GUI5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-47106Ellucian Banner Self-Service Stored XSS via getFacultyMeetingTimes APIBanner Self-Service5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-46442Flowise < 3.1.2 - node-custom-function Unauthorized RCEflowise9.4 (v4.0)Critical345240
CVE-2024-58348WordPress Background Image Cropper 1.2 Remote Code ExecutionBackground Image Cropper9.3 (v4.0)Critical340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2023-54350WordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedAugmented Reality8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 , 393781
CVE-2026-25559OpenBullet2 0.3.2 Path Traversal via Wordlist Endpointopenbullet28.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-25855OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Uploadopenbullet28.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-25856OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interfaceopenbullet28.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-9506Path Traversal Vulnerability in BagistoBagisto8.7 (v4.0)High344360 , 347009 , 390709
CVE-2026-46484Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/userheadplane8.1 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-40519Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()nginx-proxy-manager7.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-11474Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted uploadstudent-management-system5.5 (v4.0)Medium351000 , 393655
CVE-2026-11482SourceCodester Class and Exam Timetabling System archive5.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11483SourceCodester Class and Exam Timetabling System archive4.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11484SourceCodester Class and Exam Timetabling System archive3.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11485SourceCodester Class and Exam Timetabling System archive2.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11486SourceCodester Class and Exam Timetabling System archive1.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11488code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injectionSimple Flight Ticket Booking System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11489code-projects Online Music Site AdminDeleteAlbum.php sql injectionOnline Music Site5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11490code-projects Online Music Site Search.php sql injectionOnline Music Site5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11501SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injectionHospitals Patient Records Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11582CodeAstro Student Attendance Management System index.php sql injectionStudent Attendance Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11569Quay: quay: stored xss via filedrop svg uploadRed Hat Quay 35.4 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-47983WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_codeAccept Stripe Payments5.1 (v4.0)Medium340095 , 346755
CVE-2026-11467jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversaljshERP2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2026-11475Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injectionstudent-management-system2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11476Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorizationstudent-management-system2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11477hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirecthsweb-framework2.1 (v4.0)Low340162 , 340163 , 340165 , 344365
CVE-2026-11495CodeAstro Ingredients Stock Management System add_stock.php sql injectionIngredients Stock Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11506CodeAstro Leave Management System search_staff_for_deletion.php sql injectionLeave Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11507CodeAstro Leave Management System delete_leave_type.php sql injectionLeave Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11508CodeAstro Leave Management System search_staff_to_assign_pc.php sql injectionLeave Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11510CodeAstro Leave Management System add_leave.php sql injectionLeave Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11512itsourcecode Hospital Management System billing.php cross site scriptingHospital Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-11513itsourcecode Hospital Management System adminaccount.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11514itsourcecode Hospital Management System addpatient.php sql injectionHospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11518SourceCodester Inventory System User Management users.php cross site scriptingInventory System2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 380106
CVE-2026-11529designcomputer mysql-mcp-server mysql URI server.py read_resource sql injectionmysql-mcp-server2.1 (v4.0)Low340016 , 380122
CVE-2026-11558CodeAstro Payroll System home_salary.php sql injectionPayroll System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11559CodeAstro Payroll System view_account.php sql injectionPayroll System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11583CodeAstro Student Attendance Management System createClass.php sql injectionStudent Attendance Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11584CodeAstro Student Attendance Management System createClass.php edit sql injectionStudent Attendance Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11585CodeAstro Student Attendance Management System createClassArms.php sql injectionStudent Attendance Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11468SourceCodester Hospitals Patient Records Management System page room_types cross site scriptingHospitals Patient Records Management System1.9 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-11502JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirectJeecgBoot1.3 (v4.0)Low340162 , 340163 , 340165 , 344365
CVE-2026-11450GL.iNet GL-MT3000 Path Normalization dlopen command injectionGL-MT30006.9 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-11456Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injectionCRM5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9290WP User Manager – User Profile Builder & Membership - Local File Inclusionwp-user-manager7.5 (v3.1)High320017
CVE-2026-7537MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' ParMDJM Event Management7.2 (v3.1)High351000
CVE-2026-11435Jinher OA nextselectplan.aspx sql injectionOA5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11408vertex-app vertex Log Viewer Endpoint LogMod.js os command injectionvertex2.1 (v4.0)Low340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-11412Jinher OA GetFormSn.aspx sql injectionOA2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11436Mage AI Sign-in Flow index.tsx useMutation cross site scriptingMage AI2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-11434FluentCMS Blocks Plugin blocks cross site scriptingFluentCMS1.9 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-48907Joomla! JCE extension < 2.9.99.5 unauthenticated RCEjce10.0 (v4.0)Critical333360 , 383871
CVE-2026-49777WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCEProduct Slider Pro for WooCommerce10.0 (v3.1)Critical301006
CVE-2026-10580Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account TakeoverHippoo Mobile App for WooCommerce9.8 (v3.1)Critical320008 , 330919
CVE-2026-11419Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Writeon-prem enterprise server9.4 (v4.0)Critical340007 , 344360 , 390709
CVE-2026-11423Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege EscalationAltium Enterprise Server9.4 (v4.0)Critical344360 , 390709
CVE-2026-46397haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0haxcms-php6.5 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-50592Znuny Cross-Site Scripting VulnerabilityZnuny6.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-50230Lyrion Music Server <= 9.2.0 - Cross-Site ScriptingLyrion Music Server5.1 (v4.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390716
CVE-2026-43986Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replayTautulli9.9 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-10880Unauthenticated SQL Injection in Osnexus QuantastorQuantaStor9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-8037Progress ADC LoadMaster - Command Injectionconnection manager for objectscale9.8 (v3.1)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-35906An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability-9.6 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2019-25727WordPress Plugin ad manager wd 1.0.11 Arbitrary File DownloadAd Manager WD9.3 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-43984Tautulli has stored XSS in logFile via guest-controlled log_js_errors inputTautulli8.9 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-25728Care2x 2.7 Hospital Information System SQL Injection via ck_configCare2x8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25730Listing Hub CMS 1.0 SQL Injection via pages.php idListing Hub CMS8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25732PHP EI-Tube Script 3 SQL Injection via search parameterEI-Tube8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25745WordPress Plugin Google Review Slider 6.1 SQL Injection via tidGoogle Review Slider8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69755Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability-8.2 (v3.1)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-11111chrome Security VulnerabilityExampleProduct8.1 (v3.1)High340016 , 340162
CVE-2026-10870Shibby Tomato Web UI rc start_dhcpc os command injectionTomato7.3 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10871Shibby Tomato Web UI rc start_6rd_tunnel os command injectionTomato7.3 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10873Shibby Tomato Web UI rstats rstats_path os command injectionTomato7.3 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-42538IRIS has an Insecure File Uploadiris-web6.3 (v3.1)Medium351000
CVE-2026-40605Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APITautulli5.7 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2019-25731Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole ContactZuz Music5.3 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2019-25739GigToDo Freelance Marketplace Script 1.3 Persistent XSSGigToDo5.1 (v4.0)Medium333140 , 333141
CVE-2026-42329Iris has an Open Redirect issueiris-web4.7 (v3.1)Medium344365
CVE-2026-10806mjperpinosa stumasy add_post.php unrestricted uploadstumasy2.1 (v4.0)Low351000
CVE-2026-10807mjperpinosa stumasy change_profile_image.php unrestricted uploadstumasy2.1 (v4.0)Low351000
CVE-2026-10808itsourcecode Fees Management System manage_student.php sql injectionFees Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10809itsourcecode Fees Management System manage_user.php sql injectionFees Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10810itsourcecode Fees Management System navbar.php cross site scriptingFees Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-10811itsourcecode Fees Management System receipt.php sql injectionFees Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10874projectworlds Online Art Gallery Shop Project adminHome.php sql injectionOnline Art Gallery Shop Project2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10875projectworlds Online Art Gallery Shop Project adminHome.ph sql injectionOnline Art Gallery Shop Project2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-26379koha Server-Side Request Forgery Vulnerabilitykoha6.5 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10694SourceCodester Online Food Ordering System index.php include file inclusionOnline Food Ordering System5.5 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-10704SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injectionPizzafy E-Commerce System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-26378koha Arbitrary Code Execution Vulnerabilitykoha5.4 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-42840ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literalsERPNext5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-43924FOSSBilling has an open redirect via administrator-configured redirect targetsFOSSBilling4.8 (v4.0)Medium344365
CVE-2026-10690wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgeryDesktopCommanderMCP2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-42849authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeoverauthentik9.3 (v3.1)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-49143BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handlerbrowserstack-runner8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5385GLPI 11.0.0 - Stored XSS in knowledge baseglpi8.4 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-5073WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL Injectionarmember7.5 (v3.1)High320011
CVE-2026-35718fd8136 firmware Path Traversal Vulnerabilityfd8136 firmware6.5 (v3.1)Medium344360 , 347009
CVE-2026-49120Medplum < 5.1.14 SSRF via FHIR Subscription Endpointmedplum6.3 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10620code-projects Student Admission System index.php sql injectionStudent Admission System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-41412alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Scriptalf.io4.9 (v3.1)Medium344360
CVE-2026-32250NamelessMC has Reflected Cross-Site Scripting (XSS) in id parameter of /index.php?route=/queries/user/Nameless4.3 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10301itsourcecode Fees Management System index.php cross site scriptingFees Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-10302itsourcecode Fees Management System manage_fee.php sql injectionFees Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10558SourceCodester Pizzafy Ecommerce System index.php file inclusionPizzafy Ecommerce System2.1 (v4.0)Low344360 , 347009
CVE-2026-10559SourceCodester Pizzafy Ecommerce System index.php file inclusionPizzafy Ecommerce System2.1 (v4.0)Low340007 , 344360 , 347009 , 390709
CVE-2026-10568itsourcecode Fees Management System manage_payment.php sql injectionFees Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10662ahujasid blender-mcp ZIP File server.py requests.get server-side request forgeryblender-mcp2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-105671Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scriptingCordysCRM2.0 (v4.0)Low333140 , 333141
CVE-2026-10583nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgeryGoClaw2.0 (v4.0)Low334168 , 390719
CVE-2026-105141Panel-dev CordysCRM RequestParamTrimConfig.java cross site scriptingCordysCRM1.9 (v4.0)Low333140
CVE-2026-10529westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scriptingCicadasCMS1.9 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 344370 , 346755 , 350147 , 350148
CVE-2026-44825Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentialssolr9.8 (v3.1)Critical330925
CVE-2018-25428Paroiciel 11.20 SQL Injection via tRecIdListe ParameterParoiciel8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25433Joomla JE Photo Gallery 1.1 SQL Injection via categoryidJE Photo Gallery8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25434WP AutoSuggest 0.24 SQL Injection via autosuggest.phpWP AutoSuggest8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-43624F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()F5-TTS8.8 (v4.0)High340007 , 344360 , 390709
CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypassactivemq8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnectoractivemq8.1 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2018-25429Paroiciel 11.20 SQL Injection via zProIdPro ParameterParoiciel7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25430Paroiciel 11.20 SQL Injection via eGeqIdEquipe ParameterParoiciel7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25431No-Cms 1.0 SQL Injection via order_by ParameterNo-CMS7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-42253Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Propertiesactivemq6.1 (v3.1)Medium333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266
CVE-2026-10214zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injectionchatgpt-on-wechat5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-10249itsourcecode Online Blood Bank Management System viewrequest.php sql injectionOnline Blood Bank Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10250itsourcecode Online Blood Bank Management System campsdetails.php sql injectionOnline Blood Bank Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10251itsourcecode Online House Rental System ajax.php login sql injectionOnline House Rental System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-10252itsourcecode Online House Rental System manage_tenant.php sql injectionOnline House Rental System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10253itsourcecode Online House Rental System manage_payment.php sql injectionOnline House Rental System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10260CodeAstro Online Job Portal delete-jobs.php sql injectionOnline Job Portal5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10261CodeAstro Online Job Portal application_status.php sql injectionOnline Job Portal5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10262code-projects Real State Services Login loginuser.php sql injectionReal State Services5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10263SourceCodester Computer Repair Shop Management System manage_product.php sql injectionComputer Repair Shop Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10280horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgerymcpilot5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10287SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgerySEO Meta Tag Extractor5.5 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-49138Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Followingnanobot5.3 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-48559Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tagslms5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-10202OFCMS JSON Query SystemDictController.java query sql injectionOFCMS2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10203OFCMS JSON Query SystemParamController.java query sql injectionOFCMS2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10204OFCMS JSON Query SysUserController.java query sql injectionOFCMS2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10209code-projects Online Hospital Management System Appointment appointmentdetail.php sql injectionOnline Hospital Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10213AstrBotDevs AstrBot API Endpoint delete path traversalAstrBot2.1 (v4.0)Low340007 , 344360
CVE-2026-10239JeecgBoot edit WordUtil.addImage server-side request forgeryJeecgBoot2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-10240JeecgBoot test server-side request forgerythe file /airag/airagModel/test2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-10241jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNetThe server processes these URLs2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10256itsourcecode Content Management System save_comment.php sql injectionContent Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10258itsourcecode Content Management System add_sub_topic.php sql injectionContent Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10265itsourcecode Content Management System edit_topic.php sql injectionContent Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10274indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgeryaem-mcp-server2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10276hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgeryJenkins-server-mcp2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10278ishayoyo excel-mcp read_file/write_file index.ts path traversalexcel-mcp2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2026-10279hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injectionwezterm-mcp2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10286CodeAstro Payroll System home_employee.php sql injectionPayroll System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10289code-projects Hotel and Tourism Reservation System tour.php cross site scriptingHotel and Tourism Reservation System2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-10296itsourcecode Fees Management System ajax.php sql injectionFees Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-10297itsourcecode Fees Management System manage_course.php sql injectionFees Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10228raisulislamg4 student_management_system_by_php admission_form_check.php cross site scriptingstudent management system by php2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-10234Mettle sendportal Campaign webview cross site scriptingsendportal2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10244SourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scriptingPharmacy Sales and Inventory System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10245SourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scriptingPharmacy Sales and Inventory System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10246SourceCodester Pharmacy Sales and Inventory System main create_medicine_presentation cross site scriptingPharmacy Sales and Inventory System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10247SourceCodester Pharmacy Sales and Inventory System main create_generic_name cross site scriptingPharmacy Sales and Inventory System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-49489OpenCATS - SQL Injection in DataGrid sortDirection ParameterOpenCATS8.4 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10178code-projects Online Music Site AdminEditAlbum.php sql injectionOnline Music Site5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10186code-projects Online Hospital Management System patient.php sql injectionOnline Hospital Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10170code-projects Visitor Management System phone_0.php sql injectionVisitor Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10172Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadMulti-Store Inventory Management System2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10173Orthanc Explorer 2 URL StudyList.vue cross site scriptingExplorer 22.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10193OFCMS ComnController ComnController.java query sql injectionOFCMS2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10155Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injectionMulti-Store Inventory Management System2.0 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10171code-projects Online Music Site AdminUpdateAlbum.php sql injectionOnline Music Site2.0 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25412Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.phpdeltasql9.3 (v4.0)Critical351000
CVE-2018-25411MGB OpenSource Guestbook 0.7.0.2 SQL Injection via email.phpMGB OpenSource Guestbook8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25413AiOPMSD Final 1.0.0 SQL Injection via search.phpAiOPMSD Final8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25414AiOPMSD Final 1.0.0 SQL Injection via actor.phpAiOPMSD Final8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25416AiOPMSD Final 1.0.0 SQL Injection via country.phpAiOPMSD Final8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25417AiOPMSD Final 1.0.0 SQL Injection via quality.phpAiOPMSD Final8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25418AiOPMSD Final 1.0.0 SQL Injection via year.phpAiOPMSD Final8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25419AiOPMSD Final 1.0.0 SQL Injection via genre.phpAiOPMSD Final8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25420AiOPMSD Final 1.0.0 SQL Injection via watch.phpAiOPMSD Final8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25422MOGG web simulator Script All Version SQL Injection via play.phpMOGG web simulator Script8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25424Gate Pass Management System 2.1 SQL Injection via login-exec.phpGate Pass Management System8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25425Yot CMS 3.3.1 SQL Injection via aid and cid ParametersYot CMS8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25409SIM-PKH 2.4.1 Arbitrary File Upload via aksi_pengurus.phpSIM-PKH8.7 (v4.0)High351000
CVE-2018-25410SIM-PKH 2.4.1 SQL Injection via media.php id ParameterSIM-PKH7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25421Open STA Manager 2.3 Arbitrary File Download via Path TraversalOpen STA Manager7.1 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-10153westboy CicadasCMS AbstractCacheManager.java search cross site scriptingCicadasCMS2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10112sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scriptingSTUDENT-MANAGEMENT-SYSTEM1.9 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-45629Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpointdokploy9.9 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-45632Dokploy: Schedule Authorization Bypass Enables Host/Server Command Executiondokploy9.9 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-45668Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)Trilium9.3 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-10042manga-image-translator RCE via Unsafe Pickle Deserialization in Share Modelmanga-image-translator9.2 (v4.0)Critical340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-45630Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statementdokploy9.0 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2018-25385E-Registrasi Pencak Silat 18.10 SQL Injection via id_partaiRegistrasi Pencak Silat8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25386HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.phpHaPe PKH8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25394Kados R10 GreenBee SQL Injection via update_release.phpKados R10 GreenBee8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25395Kados R10 GreenBee SQL Injection via update_feature.phpKados R10 GreenBee8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-45578WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URLavideo8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-45662Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)dokploy8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10108xiaomusic 0.5.7 Path Traversal via GET /music endpointxiaomusic8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-48527HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpointhaxcms-nodejs8.7 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-44238FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reportsfreepbx8.5 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-46372SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrlSillyTavern8.5 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-44285FastGPT: SSRF Protection Bypass via externalFile in Dataset Preview APIFastGPT7.7 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-47179Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcanearcane7.7 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-44239FreePBX: Authenticated Local File Inclusion in Dashboard Modulefreepbx7.6 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2018-25392MaxOn ERP Software 8.x-9.x SQL Injection via nomor ParameterMaxOn ERP7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25393Navigate CMS 2.8.5 Path Traversal via navigate_download.phpNavigate CMS7.1 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-10107MoviePilot v2 SSRF via /api/v1/system/img/{proxy} EndpointMoviePilot7.0 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-44651SillyTavern: Reflected XSS vulnerability in the CORS proxy middlewareSillyTavern6.9 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-44652SillyTavern: SSRF vulnerability in the CORS proxy middlewareSillyTavern6.9 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-45731WWBN AVideo: Authenticated Arbitrary File Read in view/update.phpavideo6.9 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-46337WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.phpavideo6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-39229Bolt CMS through 3.7.0 SQL Injection Vulnerability-6.5 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-44287FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassableFastGPT6.3 (v3.1)Medium340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-45626Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameterarcane6.3 (v3.1)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-36324SourceCodester Doctor Appointment System 1.0 Cross-Site Scripting Vulnerability-6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-45580WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attributeavideo5.4 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-45551Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Writegroupoffice5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-10052Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config validation endpointsRed Hat Quay 34.1 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-44881Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Updateportainer8.5 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-45344LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instancesLinkAce8.1 (v3.1)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-44657MantisBT: Stored XSS in File Downloadmantisbt7.5 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-8054dotCMS Core Publish Audit API - Unauthenticated SQL Injectiondotcms10.0 (v4.0)Critical340145 , 340156 , 344366
CVE-2026-44886Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL InjectionPi.Alert8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-3001Gutenverse Plugin <= 3.4.6 - Cross-Site Scriptinggutenverse6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 , 390585
CVE-2026-9606itsourcecode Courier Management System manage_user.php sql injectionCourier Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9607itsourcecode Courier Management System parcel_list.php sql injectionCourier Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9608QianFox FoxCMS Administrator Backend edit cross site scriptingFoxCMS1.9 (v4.0)Low340095 , 346755
CVE-2026-44450Lumiverse: RCE via MCP stdio argument injectionLumiverse9.9 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-48687fastnetmon Command Injection Vulnerabilityfastnetmon9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-43982Algernon: Path traversal file write via savein()algernon8.7 (v4.0)High340007 , 344360 , 390709
CVE-2026-44667Faction: Stored XSS in Remediation Verification Attachment Filename Preview Renderingfaction8.7 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-44669Faction: Stored XSS in Assessment Attachment Filename Preview Renderingfaction8.7 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-44729Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)twenty8.7 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-42425OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQueryOpenKM Community Edition8.6 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM Community Edition8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-45298Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)dozzle8.6 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-44706Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Valueschatwoot8.5 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48126Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent diralgernon8.2 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-48695fastnetmon Command Injection Vulnerabilityfastnetmon8.1 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-45082Karakeep has a SSRF Protection Bypass via Redirect Handlingkarakeep7.6 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-41917OpenKM 6.3.12 Local File Inclusion via Admin ScriptingOpenKM Community Edition6.9 (v4.0)Medium344360 , 347009
CVE-2026-48710Starlette - Improper Validation of Unsafe Equivalence in Inputstarlette6.5 (v3.1)Medium320009
CVE-2026-42335MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing DiscrepancyMaxKB6.3 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-9525itsourcecode Electronic Judging System edit_judge.php sql injectionElectronic Judging System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9526itsourcecode Electronic Judging System edit_team.php sql injectionElectronic Judging System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9528itsourcecode Electronic Judging System delete_judge.php sql injectionElectronic Judging System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9573itsourcecode Student Transcript Processing System index.php sql injectionStudent Transcript Processing System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9574itsourcecode Student Transcript Processing System trans.php sql injectionStudent Transcript Processing System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9575itsourcecode Student Transcript Processing System index.php sql injectionStudent Transcript Processing System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9584code-projects Project Management System Login chk.php sql injectionProject Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9524xianrendzw EasyReport REST Endpoint execute sql injectionEasyReport5.3 (v4.0)Medium340017 , 340145 , 341145 , 341245 , 380026 , 380122 , 390572
CVE-2026-42336MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL FetchMaxKB5.1 (v4.0)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-36239PbootCMS v.3.2.11 Cross-site Scripting VulnerabilityPbootCMS v.3.2.114.3 (v3.1)Medium340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-43936e107: Server-Side Request Forgery (SSRF) in the remote file fetchere1074.3 (v3.1)Medium337109 , 337110 , 341737 , 341738 , 344360 , 398021 , 398022
CVE-2026-9515Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injectionCA750-PoE2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9518hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent cross site scriptingCodeIgniter-StudentManagementSystem2.1 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-9519stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site scriptingpingvin-share2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9520blitz-js blitz Sign-in LoginForm.tsx cross site scriptingblitz2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-9527itsourcecode Electronic Judging System judges.php cross site scriptingElectronic Judging System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9531Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injectionCA750-PoE2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9532Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injectionCA750-PoE2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9533Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injectionCA750-PoE2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9534Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injectionCA750-PoE2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9542CodeAstro Leave Management System add_staff.php sql injectionLeave Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9566teableio teable Sign-up LoginPage.tsx cross site scriptingteable2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9564SourceCodester/oretnom23 Hospitals Patient Records Management System view_patient cross site scriptingHospitals Patient Records Management System1.9 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9405Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9406Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9407Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9408Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injectionA8000RU8.9 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9432Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9433Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9434Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9435Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9436Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9454Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9455Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9456Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9457Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9458Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9475Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injectionA8000RU8.9 (v4.0)High340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-9476Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9477Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9478Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2018-25362Twitter-Clone 1 SQL Injection via follow.phpPHP-Twitter-Clone8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25364Twitter-Clone 1 SQL Injection via search.phpPHP-Twitter-Clone8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25371mooSocial Store Plugin 2.6 SQL Injection via product parametermooSocial Store Plugin8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25372MedDream PACS Server Premium 6.7.1.1 SQL Injection via emailPACS Server Premium8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2018-25374Softneta MedDream PACS Server Premium 6.7.1.1 Directory TraversalMedDream PACS Server Premium8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-9469yashpokharna2555 StudentManagementSystem success.php sql injectionStudentManagementSystem5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9470yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9474yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-9415code-projects Employee Management System eloginwel.php cross site scriptingEmployee Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9416code-projects Employee Management System myprofile.php cross site scriptingEmployee Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9417code-projects Employee Management System myprofileup.php cross site scriptingEmployee Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9418code-projects Employee Management System changepassemp.php cross site scriptingEmployee Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9419code-projects Employee Management System empproject.php cross site scriptingEmployee Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9424Edimax EW-7438RPn Content-Type formWlanMP os command injectionEW-7438RPn2.1 (v4.0)Low340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9448code-projects Employee Management System applyleave.php cross site scriptingEmployee Management System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9450code-projects Employee Management System psubmit.php sql injectionEmployee Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9451code-projects Employee Management System applyleaveprocess.php sql injectionEmployee Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9473c-rick jimeng-mcp api.ts generateVideo path traversaljimeng-mcp2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2026-9511Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injectionCA750-PoE2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9512Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injectionCA750-PoE2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9514Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injectionCA750-PoE2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9464YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgeryyudao-cloud2.0 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-9384Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9385Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-9386Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9387Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9388Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9404Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9355SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injectionHospitals Patient Records Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9356SourceCodester Hospitals Patient Records Management System manage_history.php sql injectionHospitals Patient Records Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9364projectworlds Online Art Gallery Shop adminHome.php sql injectionOnline Art Gallery Shop5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9372ItzCrazyKns Vane Model Provider API route.ts server-side request forgeryVane5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-9383itsourcecode Electronic Judging System login.php sql injectionElectronic Judging System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9347Edimax EW-7438RPn webs formWizSurvey os command injectionEW-7438RPn2.1 (v4.0)Low340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2018-25357Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpdolibarr erp/crm9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904
CVE-2018-25340Smartshop 1 SQL Injection via category.phpSmartshop8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25341Smartshop 1 SQL Injection via product.php id ParameterSmartshop8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25342Smartshop 1 SQL Injection via search.phpSmartshop8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25348Joomla! Component Ek Rishta 2.10 SQL Injection via user_detailEk Rishta8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25351Joomla! Component EkRishta 2.10 SQL Injection via usernameEkRishta8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25346WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.phpForm Maker7.1 (v4.0)High340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2018-25352WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_idUltimate Form Builder Lite7.1 (v4.0)High340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2018-25349userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For HeaderuserSpice5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9302546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injectionvps-inventory-monitoring2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9342SourceCodester Hospitals Patient Records Management System view_history.php sql injectionHospitals Patient Records Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9343Edimax EW-7438RPn webs formWpsStart os command injectionEW-7438RPn2.1 (v4.0)Low340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-33712TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controlstypebot.io10.0 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-41075RT: SQL injection via entry_aggregator parameter in JSON searchrt8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-28445Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Previewtypebot.io8.7 (v3.1)High333140 , 340095 , 340147 , 341256 , 342259 , 346755
CVE-2026-41147NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request classnukeviet8.7 (v3.1)High333140
CVE-2026-39965TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blockstypebot.io7.7 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2025-45145Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability-7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-40598MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Pagemantisbt6.9 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-36227Easy Chat Server 3.1 Arbitrary Code Execution VulnerabilityEasy Chat Server 3.16.5 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-40295Devise: Open Redirect via Unvalidated request.referrer in Timeoutable Session Timeout Handlerdevise6.1 (v3.1)Medium344365
CVE-2026-39964TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browserstypebot.io5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-7798FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' ParameterFluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution5.4 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 340165 , 340464 , 340465 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-8203Concrete CMS 9.5.0 and below has Stored XSS on the height parameterconcrete cms7.3 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48231Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple ParametersTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48232Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset ParameterTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48233Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset ParameterTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48234Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir ParametersTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48236Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple ParametersTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48237Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id ParametersTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48238Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id ParameterTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48239Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id ParameterTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48240Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id ParametersTickets7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-8245Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injectionconcrete cms6.0 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-4093Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels)taxonomy term reference tree widget5.1 (v4.0)Medium333140 , 333141 , 340095
CVE-2026-48214Open ISES Tickets < 3.44.2 Reflected XSS via add_nm.php ticket_id ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48215Open ISES Tickets < 3.44.2 Reflected XSS via circle.php frm_id ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48218Open ISES Tickets < 3.44.2 Reflected XSS via icons/buttons/landb.php frm_name and frm_id ParametersTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48219Open ISES Tickets < 3.44.2 Reflected XSS via ics202.php frm_add_str ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48220Open ISES Tickets < 3.44.2 Reflected XSS via ics205.php frm_add_str ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48221Open ISES Tickets < 3.44.2 Reflected XSS via ics205a.php frm_add_str ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48222Open ISES Tickets < 3.44.2 Reflected XSS via ics213.php frm_add_str ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48223Open ISES Tickets < 3.44.2 Reflected XSS via ics213rr.php frm_add_str ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48224Open ISES Tickets < 3.44.2 Reflected XSS via ics214.php frm_add_str ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48225Open ISES Tickets < 3.44.2 Reflected XSS via landb.php _type ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48226Open ISES Tickets < 3.44.2 Reflected XSS via os_watch.php ref and mode_orig ParametersTickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48227Open ISES Tickets < 3.44.2 Reflected XSS via patient.php id and ticket_id ParametersTickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48228Open ISES Tickets < 3.44.2 Reflected XSS via patient_w.php id and ticket_id ParametersTickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48229Open ISES Tickets < 3.44.2 Reflected XSS via routes_i.php ticket_id ParameterTickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-7890Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Blockconcrete cms2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-8139Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvNameconcrete cms2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-9082Drupal Core - Anonymous SQL Injection via PostgreSQL Entity Querydrupal9.8 (v3.1)Critical340156 , 341245
CVE-2026-23734XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slashxwiki-commons9.3 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-7467Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalationexpand-maker8.8 (v3.1)High377360
CVE-2026-39352Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversalfrappe8.7 (v4.0)High340007 , 340029 , 344360 , 344370 , 390709
CVE-2026-9133Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File ReadRabbitMQ AWS8.3 (v4.0)High344360
CVE-2026-7460mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescapedmailcow-dockerized7.4 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 346755 , 350147 , 350148
CVE-2026-35593Trilium Notes has Local File Inclusion via upload modified file API endpointTrilium6.8 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-39311Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG AttachmentsTrilium6.8 (v3.1)Medium333140 , 333141 , 340095 , 340099 , 341099 , 342259 , 344363
CVE-2026-26028CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSScryptpad6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-5776Email Encoder < 2.4.7 - Unauthenticated Stored XSSEmail Encoder6.1 (v3.1)Medium333140 , 333141 , 340147 , 340148
CVE-2026-39960MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Valuesmantisbt5.4 (v3.1)Medium333140 , 341256
CVE-2026-35007Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35008Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35009Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35010Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35011Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35012Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35014Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35015Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35016Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parametertickets5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-34234CtrlPanel: Unauthenticated RCE using installer scriptpanel10.0 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-30118scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability-9.8 (v3.1)Critical337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-37281the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerabilitythe /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.09.8 (v3.1)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-46725TYPO3 ceselector Extension - Insecure Deserializationceselector9.2 (v4.0)Critical360153
CVE-2026-31069BillaBear (all versions prior to Jan 2026) SQL Injection VulnerabilityBillaBear (all versions prior to Jan 2026)8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34463MantisBT has Stored HTML Injection/XSS via Clone Issue Formmantisbt8.6 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-33741EspoCRM: Stored XSS via SVG attachment loading same-origin JavaScriptespocrm6.8 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34216CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.phppanel6.6 (v3.1)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34246CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Outputpanel4.8 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755
CVE-2026-29962HSC MailInspector - Local File Inclusionmailinspector7.5 (v3.1)High344360 , 347009 , 390709
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanismfacturascripts7.2 (v3.1)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-42596Gotenberg < 8.31.0 - Server-Side Request Forgerygotenberg9.4 (v3.1)Critical344362 , 398004
CVE-2026-42281MagicMirror <= 2.35.0 - Server-Side Request Forgerymagicmirror9.2 (v4.0)Critical398001
CVE-2026-42578Netty: HTTP Header Injection via HttpProxyHandler Disabled Validationnetty2.9 (v4.0)Low390719
CVE-2026-44262Scramble Laravel - Remote Code Executionscramble9.4 (v3.1)Critical341245 , 380026 , 380122
CVE-2026-44343WGDashboard < 4.3.2 - Unauthenticated File Readwgdashboard9.3 (v4.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-2614MLflow <= 3.9.0 - Arbitrary File Readmlflow7.5 (v3.1)High398008
CVE-2026-6433FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code Executioncustom-css-js-php7.3 (v3.1)High340016 , 340017 , 360147 , 360148
CVE-2026-42188Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URLgeyser4.3 (v3.1)Medium337109 , 337110 , 398021 , 398022
CVE-2026-8264Tenda AC6 httpd WifiApScan formWifiApScan os command injectionac6 firmware2.1 (v4.0)Low340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8259Tenda AC6 httpd telnet os command injectionac6 firmware2.0 (v4.0)Low340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8265Tenda AC6 httpd getLogFile get_log_file os command injectionac6 firmware2.0 (v4.0)Low340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2021-47940WordPress Download From Files 1.48 Arbitrary File UploadDownload From Files9.3 (v4.0)Critical351000
CVE-2021-47928Opencart TMD Vendor System 3.x Blind SQL Injection via product routeExtension TMD Vendor System8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2021-47930Balbooa Joomla Forms Builder 2.0.6 SQL Injection UnauthenticatedBalbooa Joomla Forms Builder8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2021-47938ImpressCMS 1.4.2 Remote Code Execution via AutotasksImpressCMS8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2021-47939Evolution CMS 3.1.6 Authenticated Remote Code Execution via Module CreationEvolution CMS8.7 (v4.0)High340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File UploadTextPattern CMS8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2022-50944Aero CMS 0.0.1 PHP Code Injection via posts.phpAero CMS8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-6735XSS within PHP-FPM status endpointphp7.3 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50954WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusioncab-fare-calculator6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2022-50956WordPress Plugin amministrazione-aperta 3.7.3 Local File Readamministrazione-aperta6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2021-47931Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS AuthenticationExponent CMS5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-47947Projectsend r1295 Stored Cross-Site Scripting via files-edit.phpProjectsend5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2022-50943Moodle LMS 4.0 Cross-Site Scripting via course search.phpmoodle5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50948Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site ScriptingMotopress Hotel Booking Lite5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2022-50958WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.phpJetpack5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2022-50959WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.phpContact Form Builder5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2022-50960WordPress International Sms Contact Form 7 Integration 1.2 XSSInternational Sms For Contact Form5.1 (v4.0)Medium340087 , 340099 , 341099 , 341266
CVE-2022-50961WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSSIP2Location Country Blocker5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 346755
CVE-2022-50962uBidAuction 2.0.1 myOrders Reflected XSSuBidAuction5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50963uBidAuction 2.0.1 myAuctions active Reflected XSSuBidAuction5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50964uBidAuction 2.0.1 myAuctions loose Reflected XSSuBidAuction5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50965uBidAuction 2.0.1 posts manage Reflected XSSuBidAuction5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50966uBidAuction 2.0.1 news manage Reflected XSSuBidAuction5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50968uBidAuction 2.0.1 auctions manage Reflected XSSuBidAuction5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50969uBidAuction 2.0.1 mailingLog manage Reflected XSSuBidAuction5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50970WordPress Plugin AAWP 3.16 Reflected XSS via tab ParameterWordPress Plugin AAWP5.1 (v4.0)Medium340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-8227Wavlink NU516U1 adm.cgi wzdapMesh os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8228Wavlink NU516U1 wireless.cgi advance os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8229Wavlink NU516U1 wireless.cgi WifiBasic os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8230Wavlink NU516U1 login.cgi sys_login1 os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8231CodeAstro Online Catering Ordering System deleteorder.php sql injectionOnline Catering Ordering System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-44313LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Functionlinkwarden9.1 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-42455LinkWarden: Stored XSS via Client-Side Archive Upload (Unsanitized HTML served from same origin)linkwarden8.8 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-42605AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Uploadazuracast8.8 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-8188Wavlink NU516U1 adm.cgi change_wifi_password os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8189Wavlink NU516U1 adm.cgi wzdrepeater os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8190Wavlink NU516U1 adm.cgi wan os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8191Wavlink NU516U1 adm.cgi wifi_region os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-8192Wavlink NU516U1 adm.cgi wzdap os command injectionwl-nu516u1 firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-42454Termix: OS Command Injection in Docker Container Management EndpointsTermix9.9 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-42556Postiz stored XSS in public preview pagepostiz9.0 (v3.1)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-42345FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, aFastGPT7.7 (v3.1)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2023-42344OpenCMS - XML external entity (XXE)opencms7.3 (v3.1)High330791 , 340152 , 344372
CVE-2024-33288Prison Management System - SQL Injection Authentication Bypassprison management system7.3 (v3.1)High341245
CVE-2024-46507Yeti Platform < 2.1.12 - Server-Side Template Injection to RCEyeti7.3 (v3.1)High340130 , 360151
CVE-2026-42339New API: SSRF Filter Bypass via 0.0.0.0new api7.1 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-42344FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpointsFastGPT6.3 (v3.1)Medium337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-44284FastGPT: Stored MCP tool URL SSRF in FastGPT workflow executionFastGPT6.3 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2023-42343OpenCMS - Cross-Site Scriptingopencms6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2024-33724SOPlanning 1.52.00 Cross Site Scriptingsoplanning5.4 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-42350Kargo: Open Redirect in UI OIDC Login Flow via redirectTo Query Parameterkargo5.1 (v4.0)Medium344365
CVE-2026-44286FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address ValidationFastGPT2.3 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-38428kestra SQL Injection Vulnerabilitykestra9.8 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-38431erpnext Code Injection Vulnerabilityerpnext9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code executionsqlbot9.4 (v4.0)Critical340014 , 340016 , 340017 , 340023 , 340029 , 340157 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-40329SQL Injection vulnerability via sortBy in beanFeedMasaCMS9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-40330Masa CMS SQL injection via sortDirection parameter in beanFeedMasaCMS9.3 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-7412Eclipse BaSyx SSRF VulnerabilityEclipse BaSyx8.6 (v3.1)High344360 , 347009 , 390709
CVE-2026-40075OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServletopenmrs8.2 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-40280Gotenberg <= 8.30.1 - Server Side Request Forgerygotenberg7.8 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 344362 , 398021 , 398022
CVE-2026-39383Gotenberg unauthenticated blind SSRF via unfiltered webhook URLgotenberg6.9 (v4.0)Medium337109 , 337110 , 344360 , 390719 , 398021 , 398022
CVE-2026-38432erpnext Cross-Site Scripting Vulnerabilityerpnext6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-38947FluentCMS 1.2.3 Cross-Site Scripting Vulnerability-6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-42796Arelle < 2.39.10 - Remote Code Executionarelle9.2 (v4.0)Critical340162 , 340163
CVE-2026-4060Geo Mashup <= 1.13.18 - SQL InjectionGeo Mashup7.5 (v3.1)High341245 , 380026 , 380122
CVE-2026-6229Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL ParameterRoyal Addons for Elementor – Addons and Templates Kit for Elementor7.2 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-41940cPanel & WHM - Authentication Bypass via Session-File CRLF Injectioncpanel9.3 (v4.0)Critical377364
CVE-2026-27760OpenCATS - Command InjectionOpenCATS9.2 (v4.0)Critical344363 , 344370
CVE-2026-7202Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-7203Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-7204Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injectionA8000RU8.9 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-37750School Management System by mahmoudai1 Cross-Site Scripting VulnerabilitySchool Management System by mahmoudai16.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-41363OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameteropenclaw6.0 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-7205duartium papers-mcp-server main.py search_papers path traversalpapers-mcp-server5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-7206dubydu sqlite-mcp entry.py extract_to_json sql injectionsqlite-mcp5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-7212edvardlindelof notes-mcp notes_mcp.py path traversalnotes-mcp5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-7214eghuzefa engineer-your-data server.py file_inf path traversalengineer-your-data5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-7216donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversalprocessing-claude-mcp-bridge5.5 (v4.0)Medium344360 , 390709
CVE-2026-7217Deepractice PromptX Document File index.ts read_pdf absolute path traversalPromptX5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-7220jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injectionFastlyMCP5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-7221TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgeryCloudBase-MCP5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-7223BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgeryHyperChat5.5 (v4.0)Medium334168 , 390719
CVE-2026-7314eiceblue spire-doc-mcp-server base.py get_doc_path path traversalspire-doc-mcp-server5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-7315eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversalspire-pdf-mcp-server5.5 (v4.0)Medium340007 , 344360 , 390709
CVE-2026-7319elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversalexecution-system-mcp5.5 (v4.0)Medium340007 , 344360
CVE-2026-7196CodeAstro Online Classroom guestdetails sql injectionOnline Classroom2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-7222code-projects Coaching Management System Complaint Form complaint.php cross site scriptingCoaching Management System2.0 (v4.0)Low333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-7178ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgerynextchat5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-7194SourceCodester Pharmacy Sales and Inventory System ajax.php sql injectionPharmacy Sales and Inventory System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-40466Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypassactivemq8.8 (v3.1)High330925 , 340162 , 340163
CVE-2026-41473CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpointscyberpanel8.8 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-41472CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboardcyberpanel5.3 (v4.0)Medium333140 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-41179RClone RC - Command Injectionrclone9.2 (v4.0)Critical340014 , 344370
CVE-2026-40887Vendure Core - SQL Injectionvendure9.1 (v3.1)Critical340156 , 340157 , 341245 , 344361 , 344363 , 360147 , 360148
CVE-2026-41456Bludit CMS <= 3.20.0 - Cross-Site Scriptingbludit5.1 (v4.0)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2026-5718Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Executiondrag-and-drop-multiple-file-upload-contact-form-78.1 (v3.1)High382238
CVE-2026-3885WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_boShortcodes Ultimate – Content Elements6.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-40105XWiki - Cross-Site Scriptingxwiki-platform6.5 (v4.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-39808Fortinet FortiSandbox - Command Injectionfortisandbox9.8 (v3.1)Critical344363
CVE-2026-24893openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansionopenitcockpit8.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-35031Jellyfin: Potential RCE via subtitle upload path traversal + .strm chainjellyfin8.8 (v3.1)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates actionchamilo lms8.8 (v3.1)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata serchamilo lms8.6 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-35032Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tunerjellyfin8.6 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-33715Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer actionchamilo lms7.2 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-39387BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameterboidcms7.2 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-33714Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)chamilo lms7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34212Docmost page content has stored XSS via unsanitized attachment URLsdocmost5.4 (v3.1)Medium333140
CVE-2026-34161Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Executionchamilo lms5.1 (v4.0)Medium333140
CVE-2026-4810Google ADK-Python - Unauthenticated Builder Endpointadk-python9.3 (v4.0)Critical390726 , 392647
CVE-2026-33534EspoCRM <= 9.3.3 - Server-Side Request Forgeryespocrm4.3 (v3.1)Medium398003
CVE-2026-5814PHPGurukul Online Course Registration check_availability.php sql injectionOnline Course Registration5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5824code-projects Simple Laundry System userchecklogin.php sql injectionSimple Laundry System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5827code-projects Simple IT Discussion Forum question-function.php sql injectionSimple IT Discussion Forum5.5 (v4.0)Medium340147 , 340148 , 340156 , 341256 , 342259 , 346755
CVE-2026-5829code-projects Simple IT Discussion Forum content.php sql injectionSimple IT Discussion Forum5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2026-5832atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgeryapi-lab-mcp5.5 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5823itsourcecode Construction Management System borrowed_tool_report.php sql injectionConstruction Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5825code-projects Simple Laundry System delmemberinfo.php cross site scriptingSimple Laundry System2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-5826code-projects Simple IT Discussion Forum edit-category.php cross site scriptingSimple IT Discussion Forum2.1 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-5834code-projects Online Shoe Store admin_running.php cross site scriptingOnline Shoe Store1.9 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-5835code-projects Online Shoe Store admin_football.php cross site scriptingOnline Shoe Store1.9 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-5836code-projects Online Shoe Store admin_product.php cross site scriptingOnline Shoe Store1.9 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-31040stata-mcp Code Injection Vulnerabilitystata-mcp9.8 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-3296Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry MetadataEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder9.8 (v3.1)Critical300007 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009
CVE-2026-39394CI4MS has an .env CRLF Injection via Unvalidated host Parameter in Install Controllerci4ms9.8 (v3.1)Critical340007 , 344360 , 347009
CVE-2026-3396WCAPF WooCommerce Ajax Product Filter - SQL InjectionWCAPF – Ajax Product Filter for WooCommerce7.5 (v3.1)High340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122
CVE-2026-39844NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitizationnicegui7.5 (v3.1)High344360 , 390709
CVE-2026-5802idachev mcp-javadc HTTP os command injectionmcp-javadc5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5805code-projects Easy Blog Site contact_us.php sql injectionEasy Blog Site5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5813PHPGurukul Online Course Registration check_availability.php sql injectionOnline Course Registration5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-35403LORIS has potential cross-site scripting in survey_accounts moduleloris5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35455immich has Stored XSS via OCR Text in 360° Panorama Viewerimmich5.4 (v3.1)Medium333140 , 333141 , 340147 , 341256 , 346755
CVE-2026-5808openstatusHQ openstatus Onboarding Endpoint client.tsx cross site scriptingopenstatus5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-39390CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe settingci4ms4.8 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-39392CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitizationci4ms4.8 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-5803bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgeryopenai-realtime-ui2.1 (v4.0)Low337109 , 340162 , 347009 , 390722
CVE-2026-5806code-projects Easy Blog Site update.php cross site scriptingEasy Blog Site2.0 (v4.0)Low333140 , 333141 , 340095 , 342259
CVE-2026-5810SourceCodester Sales and Inventory System GET Parameter delete.php cross site scriptingSales and Inventory System2.0 (v4.0)Low333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-0740Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Uploadninja forms file uploads9.8 (v3.1)Critical382238
CVE-2026-23696Windmill < 1.603.3 - SQL Injectionwindmill9.4 (v4.0)Critical341245
CVE-2026-39342ChurchCRM has a SQL injection searchwhat parameter via QueryView.phpchurchcrm9.4 (v4.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34197Apache ActiveMQ - Remote Code Executionactivemq8.8 (v3.1)High330925 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-39363Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketvite8.2 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-39364Vite Dev Server - Directory Traversalvite8.2 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-39341SQL injection in ChurchCRM.0churchcrm8.1 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39344Reflected XSS the login page through the 'username' parameterchurchcrm8.1 (v3.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-39361OpenObserve has a SSRF Protection Bypass via IPv6 Bracket Notation in validate_enrichment_urlopenobserve7.7 (v3.1)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-39369WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLsavideo7.6 (v3.1)High340007 , 344360 , 390709
CVE-2026-39847Emmett has a path traversal in internal assets handleremmett7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-39343ChurchCRM has a SQL Injection in Event Type Editor (Admin)churchcrm7.2 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39370WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltravideo7.1 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-39838ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSSMediaWiki - ProofreadPage Extension6.9 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-39936Stored XSS in Score due to usage of non-reserved data attributesMediawiki - Score Extension6.9 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-5739PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injectionPowerJob6.9 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-39368WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal servicesavideo6.5 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34371LibreChat Affected by Arbitrary File Write via execute_code Artifact Filename Traversallibrechat6.3 (v3.1)Medium340007 , 344360 , 390709
CVE-2026-39365Vite has a Path Traversal in Optimized Deps .map Handlingvite6.3 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2026-5692Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injectionA7100RU5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5736PowerJob detailPlus Endpoint InstanceController.java sql injectionPowerJob5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5741suvarchal docker-mcp-server HTTP index.ts pull_image os command injectiondocker-mcp-server5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-39380Open Source Point of Sale has Stored XSS in Stock Location (Configuration)open source point of sale5.4 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-5719itsourcecode Construction Management System borrowedtool.php sql injectionConstruction Management System2.1 (v4.0)Low340145 , 340156 , 341145 , 380122 , 390572
CVE-2026-34976Dgraph <=v25.3.0 - Admin Mutation Missing Authorizationdgraph10.0 (v3.1)Critical398008
CVE-2026-35471Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshsgoshs9.8 (v3.0)Critical340007 , 344360 , 347009 , 390709
CVE-2026-35395WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameterwegia8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-35470OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modalsopenstamanager8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-35029LiteLLM - Arbitrary File Readlitellm8.7 (v4.0)High344360 , 390709
CVE-2026-35184EcclesiaCRM has a Critical SQL Injectionecclesiacrm8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34885WordPress Media Library Assistant <= 3.34 - SQL InjectionMedia LIbrary Assistant8.5 (v3.1)High377360
CVE-2026-35174Chyrp Lite has a Path Traversal to Remote Code Executionchyrp lite7.2 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-35404Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameteropenedx6.1 (v3.1)Medium344365
CVE-2026-5631assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injectiongpt-researcher5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5634projectworlds Car Rental Project Parameter book_car.php sql injectionCar Rental Project5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5672code-projects Simple IT Discussion Forum Parameter edit-category.php sql injectionSimple IT Discussion Forum5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5677Totolink A7100RU cstecgi.cgi CsteSystem os command injectionA7100RU5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5678Totolink A7100RU cstecgi.cgi setScheduleCfg os command injectionA7100RU5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5688Totolink A7100RU cstecgi.cgi setDdnsCfg os command injectionA7100RU5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5689Totolink A7100RU cstecgi.cgi setNtpCfg os command injectionA7100RU5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5690Totolink A7100RU cstecgi.cgi setRemoteCfg os command injectionA7100RU5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5691Totolink A7100RU cstecgi.cgi setFirewallType os command injectionA7100RU5.5 (v4.0)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-35208lichess.org has an Unsanitized Stream Title Injection on /streamerlila5.3 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-5606PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injectionOnline Shopping Portal Project5.3 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-22675OCS Inventory NG Server Stored XSS via User-Agentocs inventory server5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35396WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium340162 , 340163 , 340165 , 344365
CVE-2026-35398WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium340162 , 340163 , 340165 , 344365
CVE-2026-35472WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium340162 , 340163 , 340165 , 344365
CVE-2026-35473WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage']wegia5.1 (v4.0)Medium340162 , 340163 , 340165 , 344365
CVE-2026-35474WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect']wegia5.1 (v4.0)Medium344365
CVE-2026-35475WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect']wegia5.1 (v4.0)Medium340165 , 344365
CVE-2026-35411Directus is an Open Redirect in Admin 2FA Setup Pagedirectus4.3 (v3.1)Medium344365
CVE-2026-5607imprvhub mcp-browser-agent URL Parameter handlers.ts CallToolRequestSchema server-side request forgerymcp-browser-agent2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5620itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injectionConstruction Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5635PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5636PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5675itsourcecode Construction Management System Parameter borrowed_tool.php sql injectionConstruction Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5681itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injectionsanitize or validate this input2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5621ChrisChinchilla Vale-MCP HTTP index.ts os command injectionVale-MCP1.9 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2019-25687Pegasus CMS 1.0 Remote Code Execution via extra_fields.phppegasus cms9.3 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2019-25662ResourceSpace 8.6 SQL Injection via watched_searches.phpresourcespace8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25668News Website Script 2.0.5 SQL Injection via index.phpnews website script8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25669qdPM 9.1 SQL Injection via search_by_extrafields Parameterqdpm8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25675eDirectory All Versions SQL Injection Authentication Bypassedirectory8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25678C4G BLIS 3.4 SQL Injection via users_select.phpcomputing for good&#x27;s basic laboratory information system8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25680Advance Gift Shop Pro Script 2.0.3 SQL Injection via searchadvance gift shop pro script8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25684OpenDocMan 1.3.4 SQL Injection via where Parameteropendocman8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25694Kados R10 GreenBee SQL Injection via user2resetkados8.8 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25671VA MAX 8.3.4 Remote Code Execution via changeip.phpVA MAX8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2019-25673UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File UploadLaravel File Manager8.7 (v4.0)High351000
CVE-2019-25664SuiteCRM 7.10.7 SQL Injection via record Parametersuitecrm7.1 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5551itsourcecode Free Hotel Reservation System Parameter login.php sql injectionFree Hotel Reservation System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5554code-projects Concert Ticket Reservation System Parameter process_search.php sql injectionConcert Ticket Reservation System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5555code-projects Concert Ticket Reservation System Parameter login.php sql injectionConcert Ticket Reservation System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5564code-projects Simple Laundry System Parameter searchguest.php sql injectionSimple Laundry System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5565code-projects Simple Laundry System Parameter delmemberinfo.php sql injectionSimple Laundry System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5573Technostrobe HI-LED-WR120-G2 fs unrestricted uploadhi-led-wr120-g2 firmware5.5 (v4.0)Medium351000
CVE-2026-5575SourceCodester/jkev Record Management System Login index.php sql injectionRecord Management System5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5577Song-Li cross_browser details Endpoint uniquemachine_app.py sql injectioncross browser fingerprinting5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5538QingdaoU OnlineJudge judge_server_heartbeat Endpoint JudgeServer.service_url server-side request forgeryOnlineJudge5.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5547Tenda AC10 httpd formAddMacfilterRule os command injectionac10 firmware5.3 (v4.0)Medium340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5537halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injectionCourseSEL2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5543PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injectionUser Registration & Login and User Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5552PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5553itsourcecode Online Cellphone System Parameter available.php sql injectionOnline Cellphone System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5558PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injectionPHPGurukul Online Shopping Portal Project2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5560PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5578CodeAstro Online Classroom Parameter addassessment.php sql injectionOnline Classroom2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5579CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injectionOnline Classroom2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5580CodeAstro Online Classroom Parameter addvideos.php sql injectionOnline Classroom2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5583PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5576SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted uploadRecord Management System2.0 (v4.0)Low340156 , 341245 , 351000 , 390501
CVE-2026-35616FortiClient EMS - Authentication Bypassforticlient ems9.8 (v3.1)Critical392301
CVE-2016-20052Snews CMS 1.7 Unrestricted File Upload via snews_filessnews9.3 (v4.0)Critical351000
CVE-2025-15064Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM GadgetsUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin6.4 (v3.1)Medium346755
CVE-2026-0737Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lightbox' ShortcodeWP Shortcodes Plugin — Shortcodes Ultimate6.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-0738Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' ShortcodeWP Shortcodes Plugin — Shortcodes Ultimate6.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 346755
CVE-2018-25248MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.phpmybb downloads5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-31818Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklistbudibase9.9 (v3.1)Critical337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34612Kestra: Remote Code Execution via SQL Injectionkestra9.0 (v3.1)Critical340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-59710biztalk360 Arbitrary Code Execution Vulnerabilitybiztalk3608.8 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-27634Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filterpiwigo8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Componeragflow8.7 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-35214Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file writebudibase8.7 (v3.1)High340007 , 344360 , 390709
CVE-2025-59711biztalk360 Path Traversal Vulnerabilitybiztalk3608.3 (v3.1)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34936PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallbackpraisonai7.7 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-27834Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameterpiwigo7.2 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-27885Piwigo: SQL Injection in Activity.getListpiwigo7.2 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34607Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCEemlog7.2 (v3.1)High344360 , 347009
CVE-2026-22664prompts.chat SSRF via Fal.ai Media Status Pollingprompts.chat7.1 (v4.0)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2025-59709biztalk360 Path Traversal Vulnerabilitybiztalk3606.8 (v3.1)Medium340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34787Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameteremlog6.5 (v3.1)Medium344360 , 347009
CVE-2026-34788Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parametersemlog6.5 (v3.1)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34229Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypassemlog6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-22662prompts.chat Blind SSRF via media-generateprompts.chat5.3 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-26477dokuwiki Denial of Service Vulnerabilitydokuwiki4.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-5470mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent server-side request forGoogle-Research-MCP2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34838Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollectiongroup-office9.9 (v3.1)Critical340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-34745Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/publicfireshare9.1 (v3.1)Critical340007 , 344360 , 390709
CVE-2026-34524SillyTavern: Path traversal in /api/chats/export and /api/chats/delete allows arbitrary file read/delete within usersillytavern8.8 (v3.1)High340007 , 344360 , 390709
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileControllerwiki8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34792Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34793Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34794Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34795Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34796Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34797Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34577Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Checkpostiz8.6 (v3.1)High337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34931hoppscotch: Improper loopback redirect_uri validation in device-login flowhoppscotch8.5 (v4.0)High344365
CVE-2026-34932hoppscotch: Stored XSS via mock server responses on backend originhoppscotch8.5 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34576Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadatapostiz8.3 (v4.0)High337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34725dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configurationdbgate8.2 (v3.1)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34522SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directorysillytavern8.1 (v3.1)High340007 , 344360 , 390709
CVE-2026-34598YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"yeswiki7.1 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-30251zenshare suite Cross-Site Scripting Vulnerabilityzenshare suite6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-30252zencrm Cross-Site Scripting Vulnerabilityzencrm6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 , 360030
CVE-2026-34847hoppscotch: Open redirect via /enter?redirect=hoppscotch6.1 (v3.1)Medium344365
CVE-2026-5346huimeicloud hm_editor image-to-base64 Endpoint mcp-server.js client.get server-side request forgeryhm editor5.5 (v4.0)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5368projectworlds Car Rental Project Parameter login.php sql injectioncar rental project5.5 (v4.0)Medium340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34590Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validationpostiz5.4 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34848hoppscotch: Stored XSS in team member overflow tooltip via display namehoppscotch5.4 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34974phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege Escalationphpmyfaq5.4 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34523SillyTavern: Path traversal allows file existence oraclesillytavern5.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2026-34798Endian Firewall /cgi-bin/routing.cgi remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34799Endian Firewall /manage/dnsmasq/hosts/ remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34800Endian Firewall /cgi-bin/uplinkeditor.cgi NAME Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34801Endian Firewall /manage/dhcp/fixed_leases/ remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34802Endian Firewall /cgi-bin/salearn.cgi remark user ham spam Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34803Endian Firewall /manage/qos/classes/ name Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34804Endian Firewall /manage/qos/rules/ dscp Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34805Endian Firewall /cgi-bin/dnat.cgi remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34806Endian Firewall /cgi-bin/snat.cgi remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34807Endian Firewall /cgi-bin/incoming.cgi remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34808Endian Firewall /cgi-bin/outgoingfw.cgi remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34809Endian Firewall /cgi-bin/zonefw.cgi remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34810Endian Firewall /cgi-bin/vpnfw.cgi remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34811Endian Firewall /cgi-bin/xtaccess.cgi remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34812Endian Firewall /cgi-bin/proxypolicy.cgi mimetypes Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34813Endian Firewall /cgi-bin/proxyuser.cgi user Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34814Endian Firewall /cgi-bin/proxygroup.cgi group Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34815Endian Firewall /cgi-bin/smtpdomains.cgi DOMAIN Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34816Endian Firewall /manage/smtpscan/domainrouting/ domain Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34817Endian Firewall /cgi-bin/smtprouting.cgi ADDRESS BCC Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34818Endian Firewall /manage/dnsmasq/localdomains/ remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34819Endian Firewall /cgi-bin/openvpnclient.cgi REMARK Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34820Endian Firewall /manage/ipsec/ remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34821Endian Firewall /manage/vpnauthentication/user/ remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34822Endian Firewall /manage/ca/certificate/ new_cert_name Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34823Endian Firewall /manage/password/web/ remark Stored Cross-Site Scriptingfirewall community5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-5351Trendnet TEW-657BRM setup.cgi add_wps_client os command injectiontew-657brm firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5352Trendnet TEW-657BRM setup.cgi edit os command injectiontew-657brm firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5353Trendnet TEW-657BRM setup.cgi ping_test os command injectiontew-657brm firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5354Trendnet TEW-657BRM setup.cgi vpn_connect os command injectiontew-657brm firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5355Trendnet TEW-657BRM setup.cgi vpn_drop os command injectiontew-657brm firmware2.1 (v4.0)Low340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-29014MetInfo CMS <= 8.1 - Remote Code Executionmetinfo9.3 (v4.0)Critical340121 , 344363 , 360152 , 380026 , 390635 , 393655
CVE-2026-34156NocoBase - VM Sandbox Escape to Remote Code Executionnocobase9.9 (v3.1)Critical344370 , 345240 , 360151
CVE-2026-3300Everest Forms Pro <= 1.9.12 - Unauthenticated RCE via Calculation Formula InjectionEverest Forms Pro9.8 (v3.1)Critical300021
CVE-2026-34243wenxian: Command Injection in GitHub Actions Workflow via issue_comment.bodywenxian9.8 (v3.1)Critical340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-34449SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injectionsiyuan9.6 (v3.1)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 393655
CVE-2026-34361HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Thefthl7 fhir core9.3 (v3.1)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-34448SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop clsiyuan9.0 (v3.1)Critical333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34367InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.7 (v3.1)High337109 , 337110 , 340147 , 340162 , 340163 , 340165 , 344360 , 344370 , 347009 , 390722 , 398021 , 398022
CVE-2026-34605SiYuan Note - Cross-Site Scriptingsiyuan8.6 (v4.0)High300013
CVE-2026-34365InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.1 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34366InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Fieldinvoiceshelf8.1 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34163Server-Side Request Forgery via MCP Tools Endpoint in FastGPTfastgpt7.7 (v3.1)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-4267Query Monitor <= 3.20.3 - Reflected Cross-Site Scripting via Request URIQuery Monitor7.2 (v3.1)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266
CVE-2026-34740AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validationavideo6.5 (v3.1)Medium337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34206Captcha Protect: Reflected XSS in challenge page via unsanitized destination rendered with text/templatecaptcha protect6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34396AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panelavideo6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-34442FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScoutfreescout6.1 (v3.1)Medium340165 , 344365
CVE-2026-34739AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.phpavideo6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34360HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probinghl7 fhir core5.8 (v3.1)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-30520loan management system SQL Injection Vulnerabilityloan management system5.4 (v3.1)Medium340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-32113Discourse: Open redirect via sso_destination_url cookie in enterdiscourse5.1 (v4.0)Medium344365
CVE-2026-5206code-projects Simple Gym Management System Payment sql injectionSimple Gym Management System2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-31831Tautulli <= 2.16.1 - Path Traversaltautulli8.7 (v4.0)High346019
CVE-2026-0560LolLMS < 2.2.0 - Server-Side Request Forgerylollms7.5 (v3.1)High360151
CVE-2026-5027Langflow <= 1.8.4 - Path Traversal to RCE via File Uploadlangflow8.8 (v3.1)High300008
CVE-2026-23921Blind, read-only SQL injection in Zabbix API via sortfield parameterzabbix8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-33497Langflow < 1.7.0 - Path Traversallangflow8.7 (v4.0)High300006
CVE-2026-22739Spring Cloud Config Server - Path Traversalspring cloud config8.6 (v3.1)High346019
CVE-2026-23482Blinko < 1.8.4 - Path Traversalblinko8.2 (v4.0)High347009
CVE-2026-23483Blinko <= 1.8.3 - Path Traversal via /pluginsblinko6.9 (v4.0)Medium347009
CVE-2026-3335Canto <= 3.1.1 - Missing Authorization to Unauthenticated File UploadCanto5.3 (v3.1)Medium300007
CVE-2026-3584WordPress Kali Forms <= 2.4.9 - Remote Code Executionkali-forms9.8 (v3.1)Critical300223
CVE-2026-33236NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwritenltk8.1 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2026-23536Feast Feature Server <=0.58.0 - Arbitrary File Readfeast7.5 (v3.1)High344360 , 390709
CVE-2026-22557UniFi Network Application - Path TraversalUniFi Network Application10.0 (v3.1)Critical340007
CVE-2025-71260BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEfootprints8.7 (v4.0)High340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2025-71257BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypassfootprints itsm6.9 (v4.0)Medium340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-29066TinaCMS - Path Traversaltinacms6.2 (v3.1)Medium347009 , 390709
CVE-2026-31844Authenticated SQL Injection in Koha displayby parameter of suggestion.plkoha8.7 (v4.0)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-2413Ally – Web Accessibility & Usability <= 4.0.3 - SQL InjectionAlly – Web Accessibility & Usability7.5 (v3.1)High380026 , 380122
CVE-2026-30958OneUptime < 10.0.21 - Path Traversaloneuptime8.6 (v3.1)High347009
CVE-2026-31807SiYuan <= v3.5.9 - SVG Animate Element XSSsiyuan6.4 (v4.0)Medium300013
CVE-2026-31809SiYuan <= v3.5.9 - Cross Site Scriptingsiyuan6.4 (v4.0)Medium300013
CVE-2026-29059Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversalwindmill6.9 (v4.0)Medium347009
CVE-2026-29183SiYuan Note - Cross-Site Scriptingsiyuan6.1 (v3.1)Medium300013 , 340147 , 341266 , 347198
CVE-2025-69411ionCube Tester Plus <= 1.3 - Local File InclusionionCube tester plus7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2025-66024XWiki Blog Application home page vulnerable to Stored XSS via Post Titleblog application8.6 (v4.0)High333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-1492WordPress User Registration & Membership <= 5.1.2 - Unauthenticated Privilege EscalationUser Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder9.8 (v3.1)Critical300020
CVE-2026-27971Qwik - Unauthenticated RCE via server$ Deserializationqwik9.2 (v4.0)Critical391213
CVE-2026-3395MaxSite CMS <=109.1 - Remote Code Executionmaxsite cms5.5 (v4.0)Medium344364 , 344370
CVE-2026-28414Gradio - Absolute Path Traversalgradio7.5 (v3.1)High390716
CVE-2026-28409WeGIA <= 3.6.4 - Remote Code Executionwegia7.2 (v3.1)High344363 , 390700 , 393655
CVE-2026-1557WP Responsive Images <= 1.0 - Arbitrary File ReadWP Responsive Images7.5 (v3.1)High336461 , 344360 , 381206
CVE-2026-2416Geo Mashup <= 1.13.17 - SQL InjectionGeo Mashup7.5 (v3.1)High380122
CVE-2026-0926Prodigy Commerce <= 3.3.0 - Local File InclusionProdigy Commerce9.8 (v3.1)Critical344360
CVE-2026-1581wpForo Forum <= 2.4.14 - SQL InjectionwpForo Forum7.5 (v3.1)High341245 , 380122
CVE-2026-0561Shield Security <= 21.0.8 - Unauthenticated Reflected XSSshield-security6.1 (v3.1)Medium340147 , 340148 , 341266 , 346755
CVE-2025-70149membership management system SQL Injection Vulnerabilitymembership management system9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-70150membership management system Missing Authorization Vulnerabilitymembership management system9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-70152scholars tracking system SQL Injection Vulnerabilityscholars tracking system9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-27174MajorDoMo - Unauthenticated RCEmajordomo9.3 (v4.0)Critical344360 , 344370 , 347009 , 390904
CVE-2025-70151scholars tracking system Arbitrary Code Execution Vulnerabilityscholars tracking system8.8 (v3.1)High351000
CVE-2025-14340Payara Server - Cross-Site ScriptingPayara Server7.3 (v4.0)High341266 , 346755
CVE-2026-1296Frontend Post Submission Manager Lite <= 1.2.7 - Open RedirectFrontend Post Submission Manager Lite – Frontend Posting WordPress Plugin6.1 (v3.1)Medium377360
CVE-2026-27176MajorDoMo - Cross-Site Scriptingmajordomo5.1 (v4.0)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148 , 390501
CVE-2026-26217Crawl4AI < 0.8.0 - Local File Inclusioncrawl4ai9.2 (v4.0)Critical344360
CVE-2026-25895FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File Writefuxa9.5 (v4.0)Critical340007
CVE-2020-37123Pinger 1.0 - Remote Code ExecutionPinger9.3 (v4.0)Critical344363
CVE-2026-25512Group-Office < 26.0.5 - Remote Code Executiongroup office9.4 (v4.0)Critical344363
CVE-2026-0743WP Content Permission <= 1.2 - Cross-Site ScriptingWP Content Permission4.4 (v3.1)Medium346755 , 377360 , 390585
CVE-2026-25616Blesta <= 5.13.1 - Cross-Site Scriptingblesta6.1 (v3.1)Medium340112 , 346755 , 350148
CVE-2026-1207Django RasterField - SQL Injectiondjango5.4 (v3.1)Medium341245
CVE-2025-40552SolarWinds Web Help Desk - Authentication Bypassweb help desk9.8 (v3.1)Critical392301
CVE-2026-0702VidShop for WooCommerce <= 1.1.4 - SQL InjectionVidShop – Shoppable Videos for WooCommerce7.5 (v3.1)High341245
CVE-2026-24128XWiki Platform Distribution Flavor Main - Cross-Site Scriptingxwiki-platform-distribution-flavor-main6.5 (v4.0)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2026-0770Langflow < 1.3.0 - Remote Code Execution via validate_code() exec()langflow9.8 (v3.0)Critical344360 , 344370
CVE-2026-21618Cross-site scripting (XSS) in OAuth Device Authorization screenhexpm8.5 (v4.0)High333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2021-47795GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scriptinggeowebserver8.7 (v4.0)High340007 , 340147 , 340148 , 341266 , 342259 , 344365 , 350148 , 390716
CVE-2026-0594WordPress List Site Contributors < 1.1.8 - Reflected XSSList Site Contributors6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2026-22200osTicket - Arbitrary File Readosticket8.7 (v4.0)High340147 , 340148
CVE-2025-68493Apache Struts XWork - XML External Entity Injectionstruts8.1 (v3.1)High344370 , 344372
CVE-2025-66744Yonyou YonBIP - Path Traversal-7.5 (v3.1)High340007
CVE-2026-21875ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL Injectionclipbucket9.8 (v3.1)Critical341245 , 380122
CVE-2026-22244OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEopenmetadata8.5 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-13801Yoco Payments <= 3.8.8 - Path TraversalYoco Payments7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2025-13418Responsive Pricing Table <= 5.1.12 - Cross-Site ScriptingResponsive Pricing Table6.4 (v3.1)Medium346755 , 377360
CVE-2025-13652WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL InjectionCBX Bookmark & Favorite6.5 (v3.1)Medium340016 , 377360 , 380122
CVE-2025-14998Branda WordPress plugin - Privilege EscalationBranda – White Label & Branding, Free Login Page Customizer9.8 (v3.1)Critical377360
CVE-2025-15098YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgeryyudao-cloud2.1 (v4.0)Low337109 , 337110 , 344360 , 398021 , 398022
CVE-2019-25246BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File DisclosureN100 H.264 VGA IP Camera7.1 (v4.0)High330925 , 344360 , 347009 , 390709
CVE-2025-68613n8n - Remote Code Execution via Expression Injectionn8n8.8 (v3.1)High340130 , 344361 , 344363 , 344364 , 345240 , 380026
CVE-2025-14437WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log Filehummingbird-performance7.5 (v3.1)High390716
CVE-2025-14528D-Link DIR-803 - Authentication Bypassdir-803 firmware5.5 (v4.0)Medium390722
CVE-2025-13339Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadHippoo Mobile App for WooCommerce7.5 (v3.1)High336461 , 340007 , 344360 , 347009 , 390709
CVE-2025-66472XWiki DeleteApplication - Cross-Site Scriptingxwiki6.5 (v4.0)Medium346755
CVE-2025-66516Apache Tika - XML External Entity Injectiontika9.8 (v3.1)Critical391213
CVE-2025-55182React Server Components - Remote Code Executionreact10.0 (v3.1)Critical331702 , 344370 , 345240 , 380026 , 393655
CVE-2025-13486Advanced Custom Fields Extended < 0.9.2 - Remote Code ExecutionAdvanced Custom Fields: Extended9.8 (v3.1)Critical377360
CVE-2025-13875Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversaloci-helper2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2025-51683mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCEmjobtime9.8 (v3.1)Critical340155 , 341155 , 341245
CVE-2025-13810jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversalwebstack-guns5.5 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2025-13814moxi159753 Mogu Blog v2 uploadPicsByUrl LocalFileServiceImpl.uploadPictureByUrl server-side request forgerymogublog5.5 (v4.0)Medium337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2025-13809orionsec orion-ops SSH Connection MachineInfoController.java server-side request forgeryorion-ops2.1 (v4.0)Low337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2025-13811jsnjfz WebStack-Guns PageFactory.java sql injectionwebstack-guns2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-13815moxi159753 Mogu Blog v2 pictures unrestricted uploadmogublog2.1 (v4.0)Low351000
CVE-2025-13816moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversalmogublog2.1 (v4.0)Low340007 , 344360 , 390709
CVE-2025-13786taosir WTCMS index.php fetch code injectionwtcms5.5 (v4.0)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390768 , 393655
CVE-2025-13792Qualitor getResumo.php eval code injectionthe file /html/st/stdeslocamento/request/getResumo.php5.5 (v4.0)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-13789ZenTao model.php makeRequest server-side request forgeryzentao2.1 (v4.0)Low337109 , 337110 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2025-62593Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attackray9.4 (v4.0)Critical340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-58360GeoServer - XML External Entity Injectiongeoserver9.8 (v3.1)Critical391213
CVE-2024-14015Studiocart <= 2.9.0 - Cross-Site ScriptingWordPress eCommerce Plugin7.1 (v3.1)High341266
CVE-2025-13138WP Directory Kit <= 1.4.3 - Unauthenticated SQL InjectionWP Directory Kit7.5 (v3.1)High340016 , 380122
CVE-2025-11368LearnPress < 4.3.0 - Arbitrary Callback Execution to Information Exposurelearnpress5.3 (v3.1)Medium344365
CVE-2021-4463Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File DownloadBEMS API8.7 (v4.0)High344360 , 347009 , 390709
CVE-2023-7327Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File ReadOzeki SMS Gateway8.7 (v4.0)High390716
CVE-2025-11307WP Google Maps < 9.0.48 - Cross-Site Scriptingwp-google-maps8.8 (v3.1)High346755
CVE-2025-62780ChangeDetection.io <= v0.50.33 - Stored XSS via Watch APIchangedetection5.4 (v3.1)Medium346755 , 350148
CVE-2025-64328FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command Injectionfreepbx8.6 (v4.0)High344364
CVE-2025-11833Post SMTP <= 3.6.0 - Email Log Disclosurepost smtp mailer9.8 (v3.1)Critical377360
CVE-2025-10897WooCommerce Designer Pro <= 1.9.28 - Arbitrary File ReadWooCommerce Designer Pro8.6 (v3.1)High344360
CVE-2025-27222TRUfusion Enterprise <= 7.10.4.0 - Path Traversaltrufusion enterprise8.6 (v3.1)High340007 , 344360
CVE-2025-12055MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path TraversalMIP 27.5 (v3.1)High344365
CVE-2025-53533Pi-hole Reflected XSS in 404-Error Pageweb interface5.1 (v4.0)Medium346755 , 347198
CVE-2025-62613VDO.Ninja - DOM-Based Cross-Site Scriptingvdo.ninja6.9 (v4.0)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2023-7305SmartBI RMIServlet Unrestricted File Upload RCESmartBI9.2 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-59287Windows Server Update Service - Insecure DeserializationWindows Server update service9.8 (v3.1)Critical392647
CVE-2025-61884Oracle E-Business Suite - Server-Side Request Forgeryconfigurator7.5 (v3.1)High337109 , 337110 , 340162 , 340163 , 340165 , 341256 , 342259 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2025-11371Gladinet CentreStack & TrioFox - Local File Inclusioncentrestack7.5 (v3.1)High340007 , 344360 , 344365 , 347019
CVE-2025-10162WordPress OrderConvo < 14 - Path TraversalAdmin and Customer Messages After Order for WooCommerce: OrderConvo7.5 (v3.1)High336461 , 344360
CVE-2025-52472XWiki - HQL Injectionxwiki9.3 (v4.0)Critical340087 , 340095 , 340156 , 340157 , 340159 , 360147 , 360148
CVE-2025-61224DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site Scriptingdokuwiki6.5 (v3.1)Medium333141 , 344370
CVE-2025-61882Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Executionconcurrent processing9.8 (v3.1)Critical391213
CVE-2025-61666Traccar(Windows) 6.1- 6.8.1 - Local File Inclusiontraccar8.7 (v4.0)High344365 , 347019
CVE-2025-9985Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log FileFeatured Image from URL (FIFU)5.3 (v3.1)Medium390716
CVE-2025-56819Datart v1.0.0-rc.3 - Remote Code Executiondatart9.8 (v3.1)Critical337209 , 337211 , 340095
CVE-2025-59528Flowise - Remote Code Executionflowise10.0 (v3.1)Critical345240 , 380026
CVE-2025-48703CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Executionwebpanel9.0 (v3.1)Critical330791 , 340152
CVE-2025-55911ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)clipbucket6.5 (v3.1)Medium340162 , 344370 , 398001
CVE-2025-10493Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via CookieChained Quiz5.3 (v3.1)Medium390726 , 392647
CVE-2025-59341esm.sh <= v136 - Local File Inclusionesm.sh7.7 (v4.0)High347009
CVE-2025-59342esm.sh <= v136 - Arbitrary File Write via Path Traversalesm.sh5.5 (v4.0)Medium340162 , 340163
CVE-2025-10592itsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injectiononline public access catalog2.1 (v4.0)Low340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-57631tduck Arbitrary Code Execution Vulnerabilitytduck9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-54123Hoverfly <= 1.11.3 - Remote Code Executionhoverfly9.8 (v3.1)Critical344360
CVE-2025-59049Mockoon < 9.2.0 - Path Traversalmockoon7.5 (v3.1)High347009
CVE-2025-10210ChanCMS <= 3.3.0 - SQL Injectionchancms2.1 (v4.0)Low340157 , 340159 , 341245 , 360147 , 360148
CVE-2025-54249Adobe Experience Manager ≤ 6.5.23.0 – SSRFexperience manager6.5 (v3.1)Medium390726 , 392647
CVE-2025-10090Jinher OA - SQL Injectionjinher oa5.5 (v4.0)Medium344366 , 361149
CVE-2025-55748XWiki Platform - Path Traversalxwiki9.3 (v4.0)Critical340007
CVE-2025-9744Loan Management System 1.0 - SQL Injectiononline loan management system5.5 (v4.0)Medium340156 , 341145
CVE-2025-57819FreePBX - Remote Code Executionfreepbx10.0 (v4.0)Critical340157 , 341245 , 344365 , 344370 , 360147 , 360148
CVE-2025-34163Dongsheng Logistics Software Unauthenticated Arbitrary File UploadDongsheng Logistics Software10.0 (v4.0)Critical351000
CVE-2025-55526n8n workflow collection Path Traversal Vulnerabilityn8n workflow collection9.1 (v3.1)Critical344360 , 347009 , 390709
CVE-2025-55523Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Downloadagent-zero3.5 (v3.1)Low344360 , 347009 , 390709
CVE-2025-54726WordPress JS Archive List <= 6.1.5 - SQL InjectionJS Archive List9.3 (v3.1)Critical341245 , 380026 , 380122
CVE-2025-54988Apache Tika - XXE Injectiontika8.4 (v3.1)High391213
CVE-2025-48157WordPress Formality Plugin <= 1.5.9 - Local File InclusionFormality8.1 (v3.1)High344360 , 347009 , 382238 , 390709
CVE-2025-51990XWiki – Stored Cross-Site Scripting (XSS)xwiki4.8 (v3.1)Medium342259
CVE-2025-41242Spring Framework - Path TraversalSpring Framework5.9 (v3.1)Medium347009
CVE-2025-55169WeGIA - Directory Traversalwegia10.0 (v4.0)Critical340007 , 344360
CVE-2025-52970Fortinet FortiWeb - Authentication Bypass to Admin Privilegefortiweb8.1 (v3.1)High340157 , 360147 , 360148
CVE-2025-25231Omnissa Workspace ONE UEM - Path Traversalworkspace one uem console7.5 (v3.1)High340007
CVE-2025-4576Liferay Portal & DXP - Cross-Site Scriptingdigital experience platform6.9 (v4.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-34152Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via time ParameterM300 Wi-Fi Repeater9.4 (v4.0)Critical344364 , 393655
CVE-2025-32430XWiki Platform - Cross-Site Scriptingxwiki-platform6.5 (v4.0)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2025-2611ICTBroadcast - Command InjectionICTBroadcast9.3 (v4.0)Critical344361 , 393655
CVE-2025-6204DELMIA Apriso - Command Injectiondelmia apriso8.0 (v3.1)High340095 , 341245 , 344361 , 344365 , 344366 , 347019 , 390724
CVE-2025-54782NestJS DevTools Integration - Remote Code Executiondevtools-integration9.4 (v4.0)Critical345240
CVE-2025-51501Microweber CMS2.0 - Cross-Site Scriptingmicroweber6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-51502Microweber CMS 2.0 - Reflected XSS in Admin Page Creationmicroweber6.1 (v3.1)Medium333140 , 341266
CVE-2025-54589Copyparty <=1.18.6 - Cross-Site Scriptingcopyparty6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-44136MapTiler Tileserver-php v2.0 - Unauthenticated XSStileserver php9.8 (v3.1)Critical341256 , 342259 , 346755 , 350148
CVE-2025-44137MapTiler Tileserver-php v2.0 - Unauthenticated File Readtileserver php8.2 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2025-8266ChanCMS <= 3.1. - Remote Code Executionchancms2.1 (v4.0)Low345240 , 380026
CVE-2025-54597Heimdall Application Dashboard < 2.7.3 - Reflected XSSheimdall6.1 (v3.1)Medium333141 , 340099 , 340147 , 341099 , 342259 , 347198 , 350147 , 350148
CVE-2018-25114osCommerce 2.3.4.1 - Remote Code ExecutionOnline Merchant9.3 (v4.0)Critical340023 , 340095 , 344360 , 344370
CVE-2025-6174WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)Qwizcards | online quizzes and flashcards6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2025-34141ETQ Reliance - Reflected XSS via SQLConverterServletreliance5.1 (v4.0)Medium333141 , 340099 , 340147 , 341099 , 342259 , 347198
CVE-2025-53770Microsoft SharePoint Server - Remote Code Execution (ToolShell)sharepoint server9.8 (v3.1)Critical330906 , 350147
CVE-2025-53771Microsoft SharePoint Server - Authentication Bypass (ToolShell)sharepoint server6.5 (v3.1)Medium330906 , 350147
CVE-2015-10138Work The Flow File Upload <= 2.5.2 - Arbitrary File Uploadwork the flow file upload9.8 (v3.1)Critical351000
CVE-2016-15043WP Mobile Detector <= 3.5 - Unrestricted File Uploadwp mobile detector9.8 (v3.1)Critical340162 , 340163 , 391740
CVE-2025-25257Fortinet FortiWeb - SQL Injectionfortiweb9.8 (v3.1)Critical340156
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpOP5 Monitor8.7 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-53833LaRecipe < 2.8.1 Remote Code Execution via SSTIlarecipe10.0 (v3.1)Critical340087
CVE-2024-26291Avid NEXIS Agent - Arbitrary File Readnexis8.7 (v4.0)High344360 , 344365 , 347009 , 390709
CVE-2025-6058WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Uploadwpbookit9.8 (v3.1)Critical382238
CVE-2025-47812Wing FTP Server <= 7.4.3 - Remote Code Executionwftpserver10.0 (v3.1)Critical344362 , 344363 , 380026 , 390614
CVE-2025-34085WordPress Simple File List <=4.2.2 - Remote Code Execution-9.8Critical382238
CVE-2025-44177White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)protop8.2 (v3.1)High347009 , 390727 , 392648
CVE-2025-6970WordPress Events Manager <= 7.0.3 - SQL Injectionevents manager7.5 (v3.1)High380122
CVE-2025-7160Zoo Management System 1.0 - SQL Injectionzoo management system5.5 (v4.0)Medium340145 , 340156
CVE-2025-5961WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Uploadmigration, backup, staging7.2 (v3.1)High377360
CVE-2025-34073Maltrail <=0.54 Username Parameter - Remote Command ExecutionMaltrail10.0 (v4.0)Critical340014 , 344363 , 344370
CVE-2025-49029WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code ExecutionCustom Login And Signup Widget9.1 (v3.1)Critical377360
CVE-2025-49493Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)CloudTest5.8 (v3.1)Medium344372
CVE-2025-34045WeiPHP 5.0 - Path Traversalweiphp8.7 (v4.0)High340007 , 344360
CVE-2025-20281Cisco ISE - Remote Code Executionidentity services engine10.0 (v3.1)Critical392301
CVE-2024-51978Brother Printers – Authentication Bypass via Default Admin PasswordDCP-J928N-W/B9.8 (v3.1)Critical390709
CVE-2025-48954Discourse OAuth Social Login - Cross-site Scriptingdiscourse6.1 (v3.1)Medium333141 , 341256 , 342259 , 344362 , 346755 , 347198 , 350148 , 390712
CVE-2024-51977Brother MFC-L9570CDW - Information DisclosureHL-L8260CDN5.3 (v3.1)Medium390709
CVE-2025-34035EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 Root Remote Code Executionesr300 firmware10.0 (v4.0)Critical341245
CVE-2025-34037Linksys Routers E/WAG/WAP/WES/WET/WRT-SeriesE420010.0 (v4.0)Critical312658 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-34040Zhiyuan OA - arbitrary file upload leadingZhiyuan OA Web Application System10.0 (v4.0)Critical330791 , 340007 , 340152
CVE-2021-41691openSIS Student Information System 8.0 SQL Injectionopensis9.8 (v3.1)Critical340157 , 340159 , 341245 , 360147 , 360148
CVE-2025-34031Moodle Jmol Filter 6.1 - Local File Inclusionjmol8.7 (v4.0)High340165 , 344360 , 347009
CVE-2025-34032Moodle LMS Jmol Plugin <= 6.1 - Cross-Site Scriptingjmol5.1 (v4.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2025-6403Code-Projects School Fees Payment System 1.0 - SQL Injectionschool fees payment system5.5 (v4.0)Medium340157 , 360147 , 360148 , 380026 , 380122
CVE-2025-34030sar2html <=3.2.2 Plot Parameter - Remote Code Executionsar2html10.0 (v4.0)Critical340014 , 340193 , 344364 , 344366
CVE-2025-49132Pterodactyl Panel - Remote Code Executionpanel10.0 (v3.1)Critical340007
CVE-2025-25034SugarCRM - Unauthenticated Remote Code Execution via PHP Object InjectionSugarCRM9.3 (v4.0)Critical344370
CVE-2025-34023Karel IP Phone IP1211 Web Management Panel - Local File InclusionKarel IP Phone IP12118.5 (v4.0)High330925 , 340007 , 344360 , 347009 , 390709
CVE-2025-1562Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Controlfunnelkit automations9.8 (v3.1)Critical377360
CVE-2025-45985Blink Router - Command Injectionbl-wr9000 firmware9.8 (v3.1)Critical344363
CVE-2025-5301ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site ScriptingDocs (DocumentServer)6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-27817Apache Kafka Client - Arbitrary File Readkafka7.5 (v3.1)High344360
CVE-2025-48281MyStyle Custom Product Designer <= 3.21.1 - SQL InjectionMyStyle Custom Product Designer9.3 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2025-4652Broadstreet WordPress plugin - Reflected XSSbroadstreet6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 377360
CVE-2025-5569IdeaCMS <= 1.7 - SQL Injectionideacms5.3 (v4.0)Medium341245
CVE-2025-45854JEHC-BPM - Remote Code Executejehc-bpm10.0 (v3.1)Critical344363 , 390724
CVE-2025-44148MailEnable Mail Service < v10 - Cross-Site Scriptingmailenable9.8 (v3.1)Critical344363 , 346755
CVE-2025-49002DataEase - Remote Code Executiondataease8.2 (v4.0)High340195
CVE-2025-5086Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserializationdelmia apriso9.0 (v3.1)Critical331702 , 344380
CVE-2025-5287Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL InjectionLikes and Dislikes Plugin7.5 (v3.1)High380122
CVE-2025-5298Campcodes Online Hospital Management System 1.0 - SQL Injectiononline hospital management system6.9 (v4.0)Medium390726 , 392647
CVE-2025-48828vBulletin replaceAdTemplate - Remote Code Executionvbulletin8.1 (v3.1)High344370
CVE-2025-32814NetMRI Unauthenticated SQL Injection via skipjackUsernamenetmri9.8 (v3.1)Critical340016 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026
CVE-2025-32813Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_requestnetmri7.2 (v3.1)High393655
CVE-2025-32815NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentialsnetmri6.5 (v3.1)Medium344360 , 390709 , 390722
CVE-2025-4524WordPress Madara - Local File InclusionMadara – Responsive and modern WordPress theme for manga sites9.8 (v3.1)Critical340748 , 344360 , 390709
CVE-2025-4008MeteoBridge <= 6.1 - Remote Code Executionmeteobridge vm8.7 (v4.0)High393655
CVE-2025-46822Java-springboot-codebase 1.1 - Arbitrary File ReadJava-springboot-codebase7.7 (v4.0)High347009
CVE-2025-41228VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)vCenter Server4.3 (v3.1)Medium340003 , 340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148 , 390727 , 392301 , 392648
CVE-2025-47577TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Uploadti-woocommerce-wishlist10.0 (v3.1)Critical382238
CVE-2024-6159Push Notification for Post and BuddyPress <= 1.93 - SQL Injectionpush notification for post and buddypress9.8 (v3.1)Critical380122
CVE-2024-8673Z-Downloads < 1.11.7 - Cross-Site Scriptingz-downloads9.1 (v3.1)Critical377360
CVE-2024-9765EKC Tournament Manager WordPress plugin - Path Traversalekc tournament manager6.5 (v3.1)Medium344360 , 347009 , 377360
CVE-2024-12724WP DeskLite - Reflected XSSwp desklite6.1 (v3.1)Medium340148 , 341266 , 346755
CVE-2024-12732AffiliateImporterEb <= 1.0.6 - Reflected XSSaffiliateimportereb6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-12734Advance Post Prefix WordPress plugin - Reflected XSSadvance post prefix6.1 (v3.1)Medium341266 , 377360
CVE-2024-12873Custom Field Manager WordPress - Cross-Site Scriptingcustom field manager6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13619LifterLMS < 8.0.1 - Cross-Site Scriptinglifterlms6.1 (v3.1)Medium340148 , 341266 , 346755 , 377360
CVE-2024-13727MemberSpace WordPress - Cross-Site Scriptingmemberspace6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-1303Plugin Oficial – Getnet para WooCommerce <= 1.8.0 - Cross-Site Scriptingplugin oficial6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2023-6030LogDash Activity Log <= 1.1.3 - SQL Injectionlogdash activity log5.4 (v3.1)Medium340016 , 341245 , 380026 , 380122
CVE-2025-47445WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Downloadeventin9.8 (v3.1)Critical344360 , 347009 , 390709
CVE-2025-47783Label Studio < 1.18.0 - Reflected XSSlabel studio7.6 (v4.0)High340147 , 340148 , 342259 , 344370 , 346755
CVE-2025-0133PAN-OS - Reflected Cross-Site ScriptingPAN-OS2.7 (v4.0)Low340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147
CVE-2024-46506NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Executionnetalertx10.0 (v3.1)Critical392301 , 392648
CVE-2024-48766NetAlert X - Arbitary File Readnetalertx8.6 (v3.1)High340007 , 340029 , 344360
CVE-2025-4396Relevanssi <= 4.24.4 (Free) - Unauthenticated SQL InjectionRelevanssi Premium7.5 (v3.1)High341245 , 380026 , 380122
CVE-2025-4427Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code Executionendpoint manager mobile7.5 (v3.1)High337210 , 340087 , 340095 , 380026 , 393655
CVE-2025-47204Bootstrap Multiselect <= 1.1.2 - Cross-Site Scriptingbootstrap multiselect6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-41393Ricoh Web Image Monitor - Reflected XSSMultiple laser printers and MFPs which implement Web Image Monitor5.1 (v4.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2025-2776SysAid On-Prem <= 23.3.40 - XML External Entitysysaid9.8 (v3.1)Critical330791 , 340152 , 344372
CVE-2025-2777SysAid On-Prem <= 23.3.40 - XML External Entitysysaid9.8 (v3.1)Critical330791 , 340152 , 344372
CVE-2025-2775SysAid On-Prem <= 23.3.40 - XML External Entitysysaid7.5 (v3.1)High330791 , 340152 , 344372
CVE-2025-47423Personal Weather Station Dashboard 12 - Directory TraversalPersonal Weather Station Dashboard5.8 (v3.1)Medium340007
CVE-2025-2011Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL InjectionDepicter — Popup & Slider Builder7.5 (v3.1)High340016 , 340017 , 360147 , 360148
CVE-2025-4388Liferay Portal - Cross-Site Scriptingdigital experience platform6.9 (v4.0)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2024-13322Ads Pro Plugin <= 4.88 - Unauthenticated SQL Injectionads pro7.5 (v3.1)High380122
CVE-2025-46565Vite Dev Server - Information Exposurevite6.0 (v4.0)Medium390709
CVE-2025-32970XWiki WYSIWYG API - Open Redirectxwiki6.1 (v3.1)Medium340162 , 340163
CVE-2025-46349YesWiki Reflected XSS via File Uploadyeswiki6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-46549YesWiki <= 4.5.1 - Cross-Site Scriptingyeswiki6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2025-46550YesWiki < 4.5.4 - Cross-Site Scriptingyeswiki6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2025-4078Wangshen SecGate 3600 Path Traversal VulnerabilitySecGate 36005.3 (v4.0)Medium340007 , 344360 , 347009 , 390709
CVE-2025-32432CraftCMS - Remote Code Executioncraftcms10.0 (v3.1)Critical344365
CVE-2025-31324SAP NetWeaver Visual Composer Metadata Uploader - Deserializationnetweaver9.8 (v3.1)Critical330791 , 340152
CVE-2025-2558WordPress The Wound Theme <= 0.0.1 - Local File Inclusionthe wound8.6 (v3.1)High336461 , 340007 , 344360 , 347009 , 381206 , 390709
CVE-2025-32969XWiki REST API Query - SQL Injectionxwiki9.3 (v4.0)Critical340016 , 340017 , 340157 , 340159 , 360147 , 360148 , 380026 , 380122
CVE-2024-13569WordPress Front End Users - Reflected XSSfront end users7.1 (v3.1)High341266 , 377360
CVE-2025-28367mojoPortal <=2.9.0.1 - Directory Traversalmojoportal6.5 (v3.1)Medium340007 , 344360 , 390709
CVE-2025-32778Web-Check < 2.0.1 Screenshot API - OS Command Injectionweb-check9.3 (v4.0)Critical344363 , 393655
CVE-2025-2563User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalationuser registration &amp; membership8.1 (v3.1)High300020
CVE-2025-32614EventON Lite <= 2.4 - Authenticated Local File Inclusionflavor8.8 (v3.1)High344360 , 377360 , 390709
CVE-2025-2636InstaWP Connect < 0.1.0.86 - Local PHP File InclusionInstaWP Connect – 1-click WP Staging & Migration8.1 (v3.1)High340007
CVE-2025-3248Langflow AI - Unauthenticated Remote Code Executionlangflow9.8 (v3.1)Critical340095 , 344360 , 344370
CVE-2025-2075Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalationuncanny automator8.8 (v3.1)High377360
CVE-2025-322571 Click WordPress Migration <= 2.2 - Unauthenticated Information Disclsoure1-click-migration5.3 (v3.1)Medium390716
CVE-2025-31486Vite server.fs.deny Bypass - Local File Inclusionvite5.3 (v3.1)Medium347009 , 390709
CVE-2025-29085Vipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey Componentvipshop Saturn v.3.5.1 and before9.8 (v3.1)Critical340157 , 340159 , 341245 , 360147 , 360148
CVE-2025-31131Yeswiki < 4.5.2 - Unauthenticated Path Traversalyeswiki7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2025-31125Vite Development Server - Path Traversalvite7.5 (v3.1)High347009 , 390709 , 390716
CVE-2025-2294Kubio AI Page Builder <= 2.5.1 - Local File InclusionKubio AI Page Builder9.8 (v3.1)Critical344360 , 347009 , 390709
CVE-2025-29306FoxCMS v.1.2.5 - Remote Code Executionfoxcms9.8 (v3.1)Critical344360 , 344370 , 347009 , 393655
CVE-2025-30567WordPress WP01 - Path TraversalWP017.5 (v3.1)High390709
CVE-2025-29635D-Link DIR-823X set_prohibiting - Command Injectiondir-823x firmware7.2 (v3.1)High340014 , 344364 , 344366
CVE-2025-30208Vite - Arbitrary File Readvite7.5 (v3.1)High347009 , 390709
CVE-2025-2709Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scriptingufida erp-nc5.3 (v4.0)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-2710Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scriptingufida erp-nc5.3 (v4.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-2711Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scriptingufida erp-nc5.3 (v4.0)Medium333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-2712Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scriptingufida erp-nc5.3 (v4.0)Medium333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2025-2609MagnusBilling Login Logs - Cross-Site Scriptingmagnusbilling6.1 (v3.1)Medium333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2025-2610MagnusBilling Alarm Module - Cross-Site Scriptingmagnusbilling5.4 (v3.1)Medium333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2025-2505WordPress Age Gate <= 3.5.3 - Unauthenticated Local File InclusionAge Gate9.8 (v3.1)Critical340007
CVE-2024-9362Polyaxon - Unauthenticated Directory Traversalpolyaxon/polyaxon7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2025-2539File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Readfile away7.5 (v3.1)High340748 , 344360 , 347006 , 390709
CVE-2024-7631Openshift-console: openshift console: path traversalRed Hat OpenShift Container Platform 3.114.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2025-24799GLPI < 10.0.17 - Pre-Auth SQL Injectionglpi9.8 (v3.1)Critical340156 , 341245 , 380026 , 380122
CVE-2025-2473Company Visitor Management System 1.0 - SQL Injectioncompany visitor management system6.9 (v4.0)Medium340145 , 340156 , 341145
CVE-2025-2221WordPress WPCOM Member <= 1.7.6 - SQL Injectionwpcom member7.5 (v3.1)High340016 , 380122
CVE-2025-1661HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusionhusky - products filter professional for woocommerce9.8 (v3.1)Critical340748
CVE-2024-13853WordPress SEO Tools Plugin 4.0.7 - Cross-Site Scriptingseo-automatic-seo-tools6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-28906Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site ScriptingSkitter Slideshow5.9 (v3.1)Medium346755 , 377360
CVE-2025-24813Apache Tomcat Path Equivalence - Remote Code Executiontomcat9.8 (v3.1)Critical392301
CVE-2025-2127JoomlaUX JUX Real Estate 3.4.0 - Reflected XSSjux real estate5.3 (v4.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-27506NocoDB < 0.258.0 - Reflected XSS in Password Resetnocodb6.1 (v3.1)Medium341266 , 347198
CVE-2025-26319FlowiseAI Flowise <= 2.2.6 - Arbitrary File Uploadflowise9.8 (v3.1)Critical346019
CVE-2024-48248NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Readbackup &amp; replication director8.6 (v3.1)High344360 , 390726 , 392647
CVE-2024-8425WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Uploadwoocommerce ultimate gift card9.8 (v3.1)Critical382238
CVE-2024-9193WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Updatewhmcs9.8 (v3.1)Critical340087 , 340748 , 344370 , 347006 , 390720
CVE-2025-1743Pichome 2.1.0 - Arbitrary File ReadPichome6.9 (v4.0)Medium340162 , 340165 , 344360 , 347009
CVE-2024-10152Simple Certain Time to Show Content - Cross-Site Scriptingsimple certain time to show content7.1 (v3.1)High341266 , 346755 , 377360
CVE-2024-12878Lazy Blocks <= 3.8.2 - Cross-Site Scriptinglazy blocks7.1 (v3.1)High340148 , 341266 , 346755 , 377360
CVE-2024-13624WordPress WPMovieLibrary Plugin <= 2.1.4.8 - Cross-Site Scriptingwpmovielibrary7.1 (v3.1)High341266 , 377360
CVE-2024-12737WP BASE Booking - Reflected XSSwp base booking of appointments, services and events6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13628WP Pricing Table - Reflected XSSwp pricing table6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13630NewsTicker <= 1.0 - Reflected Cross-Site Scriptingnewsticker6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13634Post Sync Plugin <= 1.1 - Cross-Site Scriptingpost sync6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2025-24893XWiki Platform - Remote Code Executionxwiki9.8 (v3.1)Critical340023 , 347009
CVE-2024-55457MasterSAM Star Gate v11 - Local File Inclusion-6.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2025-1023ChurchCRM - SQL Injectionchurchcrm9.3 (v4.0)Critical340156 , 341145 , 341245 , 380026 , 380122
CVE-2024-13609WordPress 1 Click Migration Plugin < 2.3 - Information Exposure1 click migration5.9 (v3.1)Medium350590 , 390716
CVE-2025-1035KLog Server - Path TraversalKLog Server5.7 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2024-13726Themes Coder Ecommerce <= 1.3.4 - SQL Injectiontc-ecommerce8.6 (v3.1)High341245 , 380026 , 380122
CVE-2024-13625Tube Video Ads Lite - Reflected XSStube video ads lite7.1 (v3.1)High341266
CVE-2024-13627OWL Carousel Slider - Cross-Site Scriptingowl carousel slider4.7 (v3.1)Medium341266 , 346755 , 377360
CVE-2025-1302JSONPath Plus < 10.3.0 - Remote Code Executionjsonpath-plus8.9 (v4.0)High345240 , 346755 , 360151 , 380026
CVE-2025-25296Label Studio < 1.16.0 - Cross-Site Scriptinglabel studio6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344370 , 346755 , 347198
CVE-2024-10763WordPress Campress Theme <= 1.35 - Unauthenticated Local File Inclusioncampress9.8 (v3.1)Critical340077
CVE-2024-13543Zarinpal Paid Download - Reflected XSSzarinpal paid download6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13570WordPress Stray Random Quotes <= 1.9.9 - Cross-Site Scriptingstray random quotes6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13352Legull WordPress - Cross-Site Scriptinglegull7.1 (v3.1)High341266 , 346755
CVE-2024-13492Guten Free Options - Cross Site Scriptingguten free options6.1 (v3.1)Medium341266 , 377360
CVE-2024-53586WebFileSys 2.31.0 - Directory Path Traversal-5.3 (v3.1)Medium340007 , 390726 , 392647
CVE-2025-24963Vitest Browser Mode - Local File Readvitest7.5 (v3.1)High344360 , 347009 , 390709
CVE-2024-13330JustRows WordPress - Cross-Site Scriptingjustrows free7.1 (v3.1)High341266 , 346755 , 377360
CVE-2024-13114WP Projects Portfolio <= 3.0 - Cross-Site Scriptingwp projects portfolio with client testimonials6.1 (v3.1)Medium340148 , 341266 , 346755 , 377360
CVE-2024-13325Glossy WordPress - Reflected XSSglossy6.1 (v3.1)Medium341266 , 377360
CVE-2024-13326iBuildApp <= 0.2.0 - Reflected Cross-Site Scriptingibuildapp6.1 (v3.1)Medium341266 , 377360
CVE-2024-13327Musicbox WordPress - Reflected XSSmusicbox6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13328Giga Messenger WordPress - Cross-Site Scriptinggiga messenger6.1 (v3.1)Medium341266 , 346755
CVE-2024-13331WP Dream Carousel < 1.0.1b - Cross-Site Scriptingwp dream carousel6.1 (v3.1)Medium340148 , 341266 , 346755 , 377360
CVE-2023-52163Digiever DS-2105 Pro - Command Injectionds-2105 pro firmware8.8 (v3.1)High390709
CVE-2024-13097WP Finance Plugin <= 1.3.6 - Cross-Site Scriptingwp finance5.4 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13098WordPress Email Newsletter - Reflected XSSwordpress email newsletter5.4 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13099Widget4Call WordPress - Cross-Site Scriptingwidget4call5.4 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-53584OpenPanel 0.3.4 - OS Command Injectionopenpanel9.8 (v3.1)Critical340023 , 344360 , 344361 , 344363
CVE-2024-53537OpenPanel 0.3.4 - Directory Traversalopenpanel9.1 (v3.1)Critical340007
CVE-2024-52875Kerio Control v9.2.5 - CRLF Injectionkerio control8.8 (v3.1)High390716
CVE-2024-13112WP MediaTagger <= 4.1.1 - Cross-Site Scriptingwp mediatagger6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13219Privacy Policy Genius - Cross-Site Scriptingprivacy policy genius6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13220WordPress Google Map Professional - Cross-Site Scriptinggoogle map professional6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13221Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scriptingfantastic elasticsearch6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13222WordPress User Messages <= 1.2.4 - Reflected XSSuser messages6.1 (v3.1)Medium341266 , 346755 , 390585
CVE-2024-13224SlideDeck 1 Lite Content Slider - Cross-Site Scriptingslidedeck 1 lite content slider6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13225ECT Home Page Products - Reflected XSSect home page products6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-13226A5 Custom Login Page - Reflected XSSa5 custom login page6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-12638Bulk Me Now! Plugin <= 2.0 - Cross-Site Scriptingbulk me now!7.1 (v3.1)High341266 , 346755 , 377360
CVE-2024-12749WordPress Competition Form Plugin <= 2.0 - Cross-Site Scriptingcompetition form7.1 (v3.1)High341266 , 346755 , 377360
CVE-2025-23211Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCErecipes9.9 (v3.1)Critical330791 , 340152
CVE-2024-13055Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scriptingdyn business panel7.1 (v3.1)High341266 , 377360
CVE-2024-13094WP Triggers Lite - Cross-Site Scriptingwp triggers lite7.1 (v3.1)High341266 , 346755 , 377360
CVE-2025-22785Course Booking System <= 6.0.6 - SQL InjectionCourse Booking System9.3 (v3.1)Critical340016 , 380122
CVE-2024-12008W3 Total Cache < 2.8.2 - Log File Exposurew3 total cache7.5 (v3.1)High390716
CVE-2024-50857GestioIP - Reflected Cross-Site Scriptinggestioip4.8 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2024-50603Aviatrix Controller - Remote Code Executioncontroller9.8 (v3.1)Critical340029 , 344360 , 344363 , 344370 , 393655
CVE-2024-12585PropertyHive < 2.1.1 - Cross-Site Scriptingpropertyhive6.1 (v3.1)Medium341266 , 346755
CVE-2024-12849Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Readerror-log-viewer-wp7.5 (v3.1)High344360 , 390709
CVE-2024-55218IceWarp Server 10.2.1 - Cross-Site Scriptingmail server6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755
CVE-2025-22214Landray EIS SQL注入漏洞-4.3 (v3.1)Medium340155 , 341155 , 341245
CVE-2024-56064WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCEindeed-wp-superbackup10.0 (v3.1)Critical382238
CVE-2024-12987DrayTek Vigor - Command InjectionVigor300B6.9 (v4.0)Medium347009 , 393655
CVE-2024-11921Give WP Plugin < 3.19.0 - Cross-Site Scriptinggivewp4.8 (v3.1)Medium341266 , 346755
CVE-2024-38819Spring Framework Path Traversal in Functional Web Frameworksspring framework7.5 (v3.1)High347009 , 390709
CVE-2024-11740Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Executiondownload manager7.3 (v3.1)High344370
CVE-2023-34990FortiWLM - Directory Traversalfortiwlm9.8 (v3.1)Critical340007
CVE-2024-12025WordPress Collapsing Categories <= 3.0.8 - SQL InjectionCollapsing Categories7.5 (v3.1)High340016 , 341245 , 380026 , 380122
CVE-2024-55956Cleo Harmony < 5.8.0.24 - File Upload Vulnerabilityharmony9.8 (v3.1)Critical391213
CVE-2024-55890D-Tale <= 3.16.0 - Pre-Auth RCE via Pandas Query Injectiondtale6.9 (v4.0)Medium344370
CVE-2024-10708System Dashboard < 2.8.15 - Admin+ Path Traversalsystem dashboard4.9 (v3.1)Medium336461 , 344360 , 377360 , 381206
CVE-2024-55550Mitel MiCollab - Arbitary File Readcmg suite2.7 (v3.1)Low340007 , 341256 , 344360 , 350147 , 390709
CVE-2024-12209WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusionwp-umbrella9.8 (v3.1)Critical344360 , 347009 , 390709
CVE-2024-11728KiviCare Clinic & Patient Management System (EHR) <= 3.6.4 - SQL Injectionkivicare7.5 (v3.1)High340016 , 340017 , 340156 , 380122
CVE-2024-53900Mongoose < 8.8.3 - Remote Code Executionmongoose9.1 (v3.1)Critical340087 , 340095 , 345240
CVE-2023-7299DataGear resolveSql sql injectiondatagear5.3 (v4.0)Medium340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2024-11320Pandora v7.0NG.777.3 - Remote Code Executionpandora fms6.9 (v4.0)Medium344363
CVE-2024-11587idcCMS V1.60 - Cross-Site Scriptingidccms5.3 (v4.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2024-52762Ganglia Web Interface (v3.7.3 - v3.7.6) - Cross-Site Scriptingganglia-web5.4 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-52763Ganglia Web Interface (v3.7.3 - v3.7.5) - Cross-Site Scriptingganglia-web5.4 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 347198
CVE-2024-11303Korenix JetPort 5601v3 - Path TraversalJetPort 56018.7 (v4.0)High347009
CVE-2020-26073Cisco SD-WAN vManage Software - Local File Inclusioncatalyst sd-wan manager7.5 (v3.1)High347009
CVE-2024-9474PAN-OS Management Web Interface - Command Injectionpan-os6.9 (v4.0)Medium344363
CVE-2024-11305Altenergy Power Control Software - SQL Injectionenergy communication unit firmware5.3 (v4.0)Medium340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2024-9935PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Downloadpdf-generator-addon-for-elementor-page-builder7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2024-10571Chartify – WordPress Chart Plugin < 2.9.6 - Local File Inclusionchartify9.8 (v3.1)Critical340748 , 347006
CVE-2024-9186Automation By Autonami < 3.3.0 - SQL Injectionwp-marketing-automations8.6 (v3.1)High340016 , 340017 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2024-5082Nexus Repository 2 - Remote Code ExecutionNexus Repository7.1 (v4.0)High330791 , 340152
CVE-2024-10146Simple File List < 6.1.13 - Reflected Cross-Site Scriptingsimple file list5.4 (v3.1)Medium340087 , 341266 , 346755 , 377360
CVE-2024-51211openSIS Classic v9.1 - SQL Injectionopensis9.8 (v3.1)Critical341245 , 380122
CVE-2024-43425Moodle - Remote Code Executionmoodle8.1 (v3.1)High340095 , 360152
CVE-2024-10081CodeChecker <= 6.24.1 - Authentication Bypasscodechecker10.0 (v3.1)Critical392301
CVE-2024-10914D-Link NAS - Command Injection via Name Parameterdns-320 firmware9.2 (v4.0)Critical344363
CVE-2024-10915D-Link NAS - Command Injection via Group Parameterdns-320 firmware9.2 (v4.0)Critical344363
CVE-2024-10758NEWS-BUZZ News Management System 1.0 - SQL Injectionnews-buzz6.9 (v4.0)Medium341245 , 344363 , 345493 , 380026 , 380122
CVE-2024-51483Changedetection.io <= 0.47.4 - Path Traversalchangedetection6.9 (v4.0)Medium340130
CVE-2024-51482ZoneMinder v1.37.* <= 1.37.64 - SQL Injectionzoneminder9.9 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2024-48307JeecgBoot v3.7.1 - SQL Injectionjeecg boot9.8 (v3.1)Critical340157 , 340159 , 341245 , 360147 , 360148
CVE-2024-50334Scoold < 1.64.0 - Authentication Bypassscoold8.7 (v4.0)High391213
CVE-2024-50498WP Query Console <= 1.0 - Remote Code Executionwp query console9.8 (v3.1)Critical340095
CVE-2024-50623Cleo Harmony < 5.8.0.21 - Arbitary File Readharmony9.8 (v3.1)Critical344365
CVE-2024-6049Lawo AG vsm LTC Time Sync (vTimeSync) - Path Traversalvsm LTC Time Sync (vTimeSync)7.5 (v3.1)High390716
CVE-2024-8852All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosureall-in-one wp migration5.3 (v3.1)Medium390716
CVE-2024-8625WordPress TS Poll < 2.4.0 - SQL Injectionts poll7.2 (v3.1)High380122
CVE-2024-44000LiteSpeed Cache <= 6.4.1 - Sensitive Information Exposurelitespeed cache9.8 (v3.1)Critical390716
CVE-2024-9264Grafana Post-Auth DuckDB - SQL Injection To File Readgrafana9.4 (v4.0)Critical340016 , 344360 , 344370
CVE-2016-15042WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Uploadfrontend file manager9.8 (v3.1)Critical382238
CVE-2021-4449ZoomSounds Plugin - Unauthenticated Arbitrary File Uploadzoomsounds9.8 (v3.1)Critical392301
CVE-2012-10018WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Uploadmapplic8.3 (v3.1)High346755 , 377360
CVE-2020-36836WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletionwp fastest cache8.0 (v3.1)High340748 , 347006 , 377360
CVE-2019-25213WordPress Advanced Access Manager - Path Traversaladvanced access manager7.5 (v3.1)High336461 , 344360 , 381206
CVE-2016-15041MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scriptingmainwp dashboard6.1 (v3.1)Medium333141 , 340149 , 346755
CVE-2022-4971Sassy Social Share <= 3.3.3 - Cross-Site Scriptingsassy social share6.1 (v3.1)Medium340099 , 341099 , 341258 , 346755 , 347198
CVE-2024-35584openSIS < 9.1 - SQL Injectionopensis8.8 (v3.1)High340156 , 380122
CVE-2024-48259Cloudlog - SQL Injectioncloudlog7.3 (v3.1)High331028 , 340016 , 340157 , 341245 , 360147 , 360148 , 380026
CVE-2024-48120X2CRM 8.5 - Stored Cross-Site Scripting (XSS)x2crm5.4 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390726 , 392647
CVE-2024-9047WordPress File Upload <= 4.24.11 - Arbitrary File Readwordpress file upload9.8 (v3.1)Critical344360
CVE-2024-9234GutenKit <= 2.1.0 - Arbitrary File Uploadgutenkit9.8 (v3.1)Critical340162 , 340163
CVE-2024-9463PaloAlto Networks Expedition - Remote Code Executionexpedition9.9 (v4.0)Critical344363
CVE-2024-9465Palo Alto Expedition - SQL Injectionexpedition9.2 (v4.0)Critical340016 , 341245 , 380026 , 380122
CVE-2024-8911LatePoint <= 5.0.11 - SQL Injectionlatepoint9.8 (v3.1)Critical380122
CVE-2024-45293TablePress < 2.4.3 - XXE Injectiontablepress7.5 (v3.1)High377360
CVE-2024-47374LiteSpeed Cache <= 6.5.0.2 - Stored XSSlitespeed cache6.1 (v3.1)Medium377360
CVE-2024-9054Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injectiontimeprovider 4100 firmware8.5 (v4.0)High392301
CVE-2024-43687Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)timeprovider 4100 firmware7.7 (v4.0)High392301
CVE-2024-7801Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injectiontimeprovider 4100 firmware6.3 (v4.0)Medium392301
CVE-2024-8353GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injectiongivewp9.8 (v3.1)Critical340014 , 344370
CVE-2024-9166TitanNit Web Control 2.01/Atemio 7600 - Remote Code ExecutionAtemio AM 520 HD Full HD Satellite Receiver9.3 (v4.0)Critical340014 , 340193 , 390904
CVE-2024-6517Contact Form 7 Math Captcha <= 2.0.1 - Cross-site Scriptingds-cf7-math-captcha6.1 (v3.1)Medium346755
CVE-2024-8484REST API TO MiniProgram <= 4.7.1 - SQL Injectionrest api to miniprogram7.5 (v3.1)High380026 , 380122
CVE-2024-8877Riello Netman 204 - SQL Injectionnetman 204 firmware6.9 (v4.0)Medium340156 , 341245
CVE-2024-9007123Solar 1.8.4.5 - Cross-Site Scripting123solar5.3 (v4.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-46986Camaleon CMS < 2.8.1 Arbitrary File Write to RCEcamaleon cms9.9 (v3.1)Critical392647
CVE-2023-47105Chaosblade < 1.7.4 - Remote Code Executionchaosblade8.6 (v3.1)High393655
CVE-2024-43971Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scriptingsunshine photo cart6.1 (v3.1)Medium344361 , 344364 , 347198 , 377360
CVE-2024-8752WebIQ 2.15.9 - Directory Traversalwebiq9.3 (v4.0)Critical344365 , 347019 , 390716
CVE-2024-46938Sitecore Experience Platform <= 10.4 - Arbitrary File Readexperience commerce7.5 (v3.1)High340007 , 344360 , 344365 , 347019 , 390709
CVE-2024-38816WebMvc.fn/WebFlux.fn - Path TraversalSpring7.5 (v3.1)High347009
CVE-2024-6587LiteLLM - Server-Side Request Forgerylitellm7.5 (v3.1)High340162 , 340163
CVE-2024-8522LearnPress < 4.2.7.1 - SQL Injectionlearnpress7.5 (v3.1)High341245 , 380026 , 380122
CVE-2024-8529LearnPress < 4.2.7.1 - SQL Injectionlearnpress7.5 (v3.1)High341245 , 380026 , 380122
CVE-2024-6924TrueBooker <= 1.0.2 - SQL Injectiontruebooker9.8 (v3.1)Critical341245 , 380122
CVE-2024-6928Opti Marketing <= 2.0.9 - SQL Injectionopti marketing9.8 (v3.1)Critical380122
CVE-2024-45507Apache OFBiz - Remote Code Executionofbiz9.8 (v3.1)Critical340162 , 340163 , 344370
CVE-2024-6926Viral Signup <= 2.1 - SQL Injectionviral signup9.8 (v3.1)Critical380122
CVE-2024-20440Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentialssmart license utility7.5 (v3.1)High390716
CVE-2024-45622ASIS - SQL Injection Authentication Bypassasis9.8 (v3.1)Critical340145 , 340156 , 341145
CVE-2024-45388Hoverfly < 1.10.3 - Arbitrary File Readhoverfly7.5 (v3.1)High344360 , 390709
CVE-2024-7354Ninja Forms 3.8.6-3.8.10 - Cross-Site Scriptingninja forms6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-3673Web Directory Free < 1.7.3 - Local File Inclusionweb directory free9.1 (v3.1)Critical340748 , 344360 , 390709
CVE-2024-8252WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusionclean login8.8 (v3.1)High344360
CVE-2024-43144Cost Calculator Builder <= 3.2.15 - SQL Injectioncost calculator builder9.8 (v3.1)Critical380122
CVE-2024-43917WordPress TI WooCommerce Wishlist Plugin <= 2.8.2 - SQL Injectionti woocommerce wishlist9.8 (v3.1)Critical380026 , 380122
CVE-2024-43965SendGrid for WordPress <= 1.4 - SQL Injectionsendgrid9.8 (v3.1)Critical380122
CVE-2024-5057WordPress Easy Digital Downloads <= 3.2.12 - SQL Injectioneasy digital downloads9.8 (v3.1)Critical380122
CVE-2024-6670WhatsUp Gold HasErrors SQL Injection - Authentication Bypasswhatsup gold9.8 (v3.1)Critical340016 , 341245 , 344362
CVE-2024-6671WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypasswhatsup gold9.8 (v3.1)Critical340016 , 340159 , 344362 , 344366
CVE-2024-45241CentralSquare CryWolf - Path Traversalcrywolf7.5 (v3.1)High340007
CVE-2024-7313Shield Security Plugin < 20.0.6 - Cross-Site Scriptingshield security6.1 (v3.1)Medium341266 , 346755
CVE-2024-7954SPIP Porte Plume Plugin - Remote Code ExecutionSPIP9.8 (v3.1)Critical340023 , 340128 , 344370 , 380018 , 390801
CVE-2024-42852AcuToWeb server/10.5.0.7577c8b - Cross-Site Scriptingacutoweb6.1 (v3.1)Medium346755
CVE-2024-7854Woo Inquiry <= 0.1 - SQL Injectionwoo inquiry9.8 (v3.1)Critical380122
CVE-2024-5932GiveWP - PHP Object Injectiongivewp9.8 (v3.1)Critical398001
CVE-2024-7928FastAdmin < V1.3.4.20220530 - Path Traversalfastadmin5.3 (v4.0)Medium340007
CVE-2024-6460WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusiontradedoubler-affiliate-tracker9.8 (v3.1)Critical336461 , 340748 , 344360 , 347006 , 381206
CVE-2024-32231Stash < 0.26.0 - SQL Injectionstash6.3 (v3.1)Medium340016 , 340017 , 340157 , 340159 , 344361 , 344362 , 344363 , 344366 , 360147 , 360148
CVE-2024-38653Ivanti Avalanche SmartDeviceServer - XML External Entityavalanche7.5 (v3.1)High330791 , 340152
CVE-2024-7593Ivanti vTM - Authentication Bypassvirtual traffic manager9.8 (v3.1)Critical392301
CVE-2024-43360ZoneMinder - SQL Injectionzoneminder9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2024-30188Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Writedolphinscheduler8.1 (v3.1)High340162 , 340165 , 344360 , 347009 , 390726 , 392647
CVE-2022-38322Temenos Transact - Cross-Site Scripting-N/AN/A333141
CVE-2024-6893Journyx - XML External Entities Injection (XXE)journyx-jtime7.5 (v3.1)High344360 , 344370 , 344372
CVE-2024-6892Journyx 11.5.4 - Reflected Cross Site Scriptingjournyx6.1 (v3.1)Medium333141
CVE-2024-6651WordPress File Upload Plugin < 4.24.8 - Cross-Site Scriptingwp-file-upload6.1 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-7314AJ-Report < 1.4.1 - Remote Code Executionreport9.8 (v3.1)Critical337209 , 337211 , 380026
CVE-2024-7029AVTECH IP Camera - Command Injectionavm1203 firmware8.7 (v4.0)High344363
CVE-2024-7332TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerabilitycp450 firmware9.3 (v4.0)Critical390716
CVE-2024-7339TVT DVR Sensitive Device - Information Disclosuresh-4050a5-5l(mm) firmware6.9 (v4.0)Medium392301
CVE-2024-39646WordPress Custom 404 Pro <= 3.11.1 - Reflected XSScustom 404 pro6.1 (v3.1)Medium346755 , 347198 , 377360
CVE-2024-7340W&B Weave Server - Remote Arbitrary File Leak-8.8 (v3.1)High347009
CVE-2024-5765WpStickyBar <= 2.1.0 - SQL Injectionwpstickybar9.8 (v3.1)Critical380122
CVE-2024-5975CZ Loan Management <= 1.1 - SQL Injectioncz loan management9.1 (v3.1)Critical380122
CVE-2024-7188Bylancer Quicklancer 2.4 G - SQL Injectionquicklancer6.9 (v4.0)Medium340016 , 340156 , 341245 , 380026 , 380122
CVE-2024-41810Twisted - Open Redirect & XSStwisted6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-41628Cluster Control CMON API - Directory Traversalcluster control7.5 (v3.1)High347009
CVE-2024-41357phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)phpipam7.1 (v3.1)High340147 , 340148 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2024-7120Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 - Command Injectionmsg2300 firmware5.3 (v4.0)Medium344363 , 344370
CVE-2024-38289TurboMeeting - Boolean-based SQL Injectionturbomeeting9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 390572
CVE-2024-38288TurboMeeting - Post-Authentication Command Injectionturbomeeting7.2 (v3.1)High344363 , 344370
CVE-2024-40422Devika v1 - Path Traversaldevika9.1 (v3.1)Critical340007 , 344360 , 347009 , 390709
CVE-2024-41667OpenAM<=15.0.3 FreeMarker - Template InjectionOpenAM8.8 (v3.1)High344360 , 392647 , 393655
CVE-2024-6753Social Auto Poster <= 5.3.14 - Stored Cross-Site Scriptingsocial auto poster6.1 (v3.1)Medium377360
CVE-2024-38773FormLift for Infusionsoft Web Forms <= 7.5.17 - SQL Injectionformlift for infusionsoft web forms9.8 (v3.1)Critical340016 , 340017 , 360147 , 360148 , 380122
CVE-2024-6911PerkinElmer ProcessPlus <= 1.11.6507.0 - Local File Inclusionprocessplus8.7 (v4.0)High344365 , 347019
CVE-2024-37259WP Extended < 3.0.0 - Stored Cross-Site Scriptingwp extended6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755
CVE-2024-37261WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scriptingwp-lister lite for amazon6.1 (v3.1)Medium346755 , 377360
CVE-2024-40348Bazarr < 1.4.3 - Arbitrary File Readbazarr8.2 (v3.1)High347009
CVE-2024-6205PayPlus Payment Gateway < 6.6.9 - SQL Injectionpayplus payment gateway9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2024-399071Panel SQL Injection - Authenticated1panel9.8 (v3.1)Critical344370 , 380026
CVE-2024-21136Oracle Retail Xstore Suite - Pre-authenticated Path Traversalretail xstore office8.6 (v3.1)High340007 , 344365 , 347019
CVE-2024-6746EasySpider 0.6.2 - Arbitrary File Readeasyspider5.3 (v4.0)Medium346019
CVE-2024-3753Hostel < 1.1.5.3 - Cross-Site Scriptinghostel5.9 (v3.1)Medium341266 , 346755 , 377360
CVE-2024-39914FOG Project < 1.5.10.34 - Remote Command Executionfogproject9.8 (v3.1)Critical344363
CVE-2024-4879ServiceNow UI Macros - Template Injectionservicenow9.3 (v4.0)Critical342259 , 344370
CVE-2024-5217ServiceNow - Incomplete Input Validationservicenow9.2 (v4.0)Critical340157 , 340159 , 342259 , 344370 , 360147 , 360148 , 380026
CVE-2024-6095LocalAI - Partial Local File Readlocalai5.8 (v3.1)Medium344360
CVE-2024-38473Apache HTTP Server - ACL BypassApache HTTP Server8.1 (v3.1)High390709
CVE-2024-36420Flowise 1.4.3 - Arbitrary File Readflowise7.5 (v3.1)High344360 , 390709
CVE-2024-36991Splunk Enterprise - Local File Inclusionsplunk7.5 (v3.1)High390716
CVE-2024-6265UsersWP <= 1.2.10 - Unauthenticated SQL Injectionuserswp9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2024-5827Vanna - SQL injectionvanna-ai/vanna9.8 (v3.0)Critical340029 , 344360 , 344370 , 347009
CVE-2024-5334Devika - Local File Inclusiondevika7.5 (v3.0)High344360 , 347009 , 390709
CVE-2024-6250LOLLMS WebUI - Absolute Path Traversallollms web ui7.5 (v3.0)High392301
CVE-2024-33326LumisXP - Cross-site Scriptinglumis experience platform6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2024-37843Craft CMS <=v3.7.31 - SQL Injectioncraft cms9.8 (v3.1)Critical344378
CVE-2024-5276Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injectionfilecatalyst workflow9.1 (v3.1)Critical341245
CVE-2024-36683PrestaShop productsalert - SQL Injectionthe module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop7.3 (v3.1)High340016 , 340156 , 380026 , 380122
CVE-2024-4841LoLLMS WebUI - Subfolder Prediction via Path Traversallollms-webui3.3 (v3.1)Low344365
CVE-2024-3605WP Hotel Booking <= 2.1.0 - SQL Injectionwp hotel booking9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2024-5522WordPress HTML5 Video Player < 2.5.27 - SQL Injectionhtml5 video player6.5 (v3.1)Medium340016 , 340017 , 340144 , 340157 , 340159 , 360147 , 360148
CVE-2024-28397pyload-ng js2py - Remote Code Executionpyload5.3 (v3.1)Medium340014 , 344363 , 346755 , 360151 , 380026
CVE-2024-36527Puppeteer Renderer - Directory Traversal-6.5 (v3.1)Medium340165 , 344360 , 347009
CVE-2024-36597AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability.life insurance management system8.8 (v3.1)High340145 , 340156 , 341145 , 390572
CVE-2024-36599AEGON LIFE v1.0 Life Insurance Management System - Stored cross-site scripting (XSS)life insurance management system6.1 (v3.1)Medium345493
CVE-2024-3552Web Directory Free < 1.7.0 - SQL Injectionweb directory free9.8 (v3.1)Critical340156 , 380122
CVE-2024-3922Dokan Pro <= 3.10.3 - SQL Injectiondokan9.8 (v3.1)Critical392301
CVE-2024-3032WordPress Themify Builder < 7.5.8 - Open Redirectbuilder6.1 (v3.1)Medium377360
CVE-2024-2473WPS Hide Login <= 1.9.15.2 - Login Page Disclosurewps hide login5.3 (v3.1)Medium377360
CVE-2024-36412SuiteCRM - SQL Injectionsuitecrm9.8 (v3.1)Critical340016 , 340017 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2024-37014Langflow <= 1.0.12 - Remote Code Executionlangflow9.8 (v3.1)Critical340095 , 344370
CVE-2024-37393SecurEnvoy Two Factor Authentication - LDAP Injectionmulti-factor authentication solutions7.5 (v3.1)High392301
CVE-2024-4577PHP CGI - Argument Injectionphp9.8 (v3.1)Critical340165 , 392301
CVE-2024-30464WPZOOM Social Icons Widget <= 4.2.15 - Missing Authorizationsocial-icons-widget-by-wpzoom8.8 (v3.1)High377360
CVE-2024-35693WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting12 step meeting list6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 347198
CVE-2024-35694Wordpress WPMobile.App >= 11.42 - Cross-Site Scriptingwpmobile.app6.1 (v3.1)Medium340147 , 341266
CVE-2024-30163IPS Community Suite - Unauthenticated SQL Injectionips community suite9.8 (v3.1)Critical380026
CVE-2024-4620ArForms < 6.6 - Remote Code Executionarforms9.8 (v3.1)Critical382238
CVE-2024-3408D-Tale 3.10.0 - 3.15.1 - Authentication Bypass & Remote Code Executiondtale9.8 (v3.1)Critical340087 , 340095
CVE-2024-28995SolarWinds Serv-U - Directory Traversalserv-u7.5 (v3.1)High340007 , 344365 , 347019
CVE-2024-2928MLflow < 2.11.3 - Path Traversalmlflow7.5 (v3.1)High340007 , 340162 , 340163 , 390709
CVE-2024-36837CRMEB v.5.2.2 - SQL Injectioncrmeb7.5 (v3.1)High340156 , 340157 , 360147 , 360148
CVE-2024-3469GP Premium <= 2.4.0 - Cross-Site Scriptinggp-premium6.1 (v3.1)Medium341266 , 346755
CVE-2024-20404Cisco Finesse - Server-Side Request Forgery (SSRF)finesse5.3 (v3.1)Medium392301
CVE-2024-4180The Events Calendar < 6.4.0.1 - Cross-site Scriptingthe events calendar9.1 (v3.1)Critical346755
CVE-2024-5420SEH utnserver Pro/ProMAX/INU-100 20.1.22 - Cross-Site Scriptingutnserver Pro8.3 (v4.0)High340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-23692Rejetto HTTP File Server - Template injectionhttp file server9.8 (v3.1)Critical344364 , 344366 , 390703 , 390722
CVE-2024-29824Ivanti EPM - Remote Code Executionendpoint manager8.8 (v3.1)High340155 , 341155 , 341245
CVE-2024-24919Check Point Quantum Gateway - Information Disclosurequantum security gateway8.6 (v3.1)High392301
CVE-2024-35219OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Deleteopenapi-generator8.3 (v3.1)High340007
CVE-2024-4455YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scriptingyith woocommerce ajax search6.1 (v3.1)Medium377360
CVE-2024-4443Business Directory Plugin <= 6.4.2 - SQL Injectionbusiness directory7.5 (v3.1)High340156 , 380026
CVE-2024-35627TileServer API - Cross Site Scriptingtileserver-gl up to v4.4.106.1 (v3.1)Medium346755
CVE-2024-27954WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRFAutomatic9.3 (v3.1)Critical340165 , 344360 , 347009
CVE-2024-3231Popup4Phone <= 1.3.2 - Unauthenticated Stored Cross-Site Scriptingpopup4phone6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-22476Intel Neural Compressor <2.5.0 - SQL InjectionIntel(R) Neural Compressor software10.0 (v3.1)Critical341245
CVE-2024-3848Mlflow < 2.11.0 - Path Traversalmlflow7.5 (v3.1)High340007 , 340162 , 340163 , 390709
CVE-2024-4956Sonatype Nexus Repository Manager 3 - Local File Inclusionnexus7.5 (v3.1)High347009
CVE-2024-3822Base64 Encoder/Decoder <= 0.9.2 - Reflected XSSbase64 encoderdecoder4.8 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-32736CyberPower < v2.8.3 - SQL Injectionpowerpanel7.5 (v3.1)High340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2024-32737CyberPower - SQL Injectionpowerpanel7.5 (v3.1)High340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2024-32738CyberPower - SQL Injectionpowerpanel7.5 (v3.1)High340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2024-32739CyberPower < v2.8.3 - SQL Injectionpowerpanel7.5 (v3.1)High340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2024-34257TOTOLINK EX1800T TOTOLINK EX1800T - Command Injectiona3700r firmware9.8 (v3.1)Critical392301
CVE-2024-29889GLPI 10.0.10-10.0.14 - SQL Injectionglpi8.1 (v3.1)High341245
CVE-2024-34470HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusionmailinspector8.6 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2024-33113D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosuredir-845l5.3 (v3.1)Medium390722
CVE-2023-40504LG Simple Editor <= v3.21.0 - Command Injectionsimple editor9.8 (v3.1)Critical340007 , 344362
CVE-2024-4439WordPress Core <6.5.2 - Cross-Site ScriptingWordPress6.1 (v3.1)Medium377360
CVE-2024-2667InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Uploadinstawp connect9.8 (v3.1)Critical340162 , 340163
CVE-2024-2876Wordpress Email Subscribers by Icegram Express - SQL InjectionEmail Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress9.8 (v3.1)Critical340016 , 380026 , 380122
CVE-2024-34061Changedetection.io <=v0.45.21 - Cross-Site Scriptingchangedetection.io4.3 (v3.1)Medium333141 , 340130 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-4348osCommerce v4.0 - Cross-site Scriptingoscommerce4.3 (v3.1)Medium340147 , 340148 , 342259 , 350147 , 350148
CVE-2024-31823ecommerce-codeigniter-bootstrap Arbitrary Code Execution Vulnerabilityecommerce-codeigniter-bootstrap9.8 (v3.1)Critical344360
CVE-2024-33559Wordpress Theme XStore 9.3.8 - SQLiXStore9.3 (v3.1)Critical340016 , 340017 , 344366
CVE-2024-4257BlueNet Technology Clinical Browsing System 1.2.1 - Sql Injectionclinical browsing system6.5 (v3.1)Medium341245 , 344366 , 361149
CVE-2023-6717Keycloak: xss via assertion consumer service url in saml post-binding flowRed Hat AMQ Broker 76.0 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-32709WP-Recall <= 16.26.5 - SQL InjectionWP-Recall9.3 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 340159 , 341245 , 360147 , 360148 , 390703
CVE-2024-20353adaptive security appliance software Denial of Service Vulnerabilityadaptive security appliance software8.6 (v3.1)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2024-4040CrushFTP VFS - Sandbox Escape LFRcrushftp10.0 (v3.1)Critical392301
CVE-2024-27348Apache HugeGraph-Server - Remote Command Executionhugegraph9.8 (v3.1)Critical380026
CVE-2024-32238H3C ER8300G2-X - Password Disclosure-9.8 (v3.1)Critical390716
CVE-2024-31750F-logic DataCube3 - SQL Injectiondatacube3 firmware9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2024-1483Mlflow < 2.9.2 - Path Traversalmlflow7.5 (v3.1)High340007 , 340162 , 340163 , 390709
CVE-2024-1561Gradio 4.3-4.12 - Local File Readgradio7.5 (v3.0)High344365
CVE-2024-32128WordPress Realtyna Organic IDX Plugin <= 4.14.4 - SQL InjectionRealtyna Organic IDX plugin9.3 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2024-32136BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL InjectionBWL Advanced FAQ Manager7.6 (v3.1)High380026 , 380122
CVE-2023-51409Jordy Meow AI Engine - Unrestricted File Uploadai engine9.8 (v3.1)Critical382238
CVE-2024-24809Traccar - Unrestricted File Uploadtraccar8.5 (v3.1)High330791 , 340152 , 391213
CVE-2024-1728Gradio > 4.19.1 UploadButton - Path Traversalgradio7.5 (v3.1)High344360
CVE-2024-3378iboss Secure Web Gateway - Stored Cross-Site Scripting (XSS)secure web gateway6.1 (v3.1)Medium392301
CVE-2024-31848CData API Server < 23.4.8844 - Path TraversalAPI Server9.8 (v3.1)Critical344365
CVE-2024-31849CData Connect < 23.4.8846 - Path TraversalConnect9.8 (v3.1)Critical344365
CVE-2024-31850CData Arc < 23.4.8839 - Path TraversalArc8.6 (v3.1)High344365
CVE-2024-31851CData Sync < 23.4.8843 - Path TraversalSync8.6 (v3.1)High344365
CVE-2024-2879WordPress Plugin LayerSlider 7.9.11-7.10.0 - SQL Injectionlayerslider7.5 (v3.1)High340016 , 380122
CVE-2024-2389Progress Kemp Flowmon - Command Injectionflowmon9.8 (v3.1)Critical344363
CVE-2024-30498CRM Perks Forms <= 1.1.4 - SQL Injectioncrm perks forms10.0 (v3.1)Critical380122
CVE-2024-30490ProfileGrid <= 5.7.8 - SQL Injectionprofilegrid9.8 (v3.1)Critical340016 , 380122
CVE-2024-30502WP Travel Engine <= 5.7.9 - SQL Injectionwp travel engine9.8 (v3.1)Critical330791 , 340016 , 340017 , 340152 , 340157 , 360147 , 360148 , 380026 , 380122
CVE-2024-29792Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scriptingunlimited elements for elementor6.1 (v3.1)Medium346755 , 347198 , 377360
CVE-2024-29931WP Go Maps <= 9.0.29 - Cross-Site Scriptingwp go maps6.1 (v3.1)Medium341266 , 344370 , 346755 , 377360
CVE-2024-30194Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scriptingsunshine photo cart6.1 (v3.1)Medium333141 , 340149 , 344361 , 344364 , 346755 , 347198 , 377360
CVE-2023-28787Quiz and Survey Master <= 8.1.4 - SQL InjectionQuiz And Survey Master9.3 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-48777WordPress Elementor 3.18.1 - File Upload/Remote Code Executionwebsite builder8.8 (v3.1)High377360
CVE-2023-47873WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Uploadwp child theme generator7.2 (v3.1)High377360
CVE-2024-27956WordPress Automatic Plugin <= 3.92.0 - SQL Injectionautomatic9.8 (v3.1)Critical340156 , 341245 , 380026 , 380122 , 390614
CVE-2024-27292Docassemble - Local File Inclusiondocassemble7.5 (v3.1)High344360 , 347009 , 390709
CVE-2023-7246System Dashboard < 2.8.10 - Cross-Site Scriptingsystem dashboard5.4 (v3.1)Medium377360
CVE-2024-24050Workout Journal App 1.0 - Stored XSSworkout journal app4.7 (v3.1)Medium333140 , 340147 , 340148 , 341256 , 342259 , 345493 , 346755 , 380026 , 390727 , 392301 , 392648
CVE-2024-2621Fujian Kelixin Communication - Command Injectionkelixin communication command and dispatch9.8 (v3.1)Critical340016 , 340156 , 341245 , 380026 , 380122
CVE-2023-40279OpenClinic GA 5.247.01 - Path Traversal (Authenticated)openclinic ga7.5 (v3.1)High340007 , 390727 , 392301 , 392648
CVE-2024-28734Coda v.2024Q1 - Cross-Site ScriptingUnit4 Financials by Coda prior to 2023Q46.1 (v3.1)Medium340112 , 340113 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-29138WordPress Restrict User Access <= 2.5 - Cross-Site Scriptingrestrict user access6.1 (v3.1)Medium346755 , 377360
CVE-2024-28253OpenMetaData - SpEL Injection in PUT /api/v1/policiesopenmetadata8.8 (v3.1)High337209 , 337210 , 337211 , 340095
CVE-2023-6825WordPress File Manager <= 7.2.1 - Directory Traversalfile manager9.9 (v3.1)Critical377360
CVE-2024-0799Arcserve Unified Data Protection - Authentication Bypassudp9.8 (v3.1)Critical391213
CVE-2024-1751Tutor LMS <= 2.1.10 - SQL Injectiontutor lms8.8 (v3.1)High380122
CVE-2024-28623RiteCMS 3.0.0 - Cross-site Scriptingritecms6.1 (v3.1)Medium346755 , 380026
CVE-2024-2330NS-ASG Application Security Gateway 6.3 - Sql Injectionapplication security gateway9.8 (v3.1)Critical340157 , 360147
CVE-2024-27564ChatGPT个人专用版 - Server Side Request Forgerychatgpt web6.5 (v3.1)Medium340165 , 344360 , 347009
CVE-2024-1698NotificationX <= 2.8.2 - SQL Injectionnotificationx9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2024-25608Liferay Portal - Open Redirectdigital experience platform,liferay portal6.1 (v3.1)Medium398005
CVE-2024-1512MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injectionmasterstudy lms9.8 (v3.1)Critical340016 , 340156 , 341245 , 380026 , 380122
CVE-2023-47218QNAP QTS and QuTS Hero - OS Command Injectionqts8.3 (v3.1)High330791 , 340152
CVE-2024-22024Ivanti Connect Secure - XXEconnect secure8.3 (v3.1)High380019
CVE-2024-0566Smart Manager 8.27.0 - Post-Authenticated SQL Injectionsmart manager7.2 (v3.1)High380122 , 390704
CVE-2024-0250Analytics Insights for Google Analytics 4 < 6.3 - Open Redirectanalytics insights6.1 (v3.1)Medium340162 , 340163
CVE-2024-24495Daily Habit Tracker 1.0 - SQL Injectiondaily habit tracker9.8 (v3.1)Critical341245 , 344366 , 380026 , 380122 , 390727 , 392301 , 392648
CVE-2024-24494Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)daily habit tracker6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 344370 , 346755 , 350148 , 360151
CVE-2024-24497Employee Management System 1.0 - txtusername and txtpassword SQL Injection (Admin Login)-N/AN/A340156 , 341245 , 345493
CVE-2024-24131SuperWebMailer 9.31.0.01799 - Cross-Site Scriptingsuperwebmailer6.1 (v3.1)Medium341266 , 346755
CVE-2023-40355Axigen WebMail - Cross-Site Scriptingaxigen mobile webmail5.4 (v3.1)Medium346755
CVE-2023-46359cPH2 Charging Station v1.87.0 - OS Command Injectioncph2 echarge9.8 (v3.1)Critical340014 , 340193 , 344363 , 344364 , 344370 , 393655
CVE-2024-24112Exrick XMall - SQL Injectionxmall9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2023-6989Shield Security WP Plugin <= 18.5.9 - Local File Inclusionshield security9.8 (v3.1)Critical340748
CVE-2024-22319IBM Operational Decision Manager - JNDI Injectionoperational decision manager9.8 (v3.1)Critical398008
CVE-2024-21485Dash Framework - Cross-site Scriptingdash5.4 (v3.1)Medium346755 , 350148
CVE-2024-21893Ivanti SAML - Server Side Request Forgery (SSRF)connect secure8.2 (v3.1)High392301
CVE-2024-1061WordPress HTML5 Video Player - SQL Injectionhtml5 video player9.8 (v3.1)Critical340016 , 380026 , 380122
CVE-2024-24328TotoLink Router setMacFilterRules - Command Injectiona3300r firmware9.8 (v3.1)Critical392301
CVE-2024-24329TotoLink Router setPortForwardRules - Command Injectiona3300r firmware9.8 (v3.1)Critical392301
CVE-2024-24565CrateDB Database - Arbitrary File Readcratedb6.5 (v3.1)Medium340016 , 340017 , 340029 , 344360 , 344370
CVE-2024-0986Issabel Authenticated - Remote Code Executionpbx9.8 (v3.1)Critical344362 , 344363
CVE-2024-23334aiohttp - Directory Traversalaiohttp7.5 (v3.1)High347009
CVE-2024-22729Netis MW5360 V1.0.1.3031 - Command Injectionmw5360 firmware9.8 (v3.1)Critical392301
CVE-2023-6697WP Go Maps (formerly WP Google Maps) < 9.0.29 - Cross-Site Scriptingwp go maps6.1 (v3.1)Medium340099 , 341099 , 346755 , 347198
CVE-2024-0705Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injectionstripe payment plugin for woocommerce7.5 (v3.1)High340016 , 380122
CVE-2022-1609The School Management < 9.9.7 - Remote Code Executionschool management9.8 (v3.1)Critical340095 , 344361
CVE-2023-22527Atlassian Confluence - Remote Code Executionconfluence data center9.8 (v3.1)Critical340095 , 344364 , 344366
CVE-2023-5558LearnPress < 4.2.5.5 - Cross-Site Scriptinglearnpress6.1 (v3.1)Medium340147 , 340148 , 342259 , 346755 , 390722 , 392301
CVE-2023-2252Directorist < 7.5.4 - Local File Inclusiondirectorist2.7 (v3.1)Low344360 , 347009 , 390709
CVE-2023-6623Essential Blocks < 4.4.3 - Local File Inclusionessential blocks9.8 (v3.1)Critical344360 , 347009
CVE-2023-6567LearnPress <= 4.2.5.7 - SQL Injectionlearnpress7.5 (v3.1)High340016 , 341245 , 380026 , 380122
CVE-2023-48728WWBN AVideo 11.6 - Cross-Site Scriptingavideo6.1 (v3.1)Medium340147 , 340148 , 341245 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2024-21650XWiki < 4.10.20 - Remote code executionxwiki9.8 (v3.1)Critical340130
CVE-2023-6750WordPress WP Clone <= 2.4.2 - Database Backup Exposureclone7.5 (v3.1)High350590 , 390716
CVE-2024-0195SpiderFlow Crawler Platform - Remote Code Executionspider-flow9.8 (v3.1)Critical337209 , 337210 , 337211 , 340095
CVE-2023-50094reNgine 2.2.0 - Command Injectionrengine8.8 (v3.1)High330791 , 340152
CVE-2023-6000WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSSpopup builder6.1 (v3.1)Medium346755 , 350148
CVE-2023-50071CVE-2023-50071 - Multiple SQL Injectioncustomer support system8.8 (v3.1)High330791 , 340152
CVE-2023-50839JS Help Desk <= 2.8.1 - SQL Injectionjs help desk9.8 (v3.1)Critical380122
CVE-2023-49230Peplink Balance Two before 8.4.0 - Unauthenticated Config Uploadbalance two firmware8.8 (v3.1)High330791 , 340152 , 392301
CVE-2023-7137Client Details System 1.0 - SQL Injectionclient details system8.8 (v3.1)High331028 , 340016 , 340017 , 340144 , 340156 , 340157 , 344364 , 344366 , 344370 , 360147 , 360148 , 360151 , 380026 , 380122
CVE-2023-7116WeiYe-Jing datax-web <= 2.1.2 - OS Command Injectiondatax-web9.8 (v3.1)Critical340014 , 344364 , 344366
CVE-2023-5991Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletionhotel booking lite9.8 (v3.1)Critical344360 , 347009 , 390709
CVE-2023-5203WP Sessions Time Monitoring Full Automatic <= 1.0.8 - SQL Injectionwp sessions time monitoring full automatic7.5 (v3.1)High340016 , 380026 , 380122
CVE-2023-32590Subscribe to Category <= 2.7.4 - SQL Injectionsubscribe to category7.5 (v3.1)High340016 , 340156 , 341145 , 341245 , 380026 , 380122
CVE-2023-6977Mlflow <2.8.0 - Local File Inclusionmlflow7.5 (v3.1)High344360
CVE-2023-44982WordPress Perfect Images (WP Retina 2x) < 6.4.6 - Sensitive Information Exposureperfect images7.5 (v3.1)High390716
CVE-2023-49489KodeExplorer 4.51 - Reflective Cross Site Scripting (XSS)kodexplorer6.1 (v3.1)Medium342259 , 346755
CVE-2023-6909Mlflow <2.9.2 - Path Traversalmlflow7.5 (v3.1)High392301
CVE-2023-50917MajorDoMo thumb.php - OS Command Injectionmajordomo9.8 (v3.1)Critical344363
CVE-2023-6553Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Executionbackup migration9.8 (v3.1)Critical301106
CVE-2023-6831mlflow - Path Traversalmlflow8.1 (v3.1)High390709
CVE-2023-48084Nagios XI < 5.11.3 - SQL Injectionnagios xi9.8 (v3.1)Critical340130 , 340145 , 340156 , 380026 , 380122
CVE-2022-45365Stock Ticker <= 3.23.2 - Cross-Site-Scriptingstock ticker6.1 (v3.1)Medium346755
CVE-2023-41621Emlog Pro v2.1.14 - Cross-Site Scriptingemlog6.1 (v3.1)Medium346755 , 350148
CVE-2023-6379OpenCMS 14 & 15 - Cross Site Scriptingopencms6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-49494DedeCMS v5.7.111 - Cross-Site Scriptingdedecms6.1 (v3.1)Medium333141 , 340087 , 340095 , 340099 , 340149 , 341099 , 341256 , 342259 , 346755
CVE-2023-6655Hongjing e-HR 2020 - SQL Injectione-hr9.8 (v3.1)Critical341245 , 344366 , 361149
CVE-2023-6568Mlflow - Cross-Site Scriptingmlflow6.1 (v3.1)Medium334168 , 391213
CVE-2023-6063WP Fastest Cache 1.2.2 - Unauthenticated SQL Injectionwp fastest cache7.5 (v3.1)High340016 , 341245 , 380026 , 380122
CVE-2023-49293Vite dev server - Cross-Site Scriptingvite6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-6360WordPress My Calendar <3.4.22 - SQL Injectionmy calendar9.8 (v3.1)Critical340016 , 340156 , 341145 , 341245 , 380026 , 380122
CVE-2023-40211Post Grid <= 2.2.50 - Information Exposure via REST APIpost grid combo7.5 (v3.1)High330791 , 340152
CVE-2023-40600EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosureimage optimizer7.5 (v3.1)High390716
CVE-2023-3368Chamilo LMS <= v1.11.20 Unauthenticated Command Injectionchamilo9.8 (v3.1)Critical344363 , 344370 , 393655
CVE-2023-48022Anyscale Ray - Remote Code Executionray9.8 (v3.1)Critical392301 , 392648
CVE-2022-41678Apache ActiveMQ < 5.16.5/5.17.3 - Remote Code Executionactivemq8.8 (v3.1)High330925
CVE-2023-6275TOTVS Fluig Platform - Cross-Site Scriptingfluig6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-5815News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusionnews &amp; blog designer pack9.8 (v3.1)Critical340748 , 347006
CVE-2023-5652WP Hotel Booking <= 2.0.7 - SQL Injectionwp hotel booking9.8 (v3.1)Critical340156 , 380122
CVE-2023-38879openSIS v9.0 - Path Traversalopensis7.5 (v3.1)High344360 , 347009 , 390709
CVE-2023-48241XWiki < 4.10.15 - Information Disclosurexwiki7.5 (v3.1)High390722
CVE-2023-44353Adobe ColdFusion WDDX Deserialization Gadgetscoldfusion9.8 (v3.1)Critical344365 , 344370 , 350147
CVE-2023-44352Adobe Coldfusion - Cross-Site Scriptingcoldfusion6.1 (v3.1)Medium340099 , 340147 , 341099 , 341266 , 346755 , 347198
CVE-2023-6020Ray Static File - Local File Inclusionray7.5 (v3.1)High347009
CVE-2023-6023VertaAI ModelDB - Path Traversalmodeldb7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2023-6038H2O ImportFiles - Local File Inclusionh2o7.5 (v3.1)High344360 , 347009 , 390709
CVE-2023-41597EyouCms v1.6.2 - Cross-Site Scriptingeyoucms6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-46022Blood Bank 1.0 - 'bid' SQLiblood bank7.8 (v3.1)High340016 , 340017 , 340144 , 340157 , 340159 , 341245 , 360147 , 360148 , 390727 , 392301 , 392648
CVE-2023-47684Essential Grid <= 3.1.0 - Cross-Site Scriptingessential grid6.1 (v3.1)Medium341266 , 346755
CVE-2023-46020Blood Bank v1.0 - Stored Cross Site Scripting (XSS)blood bank6.1 (v3.1)Medium333141 , 341256 , 342259 , 345493 , 346755 , 350147 , 350148
CVE-2023-46014Blood Bank v1.0 - Multiple SQL Injectionblood bank5.5 (v3.1)Medium345493
CVE-2023-46017Blood Bank v1.0 - Multiple SQL Injectionblood bank5.5 (v3.1)Medium345493
CVE-2023-46018Blood Bank v1.0 - Multiple SQL Injectionblood bank5.5 (v3.1)Medium345493
CVE-2023-39796WBCE 1.6.0 - Unauthenticated SQL injectionwbce cms9.8 (v3.1)Critical340016 , 340145 , 340156 , 380026 , 380122
CVE-2023-47246SysAid Server - Remote Code Executionsysaid on-premises9.8 (v3.1)Critical340007 , 390614 , 390626 , 390724
CVE-2023-47248PyArrow Flight RPC - Remote Code Executionpyarrow9.8 (v3.1)Critical391213
CVE-2023-46732XWiki < 14.10.14 - Cross-Site Scriptingxwiki6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-45805WordPress Paytm Payment Gateway <=2.7.3 - SQL Injectionpayment gateway9.8 (v3.1)Critical380122
CVE-2023-34259Kyocera TASKalfa printer - Path Traversald-copia253mf plus firmware4.9 (v3.1)Medium347009
CVE-2023-1719Bitrix Component - Cross-Site Scriptingbitrix249.8 (v3.1)Critical333141 , 341256 , 342259 , 346755 , 347198
CVE-2023-24000WordPress GamiPress <= 2.5.7 - SQL Injectiongamipress9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2023-5360WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Uploadroyal elementor addons9.8 (v3.1)Critical382238
CVE-2023-5863phpMyFAQ < 3.2.0 - Cross-site Scriptingphpmyfaq6.1 (v3.1)Medium333141 , 340248 , 342259 , 346755 , 350148
CVE-2023-45671Frigate < 0.13.0 Beta 3 - Cross-Site Scriptingfrigate4.7 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-46818ISPConfig - PHP Code Injectionispconfig7.2 (v3.1)High340095
CVE-2023-43208NextGen Healthcare Mirth Connect - Remote Code Executionmirth connect9.8 (v3.1)Critical344363 , 344364 , 344380
CVE-2023-46747F5 BIG-IP - Unauthenticated RCE via AJP Smugglingbig-ip access policy manager9.8 (v3.1)Critical390626 , 392767
CVE-2023-34048VMware vCenter Server - Out-of-Bounds Writevcenter server9.8 (v3.1)Critical392301
CVE-2023-46347PrestaShop Step by Step products Pack - SQL Injectionndk steppingpack9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 341245 , 344366 , 360147 , 360148
CVE-2023-46574TOTOLINK A3700R - Command Injectiona3700r firmware9.8 (v3.1)Critical392301 , 392648
CVE-2023-45136XWiki < 14.10.14 - Cross-Site Scriptingxwiki9.6 (v3.1)Critical341266
CVE-2023-5758firefox mobile Cross-Site Scripting Vulnerabilityfirefox mobile6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-38192SuperWebMailer 9.00.0.01710 - Cross-Site Scriptingsuperwebmailer6.1 (v3.1)Medium340147 , 340148 , 342259 , 346755
CVE-2023-38194SuperWebMailer - Cross-Site Scriptingsuperwebmailer6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-5204WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injectionwpbot7.5 (v3.1)High340016 , 380122
CVE-2023-45826Leantime < 2.4 - Authenticated SQL Injectionleantime6.5 (v3.1)Medium340017 , 340159 , 341245 , 390726 , 392647
CVE-2023-45375PrestaShop PireosPay - SQL Injectionpireospay8.8 (v3.1)High341245 , 344366
CVE-2023-45542MooSocial 3.1.8 - Cross-Site Scriptingmoosocial6.1 (v3.1)Medium340147 , 341266 , 342259 , 350147 , 350148
CVE-2023-45852Viessmann Vitogate 300 - Remote Code Executionvitogate 300 firmware9.8 (v3.1)Critical344360 , 344361 , 344363
CVE-2023-34993Fortinet FortiWLM Unauthenticated Command Injection Vulnerabilityfortiwlm9.8 (v3.1)Critical344363
CVE-2023-44393Piwigo - Cross-Site Scriptingpiwigo6.1 (v3.1)Medium341266 , 346755
CVE-2023-44812mooSocial v.3.1.8 - Cross-Site Scriptingmoosocial6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755
CVE-2023-44813mooSocial v.3.1.8 - Cross-Site Scriptingmoosocial6.1 (v3.1)Medium346755
CVE-2023-5452SnipeIT 6.2.1 - Stored Cross Site Scriptingsnipe-it5.4 (v3.1)Medium333140 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2023-43261Milesight Routers - Information Disclosureur517.5 (v3.1)High390716
CVE-2023-44012mojoPortal v.2.7.0.0 - Cross-Site Scriptingmojoportal6.1 (v3.1)Medium333141 , 341256 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148
CVE-2023-43662ShokoServer System - Local File Inclusion (LFI)shokoserver8.6 (v3.1)High344365 , 390716
CVE-2023-5244Microweber < V.2.0 - Cross-Site Scriptingmicroweber6.1 (v3.1)Medium346755 , 380026 , 393655
CVE-2023-43325MooSocial 3.1.8 - Cross-Site Scriptingmoosocial6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-4490WordPress Job Portal < 2.0.6 - SQL Injectionwp job portal9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-4148Ditty < 3.1.25 - Cross-Site Scriptingditty6.1 (v3.1)Medium340148 , 341266 , 346755
CVE-2023-43326MooSocial 3.1.8 - Cross-Site Scriptingmoosocial6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-43373Hoteldruid v3.0.5 - SQL Injectionhoteldruid9.8 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2023-43374Hoteldruid v3.0.5 - SQL Injectionhoteldruid9.8 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2023-38875PHP Login System 2.0.1 - Cross-Site Scriptingphp-login-system6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-41599JFinalCMS v5.0.0 - Directory Traversaljfinalcms5.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2023-33831FUXA - Unauthenticated Remote Code Executionfuxa9.8 (v3.1)Critical340095 , 344370 , 345240 , 380026
CVE-2023-38040Revive Adserver 5.4.1 - Cross-Site Scriptingrevive adserver6.1 (v3.1)Medium340147 , 341256 , 341266 , 346755
CVE-2023-4974Academy LMS 6.2 - SQL Injectionacademy lms9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-4973Academy LMS 6.2 - Cross-Site Scriptingacademy lms6.1 (v3.1)Medium340147 , 346755 , 350148
CVE-2023-41892CraftCMS < 4.4.15 - Unauthenticated Remote Code Executioncraft cms9.8 (v3.1)Critical344365
CVE-2023-3710Honeywell PM43 Printers - Command Injectionpm43 firmware9.8 (v3.1)Critical344361 , 344363
CVE-2023-3169tagDiv Composer < 4.2 - Stored Cross-Site Scriptingtagdiv composer6.1 (v3.1)Medium380026
CVE-2023-40924SolarView Compact < 6.00 - Directory Traversalsolarview compact firmware7.5 (v3.1)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2023-39676PrestaShop fieldpopupnewsletter Module - Cross Site Scriptingfieldpopupnewsletter6.1 (v3.1)Medium341266 , 346755
CVE-2023-4634Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusionmedia library assistant9.8 (v3.1)Critical300017
CVE-2021-36646KodExplorer - Cross-Site Scriptingkod-explorer6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-39361Cacti 1.2.24 - SQL Injectioncacti9.8 (v3.1)Critical344366 , 380026 , 380122
CVE-2023-39598IceWarp Email Client - Cross Site Scriptingwebclient6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147
CVE-2023-2813Wordpress Multiple Themes - Reflected Cross-Site Scriptingconnections reloaded6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2023-40208Stock Ticker <= 3.23.2 - Cross-Site Scriptingstock ticker6.1 (v3.1)Medium346755
CVE-2023-4151Store Locator WordPress < 1.4.13 - Cross-Site Scriptingstore locator6.1 (v3.1)Medium377360
CVE-2023-4284WordPress Post Timeline Plugin < 2.2.6 - Cross-Site Scriptingpost timeline6.1 (v3.1)Medium346755 , 347198 , 377360
CVE-2023-4596WordPress Plugin Forminator 1.24.6 - Arbitrary File Uploadforminator9.8 (v3.1)Critical300006
CVE-2023-41538PHPJabbers PHP Forum Script 3.0 - Cross-Site Scriptingphp forum script6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-39650PrestaShop Theme Volty CMS Blog - SQL Injectiontheme volty cms blog9.8 (v3.1)Critical340016 , 340156 , 341145 , 341245 , 380026 , 380122
CVE-2023-40748PHPJabbers Food Delivery Script - SQL Injectionfood delivery script9.8 (v3.1)Critical340156 , 341145 , 341245
CVE-2023-40749PHPJabbers Food Delivery Script v3.0 - SQL Injectionfood delivery script9.8 (v3.1)Critical340017 , 340156 , 340157 , 341245 , 360147 , 360148
CVE-2023-41109SmartNode SN200 Analog Telephone Adapter (ATA) & VoIP Gateway - Command Injectionsmartnode sn2009.8 (v3.1)Critical392301
CVE-2023-40750PHPJabbers Yacht Listing Script v1.0 - Cross-Site Scriptingyacht listing script6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-40751PHPJabbers Fundraising Script v1.0 - Cross-Site Scriptingfundraising script6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-40752PHPJabbers Make an Offer Widget v1.0 - Cross-Site Scriptingmake an offer widget6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-40755PHPJabbers Callback Widget v1.0 - Cross-Site Scriptingcallback widget6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2023-40753PHPJabbers Ticket Support Script v3.2 - Cross-Site Scriptingticket support script5.4 (v3.1)Medium341266
CVE-2023-4547SPA-Cart eCommerce CMS 1.9.0.3 - Cross-Site Scriptingecommerce cms6.1 (v3.1)Medium333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-39600IceWarp 11.4.6.0 - Cross-Site Scriptingicewarp6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-39700IceWarp Mail Server v10.4.5 - Cross-Site Scriptingmail server6.1 (v3.1)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755
CVE-2023-39026FileMage Gateway - Directory TraversalWindows7.5 (v3.1)High344365 , 347019 , 390716
CVE-2023-39141Aria2 WebUI - Path traversalwebui-aria27.5 (v3.1)High347009
CVE-2023-4450JeecgBoot JimuReport - Template injectionjeecg9.8 (v3.1)Critical340014 , 344370 , 393655
CVE-2023-3936Blog2Social < 7.2.1 - Cross-Site Scriptingblog2social6.1 (v3.1)Medium347198
CVE-2023-4451Cockpit - Cross-Site Scriptingcockpit6.1 (v3.1)Medium340099 , 341099 , 346755 , 347198
CVE-2023-4415Ruijie RG-EW1200G Router Background - Login Bypassrg-ew1200g firmware8.8 (v3.1)High392301
CVE-2023-38910CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )csz cms6.1 (v3.1)Medium333141 , 342259 , 346755 , 350147 , 350148
CVE-2023-38911CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')csz cms5.4 (v3.1)Medium333141 , 342259 , 346755 , 350147 , 350148
CVE-2023-36845Juniper J-Web - Remote Code Executionjunos9.8 (v3.1)Critical344360 , 390709
CVE-2023-2122Image Optimizer by 10web < 1.0.26 - Cross-Site Scriptingimage optimizer6.1 (v3.1)Medium340099 , 341099 , 346755 , 347198
CVE-2023-2272Tiempo.com <= 0.1.2 - Cross-Site Scriptingtiempo6.1 (v3.1)Medium377360
CVE-2023-4382Hyip Rio 2.1 - Arbitrary File Uploadhyip rio5.4 (v3.1)Medium392301
CVE-2023-3452WordPress Canto Plugin <= 3.0.4 - File Inclusioncanto9.8 (v3.1)Critical340077 , 340694 , 340695
CVE-2023-32563Ivanti Avalanche - Remote Code Executionavalanche9.8 (v3.1)Critical340007
CVE-2023-37988Contact Form Generator <= 2.5.5 - Cross-Site Scriptingcontact form generator6.1 (v3.1)Medium341266 , 346755
CVE-2023-36306Adiscon LogAnalyzer v.4.1.13 - Cross-Site Scriptingloganalyzer6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4173mooSocial 3.1.8 - Reflected XSSmoostore6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-4174mooSocial 3.1.6 - Reflected Cross Site Scriptingmoostore6.1 (v3.1)Medium333141 , 340099 , 340147 , 341099 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-4169Ruijie RG-EW1200G Router - Password Resetrg-ew1200g firmware8.8 (v3.1)High392301
CVE-2023-39143PaperCut < 22.1.3 - Path Traversalpapercut mf9.8 (v3.1)Critical344365 , 347019
CVE-2023-38964Academy LMS 6.0 - Cross-Site Scriptingacademy lms6.1 (v3.1)Medium333141 , 342259 , 347198 , 350147 , 350148
CVE-2023-37679NextGen Mirth Connect - Remote Code Executionmirth connect9.8 (v3.1)Critical344363
CVE-2023-38950ZKTeco BioTime v8.5.5 - Path Traversalbiotime7.5 (v3.1)High340007
CVE-2023-4110PHPJabbers Availability Booking Calendar 5.0 - Cross-Site Scriptingavailability booking calendar6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4111PHPJabbers Bus Reservation System 1.1 - Cross-Site Scriptingbus reservation system6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4112PHPJabbers Shuttle Booking Software 1.0 - Cross Site Scriptingshuttle booking software6.1 (v3.1)Medium340147 , 341266 , 346755
CVE-2023-4113PHPJabbers Service Booking Script 1.0 - Cross Site Scriptingservice booking script6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4114PHP Jabbers Night Club Booking 1.0 - Cross Site Scriptingnight club booking software6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4115PHPJabbers Cleaning Business 1.0 - Cross-Site Scriptingcleaning business software6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4116PHPJabbers Taxi Booking 2.0 - Cross Site Scriptingtaxi booking script6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-4136CrafterCMS Engine - Cross-Site Scriptingcraftercms6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2023-34960Chamilo Command Injectionchamilo9.8 (v3.1)Critical341245 , 344360 , 344361 , 344363 , 344370
CVE-2023-39108rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High340162 , 340165 , 344360 , 347009
CVE-2023-39109rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High340162 , 340165 , 344360 , 347009
CVE-2023-39110rConfig 3.9.4 - Server-Side Request Forgeryrconfig8.8 (v3.1)High340165 , 344360 , 347009
CVE-2023-34635Wifi Soft Unibox Administration 3.0 & 3.1 - SQL Injectionunibox administration9.8 (v3.1)Critical340145 , 340156 , 341145 , 390572
CVE-2023-3345LMS by Masteriyo < 1.6.8 - Information Exposuremasteriyo6.5 (v3.1)Medium377360
CVE-2023-0602Twittee Text Tweet <= 1.0.8 - Cross-Site Scriptingtwittee text tweet6.1 (v3.1)Medium341266 , 346755
CVE-2023-37580Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scriptingzimbra6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-3990Mingsoft MCMS < 5.3.1 - Cross-Site Scriptingmcms6.1 (v3.1)Medium342259 , 350148
CVE-2023-37979Ninja Forms < 3.6.26 - Cross-Site Scriptingninja forms6.1 (v3.1)Medium346755 , 377360
CVE-2023-31465TimeKeeper by FSMLabs - Remote Code Executiontimekeeper9.8 (v3.1)Critical344361 , 344364 , 393655
CVE-2023-38501CopyParty v1.8.6 - Cross Site Scriptingcopyparty6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148 , 390722
CVE-2023-2309wpForo Forum <= 2.1.8 - Cross-Site Scriptingwpforo forum6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2023-3843mooDating 1.2 - Cross-site scriptingmoodating6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3844MooDating 1.2 - Cross-Site Scriptingmoodating6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3845MooDating 1.2 - Cross-Site Scriptingmoodating6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3846MooDating 1.2 - Cross-Site Scriptingmoodating6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3847MooDating 1.2 - Cross-Site scriptingmoodating6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3848MooDating 1.2 - Cross-site scriptingmoodating6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-3849mooDating 1.2 - Cross-site scriptingmoodating6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2023-38203Adobe ColdFusion - Deserialization of Untrusted Datacoldfusion9.8 (v3.1)Critical344370 , 344380 , 350147
CVE-2023-37728IceWarp Webmail Server v10.2.1 - Cross Site Scriptingicewarp6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198
CVE-2023-3722Avaya Aura Device Services - OS Command Injectionaura device services9.8 (v3.1)Critical392301
CVE-2023-22047Oracle Peoplesoft - Unauthenticated File Readpeoplesoft enterprise7.5 (v3.1)High340165 , 344360 , 344365 , 347009
CVE-2023-1893Login Configurator <=2.1 - Cross-Site Scriptinglogin configurator6.1 (v3.1)Medium341266 , 346755
CVE-2023-37462XWiki Platform - Remote Code Executionxwiki8.8 (v3.1)High340130
CVE-2023-37474Copyparty <= 1.8.2 - Directory Traversalcopyparty7.5 (v3.1)High347009
CVE-2023-34124SonicWall GMS and Analytics Web Services - Shell Injectionanalytics9.8 (v3.1)Critical340017 , 360148 , 380123
CVE-2023-34133SonicWall GMS and Analytics - SQL Injectionanalytics7.5 (v3.1)High340017 , 360148 , 380123
CVE-2023-29300Adobe ColdFusion - Pre-Auth Remote Code Executioncoldfusion9.8 (v3.1)Critical344370 , 344380 , 350147
CVE-2023-3643CAREL Boss Mini <= 1.4.0 - Local File Inclusionboss-mini9.8 (v3.1)Critical344360 , 390709
CVE-2023-37629Online Piggery Management System v1.0 - Unauthenticated File Uploadsimple online piggery management system9.8 (v3.1)Critical330791
CVE-2023-3077MStore API < 3.9.8 - SQL Injectionmstore api9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-23897Ozette Plugins - Cross-Site Request Forgerysimple mobile url redirect8.8 (v3.1)High345490 , 377360
CVE-2023-1119WP-Optimize WordPress plugin < 3.2.13 - Cross-Site Scriptingwp-optimize,srbtranslatin6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-1780Companion Sitemap Generator < 4.5.3 - Cross-Site Scriptingcompanion sitemap generator6.1 (v3.1)Medium333141 , 346755 , 347198
CVE-2023-24488Citrix Gateway and Citrix ADC - Cross-Site Scriptinggateway6.1 (v3.1)Medium340099 , 340147 , 341099 , 341266 , 342259 , 360151 , 390722
CVE-2023-34192Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scriptingcollaboration9.0 (v3.1)Critical340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-3521FOSSBilling < 0.5.3 - Cross-Site Scriptingfossbilling6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-36934MOVEit Transfer - SQL Injectionmoveit transfer9.1 (v3.1)Critical340016 , 344362
CVE-2023-3479Hestiacp <= 1.7.7 - Cross-Site Scriptingcontrol panel6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-34843Traggo Server - Local File Inclusiontraggo7.5 (v3.1)High344365 , 347019
CVE-2023-34599Gibbon v25.0.0 - Cross-Site Scriptinggibbon6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-30203Dzzoffice 2.02.1 - Cross-Site Scriptingdzzoffice6.1 (v3.1)Medium333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2023-2624KiviCare WordPress Plugin - Cross-Site Scriptingkivicare6.1 (v3.1)Medium346755 , 347198
CVE-2023-2178Aajoda Testimonials < 2.2.2 - Cross-Site Scriptingaajoda testimonials4.8 (v3.1)Medium346755 , 377360
CVE-2023-3197WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injectionmstore api9.8 (v3.1)Critical340016 , 380026 , 380122
CVE-2023-30258MagnusBilling - Remote Code Executionmagnusbilling9.8 (v3.1)Critical344363 , 344364 , 344366
CVE-2023-3380WAVLINK WN579X3 - Remote Command Executionwn579x3 firmware9.8 (v3.1)Critical340014 , 344363
CVE-2023-36284QloApps 1.6.0 - SQL Injectionqloapps7.5 (v3.1)High341245 , 380026 , 380122
CVE-2023-35155XWiki - Cross-Site Scriptingxwiki6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198
CVE-2023-35156XWiki >= 6.0-rc-1 - Cross-Site Scriptingxwiki6.1 (v3.1)Medium346755 , 350148
CVE-2023-35158XWiki - Cross-Site Scriptingxwiki6.1 (v3.1)Medium346755 , 350148
CVE-2023-35159XWiki >= 3.4-milestone-1 - Cross-Site Scriptingxwiki6.1 (v3.1)Medium346755 , 350148
CVE-2023-35160XWiki >= 2.5-milestone-2 - Cross-Site Scriptingxwiki6.1 (v3.1)Medium346755 , 350148
CVE-2023-35161XWiki >= 6.2-milestone-1 - Cross-Site Scriptingxwiki6.1 (v3.1)Medium346755 , 350148
CVE-2023-35162XWiki < 14.10.5 - Cross-Site Scriptingxwiki6.1 (v3.1)Medium346755 , 350148
CVE-2023-36287Webkul QloApps 1.6.0 - Cross-site Scriptingqloapps6.1 (v3.1)Medium350148
CVE-2023-36289Webkul QloApps 1.6.0 - Cross-site Scriptingqloapps6.1 (v3.1)Medium333141 , 340149 , 341256 , 346755
CVE-2023-36346POS Codekop v2.0 - Cross Site Scriptingcodekop6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2020-20969PluckCMS 4.7.10 - Unrestricted File Uploadpluck7.2 (v3.1)High340035 , 390727 , 392301 , 392648
CVE-2023-35843NocoDB version <= 0.106.1 - Arbitrary File Readnocodb7.5 (v3.1)High347009
CVE-2023-35844Lightdash version <= 0.510.3 Arbitrary File Readlightdash7.5 (v3.1)High347009
CVE-2023-2779Super Socializer < 7.13.52 - Cross-Site Scriptingsocial share, social login and social comments6.1 (v3.1)Medium340099 , 341099 , 341258 , 346755 , 347198
CVE-2023-34659JeecgBoot 3.5.0 - SQL Injectionjeecg boot9.8 (v3.1)Critical330791 , 340152
CVE-2023-30625Rudder Server < 1.3.0-rc.1 - SQL Injectionrudder-server8.8 (v3.1)High392301
CVE-2023-30150PrestaShop leocustomajax 1.0 & 1.0.0 - SQL Injectionleocustomajax9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-34751bloofoxCMS v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-34752bloofoxCMS v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-34753bloofoxCMS v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-34754Bloofox v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-34755bloofoxCMS v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical380026 , 380122
CVE-2023-34756Bloofox v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical380026 , 380122
CVE-2023-34537Hoteldruid 3.0.5 - Cross-Site Scriptinghoteldruid5.4 (v3.1)Medium340130 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2023-27624WordPress Redirect After Login <= 0.1.9 - Admin Stored XSSredirect after login4.8 (v3.1)Medium346755
CVE-2023-34105SRS - Command Injectionsimple realtime server7.5 (v3.1)High344364
CVE-2023-3188Owncast - Server Side Request Forgeryowncast6.5 (v3.1)Medium392301
CVE-2023-3187Teachers Record Management System 1.0 - File Upload Type Validationteachers record management system5.4 (v3.1)Medium345493
CVE-2023-3184Sales Tracker Management System v1.0 - Multiple Vulnerabilitiessales tracker management system4.8 (v3.1)Medium345493
CVE-2023-32749Pydio Cells 4.1.2 - Unauthorised Role Assignmentscells8.8 (v3.1)High330791 , 340152
CVE-2019-25141Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Updateeasy wp smtp9.8 (v3.1)Critical390726 , 392647
CVE-2023-20887VMware VRealize Network Insight - Remote Code Executionvrealize network insight9.8 (v3.1)Critical391213
CVE-2023-33510Jeecg P3 Biz Chat - Local File Inclusionjeecg p3 biz chat7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2020-36731Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Updateflexible checkout fields for woocommerce6.1 (v3.1)Medium346755 , 377360 , 390585
CVE-2023-0900AP Pricing Tables Lite <= 1.1.6 - SQL Injectionpricing table builder7.2 (v3.1)High377360
CVE-2023-2224Seo By 10Web < 1.2.7 - Cross-Site Scriptingseo4.8 (v3.1)Medium377360
CVE-2023-34362MOVEit Transfer - Remote Code Executionmoveit cloud9.8 (v3.1)Critical340016 , 390716
CVE-2023-27639PrestaShop TshirteCommerce - Directory Traversalcustom product designer7.5 (v3.1)High340007
CVE-2023-27640PrestaShop tshirtecommerce - Directory Traversalcustom product designer7.5 (v3.1)High340007
CVE-2023-34092Vite Dev Server - Information Exposurevite7.5 (v3.1)High390709
CVE-2023-33629H3C Magic R300-2100M - Remote Code Executionmagic r300-2100m firmware7.2 (v3.1)High392301
CVE-2023-26842ChurchCRM 4.5.3 - Cross-Site Scriptingchurchcrm5.4 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 350148
CVE-2023-31548ChurchCRM v4.5.3 - Cross-Site Scriptingchurchcrm5.4 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755
CVE-2023-2023Custom 404 Pro < 3.7.3 - Cross-Site Scriptingcustom 404 pro6.1 (v3.1)Medium346755 , 347198
CVE-2023-2256WordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site Scriptingwoocommerce-product-addon6.1 (v3.1)Medium341266 , 346755
CVE-2023-2518WordPress Easy Forms for Mailchimp Plugin < 6.8.9 - Cross-Site Scriptingeasy forms for mailchimp6.1 (v3.1)Medium347198 , 377360
CVE-2022-24627AudioCodes Device Manager Express - SQL Injectiondevice manager express9.8 (v3.1)Critical340145 , 340156 , 390572
CVE-2023-2948OpenEMR < 7.0.1 - Cross-Site Scriptingopenemr6.1 (v3.1)Medium344363 , 346755
CVE-2023-2949OpenEMR < 7.0.1 - Cross-site Scriptingopenemr6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2023-33439Faculty Evaluation System v1.0 - SQL Injectionfaculty evaluation system7.2 (v3.1)High340157 , 340159 , 360147 , 360148
CVE-2023-2734MStore API <= 3.9.1 - Authentication Bypassmstore api9.8 (v3.1)Critical330791 , 340152
CVE-2023-33338Old Age Home Management System v1.0 - SQL Injectionold age home management system9.8 (v3.1)Critical340145 , 340156 , 390572
CVE-2023-33362Piwigo 13.6.0 - SQL Injectionpiwigo9.8 (v3.1)Critical390727 , 392301 , 392648
CVE-2023-27922Newsletter < 7.6.9 - Cross-Site Scriptingnewsletter6.1 (v3.1)Medium341266 , 346755
CVE-2023-2822Ellucian Ethos Identity CAS - Cross-Site Scriptingethos identity6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-30868Tree Page View Plugin < 1.6.7 - Cross-Site Scriptingcms tree page view6.1 (v3.1)Medium341266
CVE-2023-2780Mlflow <2.3.1 - Local File Inclusion Bypassmlflow9.8 (v3.1)Critical398008
CVE-2023-2766Weaver OA 9.5 - Information Disclosureweaver office automation7.5 (v3.1)High390716
CVE-2023-2745WordPress Core <=6.2 - Directory TraversalWordPress5.4 (v3.1)Medium336461 , 340007 , 344360 , 381206
CVE-2023-29439FooGallery plugin <= 2.2.35 - Cross-Site Scriptingfoogallery6.1 (v3.1)Medium340147 , 341266
CVE-2023-0600WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL Injectionwp visitor statistics9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-1835Ninja Forms < 3.6.22 - Cross-Site Scriptingninja forms6.1 (v3.1)Medium347198
CVE-2023-1890Tablesome < 1.0.9 - Cross-Site Scriptingtablesome6.1 (v3.1)Medium340148 , 341266
CVE-2023-2009Pretty Url <= 1.5.4 - Cross-Site Scriptingpretty url4.8 (v3.1)Medium377360
CVE-2023-30192PrestaShop 'possearchproducts' <= 1.7 - SQL Injectionpossearchproducts9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-2648Weaver E-Office 9.5 - Remote Code Executione-office9.8 (v3.1)Critical330791 , 340152
CVE-2023-30256Webkul QloApps 1.5.2 - Cross-site Scriptingqloapps6.1 (v3.1)Medium333141 , 340149 , 341256 , 346755 , 347198
CVE-2023-30194Prestashop posstaticfooter <= 1.0.0 - SQL Injectionpoststaticfooter9.8 (v3.1)Critical341245 , 344366
CVE-2023-30777Advanced Custom Fields < 6.1.6 - Cross-Site Scriptingadvanced custom fields6.1 (v3.1)Medium333141 , 347198
CVE-2023-1408Video List Manager <= 1.7 - SQL Injectionvideo list manager7.2 (v3.1)High380122
CVE-2023-0514Membership Database <= 1.0 - Cross-Site Scriptingmembership database6.1 (v3.1)Medium346755 , 377360
CVE-2023-0948WordPress Japanized for WooCommerce <2.5.8 - Cross-Site Scriptingjapanized for woocommerce6.1 (v3.1)Medium341266 , 346755
CVE-2023-30013TOTOLink - Unauthenticated Command Injectionx5000r firmware9.8 (v3.1)Critical392301
CVE-2023-32235Ghost CMS < 5.42.1 - Path Traversalghost7.5 (v3.1)High390703
CVE-2023-29827Embedded JavaScript(EJS) 3.1.6 - Template Injectionejs9.8 (v3.1)Critical340014 , 340193 , 344370 , 345240 , 380026
CVE-2023-25826OpenTSDB <= 2.4.1 - Unauthenticated RCE via Gnuplot Injectionopentsdb9.8 (v3.1)Critical340029 , 344363 , 390722
CVE-2023-1730SupportCandy < 3.1.5 - Unauthenticated SQL Injectionsupportcandy9.8 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2023-2479Appium Desktop Server - Remote Code Executionappium-desktop9.8 (v3.1)Critical342259
CVE-2023-30869Easy Digital Downloads - Privilege Escalationeasy digital downloads9.8 (v3.1)Critical377360
CVE-2023-1546MyCryptoCheckout < 2.124 - Cross-Site Scriptingmycryptocheckout6.1 (v3.1)Medium341266 , 346755
CVE-2023-30943Moodle - Cross-Site Scripting/Remote Code Executionmoodle5.3 (v3.1)Medium333141 , 340007 , 340099 , 340147 , 340148 , 340149 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-2356Mlflow <2.3.0 - Local File Inclusionmlflow7.5 (v3.1)High340007
CVE-2023-29489cPanel < 11.109.9999.116 - Cross-Site Scriptingcpanel6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755
CVE-2023-30210OURPHP <= 7.2.0 - Cross Site Scriptingourphp6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2023-30212OURPHP <= 7.2.0 - Cross Site Scriptingourphp6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-26947Odoo <= 15.0 - Cross-Site Scriptingodoo6.1 (v3.1)Medium333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198
CVE-2023-25346ChurchCRM 4.5.3 - Cross-Site Scriptingchurchcrm6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-26843ChurchCRM 4.5.3 - Cross-Site Scriptingchurchcrm5.4 (v3.1)Medium333141
CVE-2023-1020Steveas WP Live Chat Shoutbox <= 1.4.2 - SQL Injectionwp live chat shoutbox9.8 (v3.1)Critical340016 , 340017 , 340144 , 360147 , 360148
CVE-2023-31059Repetier Server - Directory Traversalrepetier-server7.5 (v3.1)High344365 , 347019
CVE-2023-1892Sidekiq < 7.0.8 - Cross-Site Scriptingsidekiq9.6 (v3.1)Critical333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-27350PaperCut - Unauthenticated Remote Code Executionpapercut mf9.8 (v3.1)Critical390727 , 392648
CVE-2023-29887Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusionspreadsheet-reader7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2022-45836WordPress Download Manager <= 3.2.59 - Reflected XSSdownload manager6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755
CVE-2023-2130Purchase Order Management v1.0 - SQL Injectionpurchase order management system9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2022-34128GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)positions9.8 (v3.1)Critical392301
CVE-2022-34127GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities pluginmanageentities7.5 (v3.1)High340007 , 344360
CVE-2022-38840Güralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE)man-eam-00037.5 (v3.1)High344360 , 344370 , 344372 , 380018
CVE-2022-34125GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugincmdb6.5 (v3.1)Medium340007 , 344360
CVE-2023-29506XWiki >= 13.10.8 - Cross-Site Scriptingxwiki6.1 (v3.1)Medium346755
CVE-2022-43128Dreamer CMS v4.0.0 - SQL Injection-N/AN/A340016 , 340156 , 380026 , 380122
CVE-2022-48178X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)x2crm5.4 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 390585
CVE-2022-47501Apache OFBiz < 18.12.07 - Local File Inclusionofbiz7.5 (v3.1)High340165 , 344360 , 347009
CVE-2023-29623Purchase Order Management v1.0 - Cross Site Scripting (Reflected)purchase order management6.1 (v3.1)Medium333141 , 340147 , 340148 , 342259 , 346755
CVE-2023-2059DedeCMS 5.7.87 - Directory Traversaldedecms5.3 (v3.1)Medium340007 , 347019
CVE-2023-26067Lexmark Printers - Command Injectioncxtpc firmware8.1 (v3.1)High392301
CVE-2023-1880Phpmyfaq v3.1.11 - Cross-Site Scriptingphpmyfaq6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-27167Suprema BioStar 2 v2.8.16 - SQL Injectionbiostar 26.5 (v3.1)Medium330791 , 340152 , 341145 , 380026 , 380122
CVE-2023-27008ATutor < 2.2.1 - Cross Site Scriptingatutor6.1 (v3.1)Medium344363 , 346755 , 350148
CVE-2023-27847PrestaShop xipblog - SQL Injectionxipblog9.8 (v3.1)Critical340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2023-26802DCBI-Netlog-LAB v1.0 - Command Injectiondcbi-netlog-lab firmware9.8 (v3.1)Critical344361 , 344363
CVE-2023-1177Mlflow <2.2.1 - Local File Inclusionmlflow9.8 (v3.1)Critical398008
CVE-2023-27034Jms Blog - SQL Injectionjms blog9.8 (v3.1)Critical380122
CVE-2023-26360Adobe ColdFusion - Local File Readcoldfusion8.6 (v3.1)High340007 , 344360 , 390709
CVE-2023-24367Temenos T24 R20 - Cross-Site Scriptingt246.1Medium341266
CVE-2023-27637PrestaShop tshirtecommerce Module - SQL Injectioncustom product designer9.8 (v3.1)Critical341245 , 344366 , 380026 , 380122
CVE-2023-27638tshirtecommerce PrestaShop Module - SQL Injectionprestashop9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2023-28665Woo Bulk Price Update <2.2.2 - Cross-Site Scriptingbulk price update for woocommerce5.4 (v3.1)Medium347198
CVE-2023-0630Slimstat Analytics < 4.9.3.3 Subscriber - SQL Injectionslimstat analytics8.8 (v3.1)High340016 , 340017 , 360147 , 360148 , 380122
CVE-2023-24278Squidex <7.4.0 - Cross-Site Scriptingsquidex6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2023-1454Jeecg-boot 3.5.0 qurestSql - SQL Injectionjeecg boot9.8 (v3.1)Critical340157 , 340159 , 360147 , 360148
CVE-2023-25280D-Link DIR820LA1_FW105B03 'ping_addr' - OS Command Injectiondir820la1 firmware9.8 (v3.1)Critical340014 , 344364 , 344366
CVE-2023-1389TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injectionarcher-ax218.8 (v3.1)High393655
CVE-2023-28343Altenergy Power Control Software C1.2.5 - Remote Command Injectionenergy communication unit firmware9.8 (v3.1)Critical344364
CVE-2023-0037WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injectionmap builder for google maps9.8 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2022-31474BackupBuddy - Local File Inclusionbackupbuddy7.5 (v3.1)High344360 , 347009 , 390709
CVE-2023-1315osTicket < v1.16.6 - Cross-Site Scriptingosticket5.4 (v3.1)Medium341266 , 346755
CVE-2023-1317osTicket < v1.16.6 - Cross-Site Scriptingosticket5.4 (v3.1)Medium340099 , 341099 , 347198
CVE-2023-1318osTicket < v1.16.6 - Cross-Site Scriptingosticket5.4 (v3.1)Medium341266 , 346755
CVE-2023-24657phpIPAM - 1.6 - Cross-Site Scriptingphpipam6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-1211phpIPAM 1.5.1 - SQL Injectionphpipam7.2 (v3.1)High341245 , 344366 , 344370 , 380026 , 380122
CVE-2022-4328WooCommerce Checkout Field Manager < 18.0 - Arbitrary File Uploadwoocommerce checkout field manager9.8 (v3.1)Critical382238
CVE-2023-24733PMB 7.4.6 - Cross-Site Scriptingpmb6.1 (v3.1)Medium340147 , 341266 , 342259 , 350148
CVE-2023-24737PMB v7.4.6 - Cross-Site Scriptingpmb6.1 (v3.1)Medium340147 , 341266 , 342259 , 350148
CVE-2023-27641L-Soft LISTSERV 16.5 - Cross-Site Scriptinglistserv6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-0968WordPress Watu Quiz <3.3.9.1 - Cross-Site Scriptingwatu quiz6.1 (v3.1)Medium346755 , 347198
CVE-2023-26256STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusionstagil navigation7.5 (v3.1)High344360 , 347009 , 390709
CVE-2023-1080WordPress GN Publisher <1.5.6 - Cross-Site Scriptinggn publisher6.1 (v3.1)Medium346755 , 347198
CVE-2023-0334ShortPixel Adaptive Images < 3.6.3 - Cross Site Scriptingshortpixel adaptive images6.1 (v3.1)Medium340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2023-26035ZoneMinder Snapshots - Command Injectionzoneminder9.8 (v3.1)Critical344364 , 344366
CVE-2023-0961Music Gallery Site v1.0 - SQL Injection on page view_music_details.phpmusic gallery site9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2023-0962Music Gallery Site v1.0 - SQL Injection on page Master.phpmusic gallery site8.8 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148 , 390727 , 392301 , 392648
CVE-2023-23063Cellinx NVT Web Server - Local File Disclosurenvt web server7.5 (v3.1)High344360 , 347009 , 390709
CVE-2023-0938Music Gallery Site v1.0 - SQL Injection on music_list.phpmusic gallery site9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 360147 , 360148 , 390727 , 392301 , 392648
CVE-2022-4897WordPress BackupBuddy <8.8.3 - Cross Site Scriptingbackupbuddy6.1 (v3.1)Medium341266 , 346755 , 347198
CVE-2023-0942WordPress Japanized for WooCommerce <2.5.5 - Cross-Site Scriptingjapanized for woocommerce6.1 (v3.1)Medium341266 , 346755 , 347198
CVE-2021-32853Erxes <0.23.0 - Cross-Site Scriptingerxes9.6 (v3.1)Critical340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-0915Auto Dealer Management System v1.0 - SQL Injection on manage_user.phpauto dealer management system8.8 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2023-0916Auto Dealer Management System 1.0 - Broken Access Control Exploitauto dealer management system8.8 (v3.1)High345493
CVE-2023-0903Employee Task Management System v1.0 - SQL Injection on edit-task.phpemployee task management system8.8 (v3.1)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2023-0904Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)employee task management system8.8 (v3.1)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2023-0912Auto Dealer Management System v1.0 - SQL Injectionauto dealer management system8.8 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2023-0913Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.phpauto dealer management system8.8 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2023-0905Employee Task Management System v1.0 - Broken Authenticationemployee task management system7.5 (v3.1)High344365 , 344370 , 345493 , 350147
CVE-2023-0902Employee Task Management System v1.0 - SQL Injection on edit-task.phpsimple food ordering system5.4 (v3.1)Medium340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-40032Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)simple task managing system9.8 (v3.1)Critical331028 , 340016 , 340145 , 340156 , 340157 , 341145 , 341245 , 345493 , 360147 , 360148 , 380026 , 380122 , 390572 , 393655
CVE-2022-40347Intern Record System v1.0 - SQL Injection (Unauthenticated)intern record system9.8 (v3.1)Critical331028 , 340016 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 390572 , 393655
CVE-2022-47986IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Executionlinux kernel9.8 (v3.1)Critical344364 , 344370
CVE-2022-48323Sunflower Simple and Personal 1.0.1.43315 - Remote Code Executionsunflower9.8 (v3.1)Critical392301
CVE-2023-25717Ruckus Wireless Admin - Remote Code Executionruckus wireless admin9.8 (v3.1)Critical344363 , 393655
CVE-2023-0261WordPress WP TripAdvisor Review Slider <10.8 - Authenticated SQL Injectionwp tripadvisor review slider8.8 (v3.1)High340016 , 380122
CVE-2023-0159Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCEextensive vc addons for wpbakery page builder7.5 (v3.1)High340077 , 344360 , 381206
CVE-2023-0099Simple URLs < 115 - Cross Site Scriptingsimple urls6.1 (v3.1)Medium333141 , 340147 , 340148 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-45699APsystems ECU-R Firmware - Command Injectionecu-r firmware9.8 (v3.1)Critical344364 , 344366
CVE-2023-23161Art Gallery Management System Project v1.0 - Cross-Site Scriptingart gallery management system6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2023-24322mojoPortal 2.7.0.0 - Cross-Site Scriptingmojoportal6.1 (v3.1)Medium346755 , 350148
CVE-2023-23333SolarView Compact 6.00 - OS Command Injectionsolarview compact firmware9.8 (v3.1)Critical344361 , 344363 , 390613 , 390614
CVE-2023-0669Fortra GoAnywhere MFT - Remote Code Executiongoanywhere managed file transfer7.2 (v3.1)High344370
CVE-2022-4321PDF Generator for WordPress < 1.1.2 - Cross Site Scriptingpdf generator for wordpress6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-0236WordPress Tutor LMS <2.0.10 - Cross Site Scriptingtutor lms6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 350147
CVE-2023-0676phpIPAM 1.5.1 - Cross-site Scriptingphpipam6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2023-25135vBulletin <= 5.6.9 - Pre-authentication Remote Code Executionvbulletin9.8 (v3.1)Critical344365 , 390614
CVE-2022-46552D-Link DIR-846 - Remote Command Execution (RCE) vulnerabilitydir-846 firmware8.8 (v3.1)High330791 , 340152 , 381237
CVE-2022-2546WordPress All-in-One WP Migration <=7.62 - Cross-Site Scriptingall-in-one wp migration4.7 (v3.1)Medium377360
CVE-2022-45297EQ Enterprise management system v2.2.0 - SQL Injectioneq9.8 (v3.1)Critical334168 , 341245 , 344370
CVE-2022-4306WordPress Panda Pods Repeater Field <1.5.4 - Cross-Site Scriptingpanda pods repeater field5.4 (v3.1)Medium346755 , 350148
CVE-2023-0562Bank Locker Management System v1.0 - SQL Injectionbank locker management system9.8 (v3.1)Critical340156 , 341145
CVE-2023-0563Bank Locker Management System - Cross-Site Scriptingbank locker management system4.8 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2022-48012OpenCATS 0.9.7 - Cross-Site Scriptingopencats6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755
CVE-2023-0527Online Security Guards Hiring System - Cross-Site Scriptingonline security guards hiring system6.1 (v3.1)Medium333141 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2022-45808LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLilearnpress9.8 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2022-47615LearnPress Plugin < 4.2.0 - Local File Inclusionlearnpress9.8 (v3.1)Critical344360 , 347009 , 390709
CVE-2023-0448WP Helper Lite < 4.3 - Cross-Site Scriptingwp helper premium6.1 (v3.1)Medium346755 , 347198
CVE-2023-23488WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injectionpaid memberships pro9.8 (v3.1)Critical380122
CVE-2023-23489WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injectioneasy digital downloads9.8 (v3.1)Critical340016 , 380122
CVE-2023-23492Login with Phone Number - Cross-Site Scriptinglogin with phone number8.8 (v3.1)High346755 , 347198
CVE-2022-41441ReQlogic v11.3 - Cross Site Scriptingreqlogic6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-23491Quick Event Manager < 9.7.5 - Cross-Site Scriptingquick event manager6.1 (v3.1)Medium341266 , 346755
CVE-2023-0126SonicWall SMA1000 LFIsma10007.5 (v3.1)High347009
CVE-2022-46888NexusPHP <1.7.33 - Cross-Site Scriptingnexusphp6.1 (v3.1)Medium340147 , 341266 , 342259 , 346755 , 350147 , 350148 , 360030
CVE-2022-39195LISTSERV 17 - Cross-Site Scriptinglistserv6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-4060WordPress User Post Gallery <=2.19 - Remote Code Executionuser post gallery9.8 (v3.1)Critical340087 , 344360 , 347009
CVE-2022-4447WordPress Fontsy <=1.8.6 - SQL Injectionfontsy9.8 (v3.1)Critical340016 , 340017 , 340144 , 360147 , 360148
CVE-2022-4295Show all comments < 7.0.1 - Cross-Site Scriptingshow all comments6.1 (v3.1)Medium341266
CVE-2022-4320WordPress Events Calendar <1.4.5 - Cross-Site Scriptingwordpress events calendar plugin6.1 (v3.1)Medium340748 , 341266 , 346755 , 347006
CVE-2023-0297PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)pyload9.8 (v3.1)Critical340095
CVE-2022-38467CRM Perks Forms < 1.1.1 - Cross Site Scriptingcrm perks forms6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350148 , 390720
CVE-2022-4301WordPress Sunshine Photo Cart <2.9.15 - Cross-Site Scriptingsunshine photo cart6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-4325WordPress Post Status Notifier Lite <1.10.1 - Cross-Site Scriptingpost status notifier lite6.1 (v3.1)Medium341266
CVE-2022-44877Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)webpanel9.8 (v3.1)Critical344364 , 344366 , 393655
CVE-2023-22463KubePi JwtSigKey - Admin Authentication Bypasskubepi9.8 (v3.1)Critical392301
CVE-2022-38627Nortek Linear eMerge E3-Series - SQL Injectionemerge e3 firmware9.8 (v3.1)Critical334073 , 340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2022-4059Cryptocurrency Widgets Pack < 2.0 - SQL Injectioncryptocurrency widgets pack9.8 (v3.1)Critical340016 , 380122
CVE-2022-4140WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Accesswelcart e-commerce7.5 (v3.1)High344360 , 347009 , 390709
CVE-2022-48197Yahoo User Interface library (YUI2) TreeView v2.8.2 - Cross-Site Scriptingyui6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-4260WordPress WP-Ban <1.69.1 - Stored Cross-Site Scriptingwp-ban4.8 (v3.1)Medium377360
CVE-2021-45467Control Web Panel (CWP) - File Inclusionwebpanel9.8 (v3.1)Critical320464 , 320465 , 390613 , 390614
CVE-2022-4117WordPress IWS Geo Form Fields <=1.0 - SQL Injectioniws-geo-form-fields9.8 (v3.1)Critical340016 , 380122
CVE-2021-30134Php-mod/curl Library <2.3.2 - Cross-Site Scriptingphp curl class6.1 (v3.1)Medium333141 , 342259 , 346755 , 347198 , 350148
CVE-2022-42953ZKTeco ZEM/ZMM 8.88 - Missing Authenticationzmm200 firmware7.5 (v3.1)High345493
CVE-2022-47945Thinkphp Lang - Local File Inclusionthinkphp9.8 (v3.1)Critical340007
CVE-2022-23854AVEVA InTouch Access Anywhere Secure Gateway - Local File Inclusionintouch access anywhere7.5 (v3.1)High390716
CVE-2022-4050WordPress JoomSport <5.2.8 - SQL Injectionjoomsport9.8 (v3.1)Critical380122
CVE-2022-44588Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injectioncryptocurrency widgets pack9.8 (v3.1)Critical380122
CVE-2022-46071Helmet Store Showroom v1.0 - SQL Injectionhelmet store showroom site9.8 (v3.1)Critical340145 , 340156 , 341145 , 390572
CVE-2022-46443Bangresto - SQL Injectionbangresto8.8 (v3.1)High340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2022-46073Helmet Store Showroom - Cross Site Scriptinghelmet store showroom6.1 (v3.1)Medium340147 , 341266 , 342259 , 350147 , 350148
CVE-2022-3590WordPress <= 6.2 - Server Side Request ForgeryWordPress5.9 (v3.1)Medium398001
CVE-2022-4223pgAdmin < 6.17 - Unauthenticated Remote Code Executionpgadmin 48.8 (v3.1)High393655
CVE-2022-46381Linear eMerge E3-Series - Cross-Site Scriptinglinear emerge e3 access control firmware6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2022-3982WordPress Booking Calendar <3.2.2 - Arbitrary File Uploadbooking calendar9.8 (v3.1)Critical382238
CVE-2022-3908WordPress Helloprint <1.4.7 - Cross-Site Scriptinghelloprint6.1 (v3.1)Medium341266 , 346755
CVE-2022-3933WordPress Essential Real Estate <3.9.6 - Authenticated Cross-Site Scriptingessential real estate5.4 (v3.1)Medium341266 , 346755
CVE-2022-3934WordPress FlatPM <3.0.13 - Cross-Site Scriptingflat pm5.4 (v3.1)Medium346755 , 347198
CVE-2022-41800F5 BIG-IP Appliance Mode - Command Injectionbig-ip access policy manager8.7 (v3.1)High344362 , 344363
CVE-2022-35507Proxmox - CRLF Injectionproxmox mail gateway7.1 (v3.1)High390714
CVE-2022-44290WebTareas 2.4p5 - SQL Injectionwebtareas9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2022-44291WebTareas 2.4p5 - SQL Injectionwebtareas9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2022-41412perfSONAR 4.x <= 4.4.4 - Server-Side Request Forgeryperfsonar8.6 (v3.1)High340007
CVE-2022-3768WordPress WPSmartContracts <1.3.12 - SQL Injectionwpsmartcontracts8.8 (v3.1)High340016 , 380026 , 380122
CVE-2022-41840Welcart eCommerce <=2.7.7 - Local File Inclusionwelcart e-commerce9.8 (v3.1)Critical340007 , 344360 , 347009 , 390709
CVE-2022-40881SolarView 6.00 - Remote Command Executionsolarview compact9.8 (v3.1)Critical340029 , 344360 , 344370 , 393655
CVE-2022-3980Sophos Mobile managed on-premises - XML External Entity Injectionmobile9.8 (v3.1)Critical344372
CVE-2022-42118Liferay Portal - Cross-site Scriptingliferay portal6.1 (v3.1)Medium340147 , 341266 , 342259 , 350148
CVE-2022-40843Tenda AC1200 V-W15Ev2 - Authentication Bypassac1200 v-w15ev24.9 (v3.1)Medium390716
CVE-2021-40272IRTS OP5 Monitor - Cross-Site Scriptingmonitor6.1 (v3.1)Medium346755 , 347198
CVE-2022-3484WordPress WPB Show Core - Cross-Site Scriptingwpb show core6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2022-3578WordPress ProfileGrid <5.1.1 - Cross-Site Scriptingprofilegrid6.1 (v3.1)Medium341266 , 346755
CVE-2022-44727PrestaShop lgcookieslaw - SQL Injectioneu cookie law gdpr9.1 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2022-3481NotificationX Dropshipping < 4.4 - SQL Injectionwoocommerce dropshipping9.8 (v3.1)Critical340016 , 380026 , 380122
CVE-2022-42746CandidATS 3.0.0 - Cross-Site Scripting.candidats6.1 (v3.1)Medium341266 , 346755
CVE-2022-42747CandidATS 3.0.0 - Cross-Site Scripting.candidats6.1 (v3.1)Medium341266 , 346755
CVE-2022-42748CandidATS 3.0.0 - Cross-Site Scripting.candidats6.1 (v3.1)Medium341266 , 346755
CVE-2022-42749CandidATS 3.0.0 - Cross-Site Scriptingcandidats6.1 (v3.1)Medium341266 , 346755
CVE-2022-3800IBAX - SQL Injectiongo-ibax8.8 (v3.1)High344366
CVE-2022-3254AWP Classifieds <= 4.2.1 - Unauthenticated SQL Injectionawp classifieds9.8 (v3.1)Critical340016 , 340017 , 360147 , 360148
CVE-2021-40661IND780 - Local File Inclusionind780 firmware7.5 (v3.1)High340007 , 390716
CVE-2022-2627WordPress Newspaper < 12 - Cross-Site Scriptingnewspaper6.1 (v3.1)Medium346755
CVE-2022-3766phpMyFAQ < 3.1.8 - Cross-Site Scriptingphpmyfaq6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 350148
CVE-2022-31678VMWare Cloud Foundation NSX-V - XML External Entity (XXE)cloud foundation9.1 (v3.1)Critical344372
CVE-2022-38580X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF)skipper9.8 (v3.1)Critical337110 , 390727 , 392301 , 392648 , 398022
CVE-2022-41358Garage Management System 1.0 (categoriesName) - Stored XSSgarage management system5.4 (v3.1)Medium330791 , 340152
CVE-2022-43014OpenCATS 0.9.6 - Cross-Site Scriptingopencats6.1 (v3.1)Medium341266 , 346755
CVE-2022-43015OpenCATS 0.9.6 - Cross-Site Scriptingopencats6.1 (v3.1)Medium341266
CVE-2022-43016OpenCATS 0.9.6 - Cross-Site Scriptingopencats6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-43017OpenCATS 0.9.6 - Cross-Site Scriptingopencats6.1 (v3.1)Medium341266 , 346755
CVE-2022-43018OpenCATS 0.9.6 - Cross-Site Scriptingopencats6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 346755
CVE-2022-22242Juniper Web Device Manager - Cross-Site Scriptingjunos6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-3552BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)boxbilling7.2 (v3.1)High340128 , 380018
CVE-2022-3506WordPress Related Posts <2.1.3 - Stored Cross-Site Scriptingrelated posts5.4 (v3.1)Medium377360
CVE-2022-41473RPCMS 3.0.2 - Cross-Site Scriptingrpcms6.1 (v3.1)Medium340147 , 341266 , 342259 , 350148
CVE-2022-35155Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)bus pass management system6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 345493 , 346755 , 390585
CVE-2022-3062Simple File List < 4.4.12 - Cross Site Scriptingsimple-file-list6.1 (v3.1)Medium333141 , 346755 , 347198
CVE-2022-38553Academy Learning Management System <5.9.1 - Cross-Site Scriptingacademy learning management system6.1 (v3.1)Medium340147 , 341266 , 342259 , 350147 , 350148
CVE-2022-3236Sophos Firewall <= 19.0 MR1 - Remote Code Executionfirewall9.8 (v3.1)Critical344361 , 344364
CVE-2022-40359Kae's File Manager <=1.4.7 - Cross-Site Scriptingkfm6.1 (v3.1)Medium340147 , 341266 , 346755
CVE-2022-3242Microweber <1.3.2 - Cross-Site Scriptingmicroweber6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-2840Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLizephyr project manager9.8 (v3.1)Critical340016 , 340017 , 340144 , 341155 , 360147 , 360148 , 380122
CVE-2022-35914GLPI <=10.0.2 - Remote Command Executionglpi9.8 (v3.1)Critical340023 , 344360
CVE-2022-3142NEX-Forms Plugin < 7.9.7 - SQL Injectionnex-forms8.8 (v3.1)High380122
CVE-2022-2863WordPress WPvivid Backup <0.9.76 - Local File Inclusionmigration, backup, staging4.9 (v3.1)Medium377360
CVE-2022-40734Laravel Filemanager v2.5.1 - Local File Inclusionlaravel filemanager6.5 (v3.1)Medium340007
CVE-2022-38637Hospital Management System 1.0 - SQL Injectionhospital management system9.8 (v3.1)Critical340145 , 340156 , 341145
CVE-2022-38295Cuppa CMS v1.0 - Cross Site Scriptingcuppacms6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2022-37299Shirne CMS 1.2.0 - Local File Inclusionshirne cms6.5 (v3.1)Medium340077 , 340162 , 340165 , 344360 , 347009
CVE-2022-27593QNAP QTS Photo Station External Reference - Local File Inclusionphoto station9.1 (v3.1)Critical340007
CVE-2022-2633All-In-One Video Gallery <=2.6.0 - Server-Side Request Forgeryall-in-one video gallery8.2 (v3.1)High340163
CVE-2022-36642Omnia MPX 1.5.0+r1 - Local File Inclusionomnia mpx node firmware9.8 (v3.1)Critical340007 , 344360 , 347009
CVE-2022-37122Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversalpcoweb hvac bacnet gateway7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2022-38812AeroCMS 0.1.1 - SQL Injectionaerocms6.5 (v3.1)Medium340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2022-22897PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injectionap pagebuilder9.8 (v3.1)Critical340156 , 341145 , 341245 , 380026 , 380122
CVE-2022-36553Hytec Inter HWL-2511-SS - Remote Command Executionhwl-2511-ss firmware9.8 (v3.1)Critical344360 , 347009 , 390904
CVE-2022-2599WordPress Anti-Malware Security and Brute-Force Firewall <4.21.83 - Cross-Site Scriptinganti-malware security and brute-force firewall6.1 (v3.1)Medium341266 , 346755 , 347198
CVE-2022-38794Zaver - Local File Inclusionzaver7.5 (v3.1)High347009
CVE-2022-31499Nortek Linear eMerge E3-Series <0.32-08f - Remote Command Injectionemerge e3 firmware9.8 (v3.1)Critical344364 , 344366
CVE-2022-31798Nortek Linear eMerge E3-Series - Cross-Site Scriptingemerge e3 firmware6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198
CVE-2022-37153Artica Proxy 4.30.000000 - Cross-Site Scriptingartica proxy6.1 (v3.1)Medium340147 , 340148 , 342259 , 346755
CVE-2022-38463ServiceNow - Cross-Site Scriptingservicenow6.1 (v3.1)Medium346755 , 350148
CVE-2021-24910WordPress Transposh Translation <1.0.8 - Cross-Site Scriptingtransposh wordpress translation6.1 (v3.1)Medium340099 , 341099 , 347198
CVE-2022-2383WordPress Feed Them Social <3.0.1 - Cross-Site Scriptingfeed them social6.1 (v3.1)Medium346755 , 347198
CVE-2022-32770WWBN AVideo 11.6 - Cross-Site Scriptingavideo6.1 (v3.1)Medium333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-32771WWBN AVideo 11.6 - Cross-Site Scriptingavideo6.1 (v3.1)Medium333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-32772WWBN AVideo 11.6 - Cross-Site Scriptingavideo6.1 (v3.1)Medium333140 , 340147 , 341266 , 342259
CVE-2022-37042Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Executioncollaboration9.8 (v3.1)Critical340007 , 390614 , 390626
CVE-2022-2733Openemr < 7.0.0.1 - Cross-Site Scriptingopenemr6.1 (v3.1)Medium333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2022-35493eShop 3.0.4 - Cross-Site Scriptingeshop - ecommerce / store website6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-1950Youzify < 1.2.0 - Unauthenticated SQLiyouzify9.8 (v3.1)Critical340016 , 380122
CVE-2022-31181PrestaShop - SQL Injection to Eval Injectionprestashop9.8 (v3.1)Critical340157 , 340159 , 341245 , 344362 , 360147 , 360148 , 390704
CVE-2022-31188CVAT 2.0 - Server Side Request Forgerycomputer vision annotation tool9.8 (v3.1)Critical345493
CVE-2022-1906WordPress Copyright Proof <=4.16 - Cross-Site-Scriptingcopyright proof6.1 (v3.1)Medium341266 , 346755
CVE-2022-2414FreeIPA - XML Entity Injectiondogtagpki7.5 (v3.1)High344372
CVE-2022-34140Feehi CMS 2.1.1 - Remote Code Execution (Authenticated)feehi cms5.4 (v3.1)Medium330791 , 340152 , 345493
CVE-2022-34121CuppaCMS v1.0 - Local File Inclusioncuppacms7.5 (v3.1)High340007 , 344360 , 390709
CVE-2022-33965WordPress Visitor Statistics <=5.7 - SQL Injectionwp visitor statistics9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2022-36446Webmin <1.997 - Authenticated Remote Code Executionwebmin9.8 (v3.1)Critical392301
CVE-2022-2219Unyson < 2.7.27 - Cross Site Scriptingunyson7.2 (v3.1)High341266 , 346755
CVE-2022-0899Header Footer Code Manager < 1.1.24 - Cross-Site Scriptingheader footer code manager6.1 (v3.1)Medium341266 , 346755
CVE-2022-35653Moodle LTI module Reflected - Cross-Site Scriptingmoodle6.1 (v3.1)Medium333141 , 342259 , 346755 , 350147 , 350148
CVE-2022-33901WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Readmultisafepay plugin for woocommerce7.5 (v3.1)High340748 , 344360 , 347006 , 347009 , 390709
CVE-2022-29495WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgerypopup builder4.3 (v3.1)Medium345490 , 377360
CVE-2022-28666Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Updatecustom product tabs for woocommerce5.3 (v3.1)Medium392301
CVE-2022-2486Wavlink WN535K2/WN535K3 - OS Command Injectionwl-wn535k29.8 (v3.1)Critical340014 , 340193 , 344364 , 344366 , 344370
CVE-2022-2488Wavlink WN535K2/WN535K3 - OS Command Injectionwl-wn535k2 firmware9.8 (v3.1)Critical340014 , 340193 , 344364 , 344366
CVE-2022-34045WAVLINK WN530HG4 - Improper Access Controlwl-wn530hg4 firmware9.8 (v3.1)Critical390716
CVE-2022-34590Hospital Management System 1.0 - SQL Injectionhospital management system7.2 (v3.1)High340145 , 340156
CVE-2022-34048Wavlink WN-533A8 - Cross-Site Scriptingwn533a8 firmware6.1 (v3.1)Medium392301
CVE-2022-2467Garage Management System 1.0 - SQL Injectiongarage management system9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2022-35405Zoho ManageEngine - Remote Code Executionmanageengine access manager plus9.8 (v3.1)Critical392301
CVE-2022-33891Apache Spark UI - Remote Command Injectionspark8.8 (v3.1)High344361 , 344363
CVE-2021-40150Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosuree1 zoom firmware7.5 (v3.1)High390716
CVE-2022-1933WordPress CDI <5.1.9 - Cross Site Scriptingcollect and deliver interface for woocommerce6.1 (v3.1)Medium341266 , 346755
CVE-2022-2168WordPress Download Manager < 3.2.44 - Authenticated Cross-Site Scriptingdownload manager6.1 (v3.1)Medium340148 , 341266 , 346755
CVE-2022-2187WordPress Contact Form 7 Captcha <0.1.2 - Cross-Site Scriptingcontact form 7 captcha6.1 (v3.1)Medium341266 , 346755
CVE-2021-40149Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosuree1 zoom5.9 (v3.1)Medium390716
CVE-2022-32409Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusioni3geo9.8 (v3.1)Critical340007 , 344360 , 347009 , 390709
CVE-2022-34093Software Publico Brasileiro i3geo v7.0.5 - Cross-Site Scriptingi3geo6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-34094Software Publico Brasileiro i3geo v7.0.5 - Cross-Site Scriptingi3geo6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-1057WordPress Pricing Deals for WooCommerce <=2.0.2.02 - SQL Injectionpricing deals for woocommerce9.8 (v3.1)Critical340016 , 340017 , 360147 , 360148 , 380122
CVE-2022-1952WordPress eaSYNC Booking <1.1.16 - Arbitrary File Uploadfree booking plugin for hotels, restaurant and car rental9.8 (v3.1)Critical382238
CVE-2022-1910WordPress Shortcodes and Extra Features for Phlox <2.9.8 - Cross-Site Scriptingshortcodes and extra features for phlox theme6.1 (v3.1)Medium341266 , 346755
CVE-2022-1937WordPress Awin Data Feed <=1.6 - Cross-Site Scriptingawin data feed6.1 (v3.1)Medium341266 , 346755
CVE-2022-35416H3C SSL VPN <=2022-07-10 - Cross-Site Scriptingssl vpn6.1 (v3.1)Medium342259 , 346755
CVE-2022-31137Roxy-WI < 6.1.1.0 - Remote Code Executionroxy-wi9.8 (v3.1)Critical340023 , 340029 , 344360 , 344361 , 344363
CVE-2022-0250Redirection for Contact Form 7 < 2.5.0 - Cross-Site Scriptingredirection for contact form 76.1 (v3.1)Medium341266 , 346755
CVE-2022-1946WordPress Gallery <2.0.0 - Cross-Site Scriptinggallery6.1 (v3.1)Medium341266 , 346755
CVE-2022-2290Trilium <0.52.4 - Cross-Site Scriptingtrilium6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2022-32094Hospital Management System 1.0 - SQL Injectionhospital management system9.8 (v3.1)Critical340145 , 340156 , 341145
CVE-2022-31056GLPI v10.0.2 - SQL Injection (Authentication Depends on Configuration)glpi9.8 (v3.1)Critical330791 , 340152
CVE-2021-41460ECShop 4.1.0 - SQL Injectionecshop7.5 (v3.1)High340157 , 340159 , 360147 , 360148
CVE-2022-1574WordPress HTML2WP <=1.0.0 - Arbitrary File Uploadhtml2wp9.8 (v3.1)Critical382238
CVE-2022-1904WordPress Easy Pricing Tables <3.2.1 - Cross-Site Scriptingeasy pricing tables6.1 (v3.1)Medium341266 , 346755
CVE-2022-1916WordPress Active Products Tables for WooCommerce <1.0.5 - Cross-Site Scriptingwoot6.1 (v3.1)Medium346755
CVE-2022-1029Limit Login Attempts - Stored Cross-Site Scriptinglimit login attempts4.8 (v3.1)Medium377360
CVE-2022-34305Apache Tomcat Examples Web Application - Cross-Site Scriptingtomcat6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2022-34328PMB 7.3.10 - Cross-Site Scriptingpmb6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-29299SolarView Compact 6.00 - 'time_begin' Cross-Site Scriptingsolarview compact firmwareN/AN/A341266
CVE-2022-29301SolarView Compact 6.00 - 'pow' Cross-Site Scripting-N/AN/A341266
CVE-2022-2174microweber 1.2.18 - Cross-site Scriptingmicroweber6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-31373SolarView Compact 6.00 - Cross-Site Scriptingsv-cpt-mc310 firmware6.1 (v3.1)Medium341266
CVE-2022-33119NUUO NVRsolo Video Recorder 03.06.02 - Cross-Site Scriptingnvrsolo firmware6.1 (v3.1)Medium340003 , 340158 , 342259
CVE-2021-25104WordPress Ocean Extra <1.9.5 - Cross-Site Scriptingocean extra6.1 (v3.1)Medium340147 , 340148 , 341266 , 346755
CVE-2022-2130Microweber < 1.2.17 - Cross-Site Scriptingmicroweber6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-31062GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusionglpi inventory5.3 (v3.1)Medium340007 , 344360
CVE-2022-31299Haraj 3.7 - Cross-Site Scriptingharaj6.1 (v3.1)Medium340147 , 341266
CVE-2022-0786WordPress KiviCare <2.3.9 - SQL Injectionkivicare9.8 (v3.1)Critical340016 , 380122
CVE-2022-0827WordPress Best Books <=2.6.3 - SQL Injectionbestbooks9.8 (v3.1)Critical340156 , 380122
CVE-2022-1768WordPress RSVPMaker <=9.3.2 - SQL Injectionrsvpmaker7.5 (v3.1)High341245 , 380026 , 380122
CVE-2022-1724WordPress Simple Membership <4.1.1 - Cross-Site Scriptingsimple membership6.1 (v3.1)Medium341266 , 346755
CVE-2022-1756Newsletter < 7.4.5 - Cross-Site Scriptingnewsletter6.1 (v3.1)Medium346755 , 347198
CVE-2021-41749CraftCMS SEOmatic - Server-Side Template Injectionseomatic9.8 (v3.1)Critical390719
CVE-2022-29013Razer Sila Gaming Router - Remote Code Executionsila9.8 (v3.1)Critical392301
CVE-2022-29014Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusionsila firmware7.5 (v3.1)High344360
CVE-2022-32195Open edX <2022-06-06 - Cross-Site Scriptingopen edx6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755
CVE-2022-0788WordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL Injectionwp fundraising donation and crowdfunding platform9.8 (v3.1)Critical340016 , 380026 , 380122 , 390727 , 392648
CVE-2022-1597WordPress WPQA <5.4 - Cross-Site Scriptingwpqa builder6.1 (v3.1)Medium346755
CVE-2021-37589Virtua Software Cobranca 12S - SQLicobranca7.5 (v3.1)High340156 , 341145 , 341245
CVE-2022-31470Axigen WebMail - Cross-Site Scriptingwebmail6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-29296Avantune Genialcloud ProJ 10 - Cross-Site Scripting (XSS)genialcloud proj6.1 (v3.1)Medium344370
CVE-2022-26134Confluence - Remote Code Executionconfluence data center9.8 (v3.1)Critical337209 , 337211 , 340087
CVE-2022-31340simple inventory system SQL Injection Vulnerabilitysimple inventory system9.8 (v3.1)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2022-31976Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2022-31977Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2022-31978Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2022-31339simple inventory system SQL Injection Vulnerabilitysimple inventory system7.2 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2022-31974Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-31975Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-31984Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system7.2 (v3.1)High340016 , 340017 , 340144 , 340157 , 360147 , 360148
CVE-2022-32007Complete Online Job Search System 1.0 - SQL Injectioncomplete online job search system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-32015Complete Online Job Search System 1.0 - SQL Injectioncomplete online job search system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-32018Complete Online Job Search System 1.0 - SQL Injectioncomplete online job search system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-32022Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High340156
CVE-2022-32024Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-32025Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-32026Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-32028Car Rental Management System 1.0 - SQL Injectioncar rental management system7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-30513School Dormitory Management System 1.0 - Authenticated Cross-Site Scriptingschool dormitory management system6.1 (v3.1)Medium392301
CVE-2022-30514School Dormitory Management System 1.0 - Authenticated Cross-Site Scriptingschool dormitory management system6.1 (v3.1)Medium346755 , 392301
CVE-2022-26833Open Automation Software OAS Platform V16.00.0121 - Missing Authenticationoas platform9.4 (v3.1)Critical390726 , 392647
CVE-2022-1883Terraboard <2.2.0 - SQL Injectionterraboard8.8 (v3.1)High341245
CVE-2022-0781WordPress Nirweb Support <2.8.2 - SQL Injectionnirweb support9.8 (v3.1)Critical340016 , 340017 , 340144 , 360147 , 360148
CVE-2022-0346WordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code Executionxml sitemap generator6.1 (v3.1)Medium333141 , 340165 , 341256 , 342259 , 344370 , 346755 , 347198 , 350148
CVE-2022-1221WordPress Gwyn's Imagemap Selector <=0.3.3 - Cross-Site Scriptinggwyn&#x27;s imagemap selector6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-29004Diary Management System 1.0 - Cross-Site Scriptinge-diary management system6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755
CVE-2022-29005Online Birth Certificate System 1.2 - Stored Cross-Site Scriptingonline birth certificate system6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2022-0867WordPress ARPrice <3.6.1 - SQL Injectionpricing table9.8 (v3.1)Critical340016 , 380122
CVE-2022-1398External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request Forgeryexternal media without import6.5 (v3.1)Medium377360
CVE-2022-30776Atmail 6.5.0 - Cross-Site Scriptingatmail6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755
CVE-2022-30777Parallels H-Sphere 3.6.1713 - Cross-Site Scriptingh-sphere6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-0873WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scriptinggmedia gallery4.8 (v3.1)Medium377360
CVE-2022-29383NETGEAR ProSafe SSL VPN firmware - SQL Injectionssl312 firmware9.8 (v3.1)Critical340156 , 341145 , 341245
CVE-2022-30489Wavlink WN-535G3 - Cross-Site Scriptingwn535g3 firmware6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2022-29303SolarView Compact 6.0 - OS Command Injectionsv-cpt-mc310 firmware9.8 (v3.1)Critical340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 393655
CVE-2022-30525Zyxel Firewall - OS Command Injectionusg flex 100w firmware9.8 (v3.1)Critical344363
CVE-2022-29298SolarView Compact 6.00 - Local File Inclusionsv-cpt-mc310 firmware7.5 (v3.1)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2022-29006Directory Management System 1.0 - SQL Injectiondirectory management system9.8 (v3.1)Critical340145 , 340156
CVE-2022-29007Dairy Farm Shop Management System 1.0 - SQL Injectiondairy farm shop management system9.8 (v3.1)Critical340145 , 340156 , 341145
CVE-2022-29316Complete Online Job Search System 1.0 - Cross-Site Scriptingcomplete online job search system9.8 (v3.1)Critical340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2022-1453RSVPMaker <= 9.2.5 - SQL Injectionrsvpmaker7.5 (v3.1)High340016 , 341245 , 380026 , 380122
CVE-2022-0592MapSVG < 6.2.20 - Unauthenticated SQLimapsvg9.8 (v3.1)Critical340016 , 380026 , 380122
CVE-2022-0814Ubigeo de Peru < 3.6.4 - SQL Injectionubigeo de peru para woocommerce9.8 (v3.1)Critical340016 , 340017 , 340144 , 360147 , 360148
CVE-2022-0817WordPress BadgeOS <=3.7.0 - SQL Injectionbadgeos9.8 (v3.1)Critical340016 , 340017 , 340144 , 360147 , 360148
CVE-2022-0826WordPress WP Video Gallery <=1.7.1 - SQL Injectionwp-video-gallery-free9.8 (v3.1)Critical340016 , 380122
CVE-2022-0948WordPress Order Listener for WooCommerce <3.2.2 - SQL Injectionorder listener for woocommerce9.8 (v3.1)Critical380026 , 380122
CVE-2022-1013WordPress Personal Dictionary <1.3.4 - Blind SQL Injectionpersonal dictionary9.8 (v3.1)Critical340016 , 380122
CVE-2022-27412Explore CMS 1.0 - SQL Injectionexplore cms9.8 (v3.1)Critical340145 , 340156 , 341145 , 390572
CVE-2022-24899Contao <4.13.3 - Cross-Site Scriptingcontao6.1 (v3.1)Medium341266
CVE-2022-1388F5 BIG-IP iControl - REST Auth Bypass RCEbig-ip access policy manager9.8 (v3.1)Critical344361 , 392767
CVE-2022-28079College Management System 1.0 - 'course_code' SQL Injection (Authenticated)college management system8.8 (v3.1)High340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 345493 , 360147 , 360148 , 390572
CVE-2022-28080Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)event management system8.8 (v3.1)High330791 , 340016 , 340017 , 340144 , 340145 , 340152 , 340156 , 340157 , 341145 , 341245 , 345493 , 360147 , 360148 , 390572
CVE-2022-28508MantisBT < 2.25.2 - Cross-Site Scriptingmantisbt6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-0773Documentor <= 1.5.3 - Unauthenticated SQL Injectiondocumentor9.8 (v3.1)Critical340016 , 380122
CVE-2022-0783Multiple Shipping Address Woocommerce < 2.0 - SQL Injectionmultiple shipping addresses for woocommerce9.8 (v3.1)Critical340016 , 380122
CVE-2022-1281Photo Gallery WordPress v1.6.3 - SQL Injectionphoto gallery9.8 (v3.1)Critical340016 , 340017 , 360147 , 360148
CVE-2021-40822Geoserver - Server-Side Request Forgerygeoserver7.5 (v3.1)High340007
CVE-2022-24900Piano LED Visualizer 1.3 - Local File Inclusionpiano led visualizer8.6 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2022-27984Cuppa CMS v1.0 - SQL injectioncuppacms9.8 (v3.1)Critical380026 , 380122
CVE-2022-27985Cuppa CMS v1.0 - SQL injectioncuppacms9.8 (v3.1)Critical340017 , 341245
CVE-2022-26564HotelDruid Hotel Management Software 3.0.3 - Cross-Site Scriptinghoteldruid6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-0693WordPress Master Elements <=8.0 - SQL Injectionmaster elements9.8 (v3.1)Critical340016 , 380122
CVE-2022-0769Users Ultra <= 3.1.0 - SQL Injectionusers ultra9.8 (v3.1)Critical340016 , 380122
CVE-2022-1390WordPress Admin Word Count Column 2.2 - Local File Inclusionadmin word count column9.8 (v3.1)Critical340007 , 344360 , 347009 , 390709
CVE-2022-1391WordPress Cab fare calculator < 1.0.4 - Local File Inclusioncab fare calculator9.8 (v3.1)Critical340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2022-29078Node.js Embedded JavaScript 3.1.6 - Template Injectionejs9.8 (v3.1)Critical340014 , 340193 , 344370 , 345240 , 380026
CVE-2021-25094Wordpress Tatsubuilder <= 3.3.11 - Remote Code Executiontatsu8.1 (v3.1)High382238
CVE-2021-35250SolarWinds Serv-U 15.3 - Directory Traversalserv-u7.5 (v3.1)High340007
CVE-2022-0656uDraw <3.3.3 - Local File Inclusion[web to print shop](vendors/webtoprint/web-to-print-shop.md)7.5 (v3.1)High344360 , 390709
CVE-2022-28290WordPress Country Selector <1.6.6 - Cross-Site Scriptingwordpress country selector6.1 (v3.1)Medium340130 , 346755
CVE-2022-1439Microweber <1.2.15 - Cross-Site Scriptingmicroweber6.1 (v3.1)Medium346755 , 347198 , 350148
CVE-2022-27926Zimbra Collaboration (ZCS) - Cross Site Scriptingcollaboration6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-29548WSO2 - Cross-Site Scriptingapi manager6.1 (v3.1)Medium346755
CVE-2022-27927Microfinance Management System 1.0 - 'customer_number' SQLimicrofinance management system9.8 (v3.1)Critical331028 , 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 390572 , 393655
CVE-2022-1329Elementor Website Builder - Remote Code Executionwebsite builder8.8 (v3.1)High377360
CVE-2022-1119WordPress Simple File List <3.2.8 - Local File Inclusionsimple-file-list7.5 (v3.1)High336461 , 340007 , 344360 , 381206
CVE-2022-0785WordPress Daily Prayer Time <2022.03.01 - SQL Injectiondaily prayer time9.8 (v3.1)Critical340016 , 380122
CVE-2021-25120Easy Social Feed < 6.2.7 - Cross-Site Scriptingeasy social feed6.1 (v3.1)Medium341266 , 346755
CVE-2022-0879Caldera Forms < 1.9.7 - Reflected Cross-Site Scriptingcaldera forms6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 344361 , 344364 , 346755 , 347198 , 350148
CVE-2022-0765WordPress Loco Translate < 2.6.1 - Cross-Site Scriptingloco translate5.4 (v3.1)Medium377360
CVE-2022-27043Yearning - Directory Traversalyearning7.5 (v3.1)High347009 , 347019 , 390709 , 390716
CVE-2021-43287Pre-Auth Takeover of Build Pipelines in GoCDgocd7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2022-24816GeoServer <1.2.2 - Remote Code Executionjai-ext10.0 (v3.1)Critical337209 , 337210 , 337211 , 340121 , 344360 , 344370 , 380026
CVE-2021-31805Apache Struts2 S2-062 - Remote Code Executionstruts9.8 (v3.1)Critical330791 , 340152
CVE-2022-28032Atom CMS v2.0 - SQL Injectionatomcms9.8 (v3.1)Critical380026 , 380122
CVE-2022-28033Atom.CMS 2.0 - SQL Injectionatomcms9.8 (v3.1)Critical380026 , 380122
CVE-2021-37291KevinLAB BEMS 1.0 - SQL Injection4st l-bems9.8 (v3.1)Critical340156 , 341245
CVE-2022-0949WordPress Stop Bad Bots <6.930 - SQL Injectionblock and stop bad bots9.8 (v3.1)Critical380122
CVE-2022-22954VMware Workspace ONE Access - Server-Side Template Injectionidentity manager9.8 (v3.1)Critical344360 , 344361 , 344363 , 344370 , 393655
CVE-2021-24987WordPress Super Socializer <7.13.30 - Cross-Site Scriptingsuper socializer6.1 (v3.1)Medium340099 , 341099 , 346755 , 347198
CVE-2022-0271LearnPress <4.1.6 - Cross-Site Scriptinglearnpress6.1 (v3.1)Medium340099 , 341099 , 346755 , 347198
CVE-2022-1007WordPress Advanced Booking Calendar <1.7.1 - Cross-Site Scriptingadvanced booking calendar6.1 (v3.1)Medium341266 , 346755
CVE-2022-28363Reprise License Manager 14.2 - Cross-Site Scriptingreprise license manager6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2021-43421Studio-42 elFinder <2.1.60 - Arbitrary File Uploadelfinder9.8 (v3.1)Critical393781
CVE-2021-46419Telesquare TLR-2855KS6 - Arbitrary File Deletiontlr-2855ks6 firmware9.1 (v3.1)Critical392301 , 393134
CVE-2021-46417Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI)colibri firmware7.5 (v3.1)High340007 , 344360 , 347009
CVE-2021-46418Telesquare TLR-2855KS6 - Arbitrary File Creationtlr-2855ks67.5 (v3.1)High392301
CVE-2022-26585Mingsoft MCMS v5.2.7 - SQL Injectionmcms9.8 (v3.1)Critical340156 , 340157 , 360147 , 360148
CVE-2022-28219Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Executionmanageengine adaudit plus9.8 (v3.1)Critical344370
CVE-2022-25356Alt-n/MDaemon Security Gateway <=8.5.0 - XML Injectionsecuritygateway5.3 (v3.1)Medium390716
CVE-2022-0864UpdraftPlus < 1.22.9 - Cross-Site Scriptingupdraftplus6.1 (v3.1)Medium341266 , 346755
CVE-2022-1168WordPress WP JobSearch <1.5.1 - Cross-Site Scriptingjobsearch wp job board6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198
CVE-2022-1170JobMonster < 4.5.2.9 - Cross-Site Scriptingjobmonster6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-26233Barco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusioncontrol room management suite7.5 (v3.1)High347019
CVE-2021-26599ImpressCMS < 1.4.3 - SQL Injectionimpresscms9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2022-0479Popup Builder Plugin - SQL Injection and Cross-Site Scriptingpopup builder9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 377360
CVE-2022-0679WordPress Narnoo Distributor <=2.5.1 - Local File Inclusionnarnoo distributor9.8 (v3.1)Critical344360 , 390709
CVE-2022-0784WordPress Title Experiments Free <9.0.1 - SQL Injectiontitle experiments free9.8 (v3.1)Critical340016 , 380122
CVE-2022-0787Limit Login Attempts (Spam Protection) < 5.1 - SQL Injectionlimit login attempts9.8 (v3.1)Critical340016 , 380122
CVE-2022-0846SpeakOut Email Petitions < 2.14.15.1 - SQL Injectionspeakout! email petitions9.8 (v3.1)Critical340016 , 380122
CVE-2022-2627174cmsSE v3.4.1 - Arbitrary File Read74cms7.5 (v3.1)High340007
CVE-2021-43725Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)spotweb6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2022-0599WordPress Mapping Multiple URLs Redirect Same Page <=5.8 - Cross-Site Scriptingmapping multiple urls redirect same page6.1 (v3.1)Medium346755 , 347198
CVE-2021-4191GitLab GraphQL API User Enumerationgitlab5.3 (v3.1)Medium344361 , 344363
CVE-2022-1040Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypasssfos9.8 (v3.1)Critical345493
CVE-2021-20323Keycloak 10.0.0 - 18.0.0 - Cross-Site Scriptingkeycloak6.1 (v3.1)Medium333141 , 341258
CVE-2022-0747Infographic Maker iList < 4.3.8 - SQL Injectioninfographic maker9.8 (v3.1)Critical340016 , 380122
CVE-2022-0760WordPress Simple Link Directory <7.7.2 - SQL injectionsimple link directory9.8 (v3.1)Critical340016 , 380122
CVE-2022-26960elFinder <=2.1.60 - Local File Inclusionelfinder9.1 (v3.1)Critical340007 , 344360 , 347009 , 390709 , 393781
CVE-2022-23347BigAnt Server v5.6.06 - Local File Inclusionbigant server7.5 (v3.1)High340007
CVE-2021-46107Ligeo Archives Ligeo Basics - Server Side Request Forgeryligeo basics7.5 (v3.1)High340162 , 340165 , 344360 , 347009
CVE-2022-25488Atom CMS v2.0 - SQL Injectionatomcms9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 360147 , 360148
CVE-2022-25485Cuppa CMS v1.0 - Local File Inclusioncuppacms7.8 (v3.1)High340007 , 344360 , 390709
CVE-2022-25486Cuppa CMS v1.0 - Local File Inclusioncuppacms7.8 (v3.1)High340007 , 344360 , 390709
CVE-2022-0954Microweber <1.2.11 - Stored Cross-Site Scriptingmicroweber5.4 (v3.1)Medium333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2022-25489Atom CMS v2.0 - Cross-Site Scriptingatomcms5.4 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2022-25497Cuppa CMS v1.0 - Local File Inclusioncuppacms5.3 (v3.1)Medium340007 , 344360 , 390709
CVE-2021-25003WordPress WPCargo Track & Trace <6.9.0 - Remote Code Executionwpcargo track &amp; trace9.8 (v3.1)Critical331324
CVE-2022-0169Photo Gallery by 10Web < 1.6.0 - SQL Injectionphoto gallery9.8 (v3.1)Critical340016 , 340017 , 360147 , 360148
CVE-2022-0658CommonsBooking < 2.6.8 - SQL Injectioncommonsbooking9.8 (v3.1)Critical340016 , 380122
CVE-2021-24940WordPress Persian Woocommerce <=5.8.0 - Cross-Site Scriptingpersian-woocommerce6.1 (v3.1)Medium346755 , 347198
CVE-2022-0147WordPress Cookie Information/Free GDPR Consent Solution <2.0.8 - Cross-Site Scriptingwp-gdpr-compliance6.1 (v3.1)Medium346755 , 347198
CVE-2022-24384SmarterTools SmarterTrack - Cross-Site Scriptingsmartertrack6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147
CVE-2021-24966WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)error log viewer4.9 (v3.1)Medium336461 , 344360 , 381206
CVE-2021-32478Moodle 3.8-3.10.3 - Reflected XSS & Open Redirectmoodle6.1 (v3.1)Medium346755 , 350148
CVE-2022-0928Microweber < 1.2.12 - Stored Cross-Site Scriptingmicroweber5.4 (v3.1)Medium333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-33851WordPress Customize Login Image <3.5.3 - Cross-Site Scriptingcustomize login image5.4 (v3.1)Medium377360
CVE-2022-24716Icinga Web 2 - Arbitrary File Disclosureicinga web 27.5 (v3.1)High347009
CVE-2022-0349WordPress NotificationX <2.3.9 - SQL Injectionnotificationx9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2022-0434WordPress Page Views Count <2.4.15 - SQL Injectionpage view count9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-0439Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injectionemail subscribers &amp; newsletters8.8 (v3.1)High340016 , 377360 , 380122
CVE-2022-0429WP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Cross-Site Scriptingwp cerber security, anti-spam &amp; malware scan6.1 (v3.1)Medium347198
CVE-2022-0533Ditty (formerly Ditty News Ticker) < 3.0.15 - Cross-Site Scriptingditty6.1 (v3.1)Medium333141 , 346755 , 347198
CVE-2022-0535WordPress E2Pdf <1.16.45 - Cross-Site Scriptinge2pdf4.8 (v3.1)Medium377360
CVE-2021-46381DLINK DAP-1620 A1 v1.01 - Directory Traversaldap-1620 firmware7.5 (v3.1)High344360 , 390709 , 390726 , 392301 , 392647
CVE-2022-23397Cedar Gate EZ-NET <= 6.8.0 - Cross-Site Scriptingez-net portal6.1 (v3.1)Medium333141 , 340099 , 340147 , 341099 , 341256 , 346755 , 347198
CVE-2022-22947Spring Cloud Gateway Code Injectionspring cloud gateway10.0 (v3.1)Critical344370 , 393655
CVE-2022-23898MCMS 5.2.5 - SQL Injectionmcms9.8 (v3.1)Critical340156 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-25125MCMS 5.2.4 - SQL Injectionmcms9.8 (v3.1)Critical340157 , 340159 , 341245 , 360147 , 360148
CVE-2021-4039Zyxel NWA-1100-NH - Command Injectionnwa1100-nh firmware9.8 (v3.1)Critical344364 , 344366
CVE-2021-46387Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)zywall 2 plus internet security appliance firmware6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147
CVE-2022-0412WordPress TI WooCommerce Wishlist <1.40.1 - SQL Injectionti woocommerce wishlist9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2020-36510WordPress 15Zine <3.3.0 - Cross-Site Scripting15zine6.1 (v3.1)Medium341266 , 346755
CVE-2021-25112WordPress WHMCS Bridge <6.4b - Cross-Site Scriptingwhmcs bridge6.1 (v3.1)Medium346755 , 347198
CVE-2022-0189WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scriptingwp rss aggregator6.1 (v3.1)Medium346755 , 377360
CVE-2022-0377WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaminglearnpress4.3 (v3.1)Medium340007 , 345493
CVE-2021-44567RosarioSIS 7.6 - SQL Injectionrosariosis9.8 (v3.1)Critical392301
CVE-2022-25082TOTOLink - Unauthenticated Command Injectiona950rg firmware9.8 (v3.1)Critical344361 , 344363
CVE-2020-27467Processwire CMS <2.7.1 - Local File Inclusionprocesswire7.5 (v3.1)High344360 , 347009 , 390709
CVE-2022-0653Wordpress Profile Builder Plugin Cross-Site Scriptingprofile builder6.1 (v3.1)Medium340112
CVE-2021-25082WordPress Popup Builder < 4.0.7 - Remote Code Executionpopup builder8.8 (v3.1)High340162 , 340165 , 377360 , 390904 , 398007
CVE-2022-0228Popup Builder < 4.0.7 - SQL Injectionpopup builder7.2 (v3.1)High340017 , 380026 , 380122
CVE-2021-25055WordPress FeedWordPress < 2022.0123 - Authenticated Cross-Site Scriptingfeedwordpress6.1 (v3.1)Medium340099 , 341099 , 346755 , 347198
CVE-2022-0234WordPress WOOCS < 1.3.7.5 - Cross-Site Scriptingwoocs6.1 (v3.1)Medium346755 , 347198
CVE-2021-25075WordPress Duplicate Page or Post <1.5.1 - Cross-Site Scriptingduplicate page or post3.5 (v3.1)Low346755 , 377360
CVE-2022-0678Microweber <1.2.11 - Cross-Site Scriptingmicroweber6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-0666Microweber < 1.2.11 - CRLF Injectionmicroweber7.5 (v3.1)High330708 , 390722
CVE-2022-25323ZEROF Web Server 2.0 - Cross-Site Scriptingweb server6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2021-45382D-Link - Remote Command Executiondir-820l firmware9.8 (v3.1)Critical392301
CVE-2022-24086Adobe Commerce (Magento) - Remote Code Executioncommerce9.8 (v3.1)Critical344360 , 344370
CVE-2022-25241FileCloud 21.2 - Cross-Site Request Forgery (CSRF)filecloud8.8 (v3.1)High345490
CVE-2021-35380TermTalk Server 3.24.0.2 - Local File Inclusiontermtalk server7.5 (v3.1)High340007
CVE-2021-43734kkFileview v4.0.0 - Local File Inclusionkkfileview7.5 (v3.1)High340165 , 344360 , 347009
CVE-2022-0201WordPress Permalink Manager <2.2.15 - Cross-Site Scriptingpermalink manager lite6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198
CVE-2022-0206WordPress NewStatPress <1.3.6 - Cross-Site Scriptingnewstatpress6.1 (v3.1)Medium346755 , 347198
CVE-2022-0208WordPress Plugin MapPress <2.73.4 - Cross-Site Scriptingmappress6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2022-0212WordPress Spider Calendar <=1.5.65 - Cross-Site Scriptingspidercalendar6.1 (v3.1)Medium341266 , 346755 , 347198
CVE-2022-24112Apache APISIX - Remote Code Executionapisix9.8 (v3.1)Critical344364 , 344366 , 344370
CVE-2022-0020Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)cortex xsoar5.4 (v3.1)Medium330791 , 333141 , 340152 , 341256 , 342259 , 346755
CVE-2022-22536SAP Memory Pipes (MPI) Desynchronizationcontent server10.0 (v3.1)Critical392301
CVE-2021-25114WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injectionpaid memberships pro9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2021-24947WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Readresponsive vector maps6.5 (v3.1)Medium344360 , 347009 , 390709
CVE-2021-24878SupportCandy < 2.2.7 - Reflected Cross-Site Scriptingsupportcandy6.1 (v3.1)Medium346755
CVE-2022-0149WooCommerce Stored Exporter WordPress Plugin < 2.7.1 - Cross-Site Scriptingstore exporter for woocommerce6.1 (v3.1)Medium341266 , 346755
CVE-2022-0148WordPress All-in-one Floating Contact Form <2.0.4 - Cross-Site Scriptingmystickyelements5.4 (v3.1)Medium346755 , 347198
CVE-2022-0437karma-runner DOM-based Cross-Site Scriptingkarma6.1 (v3.1)Medium340112 , 346755 , 350148
CVE-2022-24260VoipMonitor - Pre-Auth SQL Injectionvoipmonitor9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2021-46398FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)filebrowser8.8 (v3.1)High345490 , 345493
CVE-2022-0381WordPress Embed Swagger <=1.0.0 - Cross-Site Scriptingembed swagger6.1 (v3.1)Medium346755 , 350148
CVE-2021-43062Fortinet FortiMail 7.0.1 - Cross-Site Scriptingfortimail6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-24762WordPress Perfect Survey <1.5.2 - SQL Injectionperfect survey9.8 (v3.1)Critical340016 , 380122
CVE-2021-43510Sourcecodester Simple Client Management System 1.0 - SQL Injectionsimple client management system9.8 (v3.1)Critical340145 , 340156 , 341145
CVE-2022-24223Atom CMS v2.0 - SQL Injectionatomcms9.8 (v3.1)Critical340016 , 340156 , 380122
CVE-2021-24926WordPress Domain Check <1.0.17 - Cross-Site Scriptingdomain check6.1 (v3.1)Medium341266 , 346755
CVE-2021-24934Visual CSS Style Editor < 7.5.4 - Cross-Site Scriptingvisual css style editor6.1 (v3.1)Medium341266
CVE-2021-25063WordPress Contact Form 7 Skins <=2.5.0 - Cross-Site Scriptingcontact form 7 skins6.1 (v3.1)Medium346755 , 347198
CVE-2021-25085WOOF WordPress plugin - Cross-Site Scriptingwoocommerce products filter6.1 (v3.1)Medium340099 , 341099 , 347198
CVE-2021-34805FAUST iServer 9.0.018.018.4 - Local File Inclusionfaust iserver7.5 (v3.1)High344365 , 347019 , 390716
CVE-2022-24264Cuppa CMS v1.0 - SQL injectioncuppacms7.5 (v3.1)High340016 , 340017 , 340144 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2022-24265Cuppa CMS v1.0 - SQL injectioncuppacms7.5 (v3.1)High341245 , 344370 , 380026 , 380122
CVE-2022-24266Cuppa CMS v1.0 - SQL injectioncuppacms7.5 (v3.1)High341245 , 360147 , 360148 , 380026 , 380122
CVE-2022-24124Casdoor 1.13.0 - Unauthenticated SQL Injectioncasdoor7.5 (v3.1)High341245
CVE-2022-0378Microweber Cross-Site Scriptingmicroweber5.4 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2022-0332Moodle 3.11.4 - SQL Injectionmoodle9.8 (v3.1)Critical340017 , 340157 , 341245 , 344361 , 360147 , 360148 , 380026 , 390727 , 392301 , 392648
CVE-2021-25008The Code Snippets WordPress Plugin < 2.14.3 - Cross-Site Scriptingcode snippets6.1 (v3.1)Medium346755 , 347198
CVE-2021-25074WordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open Redirectwebp converter for media6.1 (v3.1)Medium340162 , 340163
CVE-2021-25078Affiliates Manager < 2.9.0 - Cross Site Scriptingaffiliates manager6.1 (v3.1)Medium347198
CVE-2021-25079Contact Form Entries < 1.2.4 - Cross-Site Scriptingcontact form entries6.1 (v3.1)Medium341266 , 346755
CVE-2021-45380AppCMS - Cross-Site Scriptingappcms6.1 (v3.1)Medium340147 , 341266 , 342259 , 350147 , 350148
CVE-2022-23808phpMyAdmin < 5.1.2 - Cross-Site Scriptingphpmyadmin6.1 (v3.1)Medium341266 , 346755
CVE-2021-46104webp_server_go 0.4.0 - Path Traversalwebp server go7.5 (v3.1)High390709
CVE-2021-26247Cacti - Cross-Site Scriptingcacti6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-46005Sourcecodester Car Rental Management System 1.0 - Stored Cross-Site Scriptingcar rental management system5.4 (v3.1)Medium340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2021-24838WordPress AnyComment <0.3.5 - Open Redirectanycomment6.1 (v3.1)Medium390145
CVE-2021-25065Smash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site Scriptingsmash balloon social post feed5.4 (v3.1)Medium341266 , 346755 , 347198
CVE-2021-25067Landing Page Builder < 1.4.9.6 - Cross-Site Scriptinglanding page5.4 (v3.1)Medium333141 , 347198
CVE-2021-42551NetBiblio WebOPAC - Cross-Site Scriptingnetbiblio6.1 (v3.1)Medium341245 , 344370 , 346755
CVE-2021-45422Reprise License Manager 14.2 - Cross-Site Scriptingreprise license manager6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-0087Keystone 6 Login Page - Open Redirect and Cross-Site Scriptingkeystone6.1 (v3.1)Medium333140 , 346755 , 350148
CVE-2021-28377Joomla! ChronoForums 2.0.11 - Local File Inclusionchronoforums5.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2021-25052WordPress Button Generator <2.3.3 - Remote File Inclusionbutton generator8.8 (v3.1)High340464 , 340465
CVE-2021-24862WordPress RegistrationMagic <5.0.1.6 - Authenticated SQL Injectionregistrationmagic7.2 (v3.1)High340016 , 380122
CVE-2022-21661WordPress Core 5.8.2 - 'WP_Query' SQL InjectionWordPress7.5 (v3.1)High345493
CVE-2021-46068Vehicle Service Management System - Stored Cross-Site Scriptingvehicle service management system4.8 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-46069Vehicle Service Management System 1.0 - Stored Cross Site Scriptingvehicle service management system4.8 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755
CVE-2021-46071ehicle Service Management System 1.0 - Cross-Site Scriptingvehicle service management system4.8 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-46072Vehicle Service Management System 1.0 - Stored Cross Site Scriptingvehicle service management system4.8 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-46073Vehicle Service Management System 1.0 - Cross Site Scriptingvehicle service management system4.8 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-31589BeyondTrust Secure Remote Access Base <=6.0.1 - Cross-Site Scriptingappliance base software6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198
CVE-2021-45428Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Uploadtlr-2005ksh9.8 (v3.1)Critical392301
CVE-2021-24786Download Monitor < 4.4.5 - SQL Injectiondownload monitor7.2 (v3.1)High380026 , 380122
CVE-2021-25016Chaty < 2.8.2 - Cross-Site Scriptingchaty6.1 (v3.1)Medium341266 , 346755 , 347198
CVE-2021-24991WooCommerce PDF Invoices & Packing Slips WordPress Plugin < 2.10.5 - Cross-Site Scriptingwoocommerce pdf invoices&amp; packing slips4.8 (v3.1)Medium347198
CVE-2021-20158Trendnet AC2600 TEW-827DRU 2.08B01 - Admin Password Changetew-827dru firmware9.8 (v3.1)Critical392301
CVE-2021-20167Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrunrax43 firmware8.0 (v3.1)High392301
CVE-2021-20150Trendnet AC2600 TEW-827DRU - Credentials Disclosuretew-827dru firmware5.3 (v3.1)Medium392301
CVE-2021-45425SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)safari montage6.1 (v3.1)Medium333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24979Paid Memberships Pro < 2.6.6 - Cross-Site Scriptingpaid memberships pro6.1 (v3.1)Medium346755 , 347198
CVE-2021-21881Lantronix PremierWave 2050 8.9.0.0R4 - Remote Command Injectionpremierwave 2050 firmware9.9 (v3.1)Critical340014 , 344363 , 344370
CVE-2021-24849WCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL Injectionfrontend manager for woocommerce along with bookings subscription listings compatible9.8 (v3.1)Critical340016 , 340017 , 360147 , 360148 , 380122
CVE-2021-24750WordPress Visitor Statistics (Real Time Traffic) <4.8 -SQL Injectionwp visitor statistics (real time traffic)8.8 (v3.1)High340016 , 340017 , 360147 , 360148
CVE-2021-24956Blog2Social < 6.8.7 - Cross-Site Scriptingblog2social6.1 (v3.1)Medium341266 , 346755
CVE-2021-43831Gradio < 2.5.0 - Arbitrary File Readgradio7.7 (v3.1)High347009
CVE-2021-45043HD-Network Realtime Monitoring System 2.0 - Local File Inclusionhd-network real-time monitoring system7.5 (v3.1)High344360
CVE-2021-36450Verint Workforce Optimization 15.2.8.10048 - Cross-Site Scriptingworkforce optimization6.1 (v3.1)Medium350147
CVE-2021-45046Apache Log4j2 - Remote Code Injectionlog4j9.0 (v3.1)Critical345115 , 345117 , 345118 , 393655
CVE-2021-39312WordPress True Ranker <2.2.4 - Local File Inclusiontrue ranker7.5 (v3.1)High336461 , 344360 , 381206
CVE-2021-3831Gnuboard 5 - Cross-Site Scriptinggnuboard56.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2021-42063SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scriptingknowledge warehouse6.1 (v3.1)Medium346755
CVE-2021-24946WordPress Modern Events Calendar <6.1.5 - Blind SQL Injectionmodern events calendar lite9.8 (v3.1)Critical340016 , 340017 , 360147 , 360148 , 380122
CVE-2021-24970WordPress All-In-One Video Gallery <2.5.0 - Local File Inclusionall-in-one video gallery7.2 (v3.1)High377360
CVE-2021-44228Apache Log4j2 Remote Code Injectionlog4j10.0 (v3.1)Critical345115 , 345117 , 345118 , 393655
CVE-2021-20137Gryphon Tower - Cross-Site Scriptinggryphon tower6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-20038SonicWall SMA100 Stack - Buffer Overflow/Remote Code Executionsma 200 firmware9.8 (v3.1)Critical340193
CVE-2021-43798Grafana v8.x - Arbitrary File Readgrafana7.5 (v3.1)High347009
CVE-2021-42567Apereo CAS Cross-Site Scriptingcentral authentication service6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 350148
CVE-2021-43810Admidio - Cross-Site Scriptingadmidio6.1 (v3.1)Medium340112 , 350148 , 390722
CVE-2021-24931WordPress Secure Copy Content Protection and Content Locking <2.8.2 - SQL Injectionsecure copy content protection and content locking9.8 (v3.1)Critical340016 , 380122
CVE-2021-24943Registrations for the Events Calendar < 2.7.6 - SQL Injectionregistrations for the events calendar9.8 (v3.1)Critical340016 , 380122
CVE-2021-24915Contest Gallery < 13.1.0.6 - SQL injectioncontest gallery9.8 (v3.1)Critical340017 , 340144 , 340157 , 344361
CVE-2021-24876Registrations for The Events Calendar < 2.7.5 - Authenticated Reflected Cross-Site Scriptingregistrations for the events calendar6.1 (v3.1)Medium346755 , 347198 , 377360
CVE-2021-43778GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.barcode7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2021-24644Images to WebP < 1.9 - Authenticated Local File Inclusionimages to webp7.5 (v3.1)High340007 , 377360
CVE-2021-24875WordPress eCommerce Product Catalog <3.0.39 - Cross-Site Scriptingecommerce product catalog6.1 (v3.1)Medium333141 , 346755 , 347198
CVE-2021-22053Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Executionspring cloud netflix8.8 (v3.1)High337209 , 337211 , 340087 , 340193
CVE-2021-41569SAS/Internet 9.4 1520 - Local File Inclusionsas/intrnet7.5 (v3.1)High344360 , 347009
CVE-2021-41277Metabase - Local File Inclusionmetabase7.5 (v3.1)High340165 , 344360 , 347009
CVE-2021-43495AlquistManager Local File Inclusionalquist7.5 (v3.1)High347009
CVE-2021-41951Resourcespace - Cross-Site Scriptingresourcespace6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 , 390585
CVE-2021-43574Atmail 6.5.0 - Cross-Site Scriptingatmail6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2021-3577Motorola Baby Monitors - Remote Command Executionhalo+ camera firmware8.8 (v3.1)High340014 , 340193 , 344364 , 344370 , 393655
CVE-2021-43496Clustering Local File Inclusionclustering7.5 (v3.1)High347009
CVE-2021-41349Microsoft Exchange Server Pre-Auth POST Based Cross-Site Scriptingexchange server6.5 (v3.1)Medium340147 , 340148 , 342259 , 346755 , 350148
CVE-2021-35488Thruk 2.40-2 - Cross-Site Scriptingthruk6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-24731Pie Register < 3.7.1.6 - SQL Injectionpie register9.8 (v3.1)Critical340016 , 340156 , 341245 , 380026 , 380122
CVE-2021-24827WordPress Asgaros Forum <1.15.13 - SQL Injectionasgaros forum9.8 (v3.1)Critical340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2021-24627G Auto-Hyperlink <= 1.0.1 - SQL Injectiong auto-hyperlink7.2 (v3.1)High340017 , 340144 , 340157
CVE-2021-24791Header Footer Code Manager < 1.1.14 - Admin+ SQL Injectionheader footer code manager7.2 (v3.1)High380122
CVE-2021-40577Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scriptingonline enrollment management system5.4 (v3.1)Medium340147 , 340148 , 342259 , 346755 , 350148
CVE-2021-42237Sitecore Experience Platform Pre-Auth RCEexperience platform9.8 (v3.1)Critical344362 , 344366
CVE-2021-42667Online Event Booking and Reservation System 2.3.0 - SQL Injectiononline event booking and reservation system9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 360147 , 360148
CVE-2021-39411Hospital Management System 1.0 - Cross-Site Scriptinghospital management system6.1 (v3.1)Medium340147 , 340148 , 342259 , 346755
CVE-2021-42663Sourcecodester Online Event Booking and Reservation System 2.3.0 - Cross-Site Scriptingonline event booking and reservation system4.3 (v3.1)Medium340147 , 341266 , 342259
CVE-2021-43140Simple Subscription Website 1.0 - SQLi Authentication Bypasssimple subscription website9.8 (v3.1)Critical340145 , 340156 , 341145 , 345493 , 390572
CVE-2020-20982shadoweb wdja v1.5.1 - Cross-Site Scriptingwdja cms9.6 (v3.1)Critical340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-41174Grafana 8.0.0 <= v.8.2.2 - Angularjs Rendering Cross-Site Scriptinggrafana6.1 (v3.1)Medium346755
CVE-2021-31862SysAid 20.4.74 - Cross-Site Scriptingsysaid6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2021-31682WebCTRL OEM <= 6.5 - Cross-Site Scriptingwebctrl6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-42565myfactory FMS - Cross-Site Scriptingfms6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-42566myfactory FMS - Cross-Site Scriptingfms6.1 (v3.1)Medium346755
CVE-2021-20123Draytek VigorConnect 1.6.0-B - Local File Inclusionvigorconnect7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2021-20124Draytek VigorConnect 6.0-B3 - Local File Inclusionvigorconnect7.5 (v3.1)High344360 , 347009 , 390709
CVE-2021-42325Froxlor 0.10.29.1 - SQL Injection (Authenticated)froxlor9.8 (v3.1)Critical344370 , 350147 , 390724
CVE-2021-40617openSIS Community Edition 8.0 - SQL Injectionopensis9.8 (v3.1)Critical340145 , 340156 , 341145 , 341245 , 390727 , 392301 , 392648
CVE-2021-29006rConfig 3.9.6 - Local File Inclusionrconfig6.5 (v3.1)Medium344360 , 347009 , 390709
CVE-2021-24563WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)frontend uploader6.1 (v3.1)Medium392301
CVE-2021-40542Opensis-Classic 8.0 - Cross-Site Scriptingopensis6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2021-24681Duplicate Page WordPress - Stored Cross-Site Scriptingduplicate page4.8 (v3.1)Medium377360
CVE-2021-42013Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Executionhttp server9.8 (v3.1)Critical347009
CVE-2021-40978MKdocs 1.2.2 - Directory Traversalmkdocs7.5 (v3.1)High347009
CVE-2021-39350FV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site Scriptingfv flowplayer video player6.1 (v3.1)Medium341266 , 346755
CVE-2021-41773Apache 2.4.49 - Path Traversal and Remote Code Executionhttp server9.8 (v3.1)Critical347009
CVE-2021-39433BIQS IT Biqs-drive v1.83 Local File Inclusionbiqsdrive7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2021-41878i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)i-panel administration system6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2021-40960Galera WebTemplate 1.0 Directory Traversalgalera webtemplate9.8 (v3.1)Critical347009 , 390709
CVE-2021-41649PuneethReddyHC Online Shopping System homeaction.php SQL Injectiononline-shopping-system-advanced9.8 (v3.1)Critical392301
CVE-2021-41648PuneethReddyHC action.php SQL Injectiononline-shopping-system-advanced7.5 (v3.1)High392301
CVE-2021-40968Spotweb <= 1.5.1 - Cross Site Scriptingspotweb6.1 (v3.1)Medium346755
CVE-2021-40969Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)spotweb6.1 (v3.1)Medium346755
CVE-2021-40970Spotweb <= 1.5.1 - Cross Site Scriptingspotweb6.1 (v3.1)Medium346755
CVE-2021-40971Spotweb <= 1.5.1 - Cross Site Scriptingspotweb6.1 (v3.1)Medium346755
CVE-2021-40972Spotweb <= 1.5.1 - Cross Site Scriptingspotweb6.1 (v3.1)Medium346755
CVE-2021-40973Spotweb <= 1.5.1 - Cross Site Scriptingspotweb6.1 (v3.1)Medium346755
CVE-2021-41467JustWriting - Cross-Site Scriptingjustwriting6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-41291ECOA Building Automation System - Directory Traversal Content Disclosureecs router controller-ecs firmware7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2021-41293ECOA Building Automation System - Arbitrary File Retrievalecs router controller-ecs firmware7.5 (v3.1)High392301
CVE-2021-40651OS4Ed OpenSIS Community 8.0 - Local File Inclusionopensis6.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2021-24666WordPress Podlove Podcast Publisher <3.5.6 - SQL Injectionpodlove podcast publisher9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 360147 , 360148
CVE-2021-36749Apache Druid - Local File Inclusiondruid6.5 (v3.1)Medium340029 , 344360
CVE-2021-22005VMware vCenter Server - Arbitrary File Uploadcloud foundation9.8 (v3.1)Critical330791 , 340152
CVE-2021-36873WordPress iQ Block Country <=1.2.11 - Cross-Site Scriptingiq block country5.4 (v3.1)Medium377360
CVE-2021-22017vCenter Server - Improper Access Controlvcenter server5.3 (v3.1)Medium344370
CVE-2021-36260Hikvision IP camera/NVR - Remote Command Executionds-2cd2026g2-iu/sl firmware9.8 (v3.1)Critical393655
CVE-2021-40868Cloudron 6.2 Cross-Site Scriptingcloudron6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24657Limit Login Attempts WordPress - Stored Cross-site Scriptinglimit login attempts6.1 (v3.1)Medium377360
CVE-2021-40438Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgeryhttp server9.0 (v3.1)Critical345271 , 390723
CVE-2021-33690SAP NetWeaver Development Infrastructure - Server Side Request Forgerynetweaver development infrastructure9.9 (v3.1)Critical340162 , 340163
CVE-2021-40870Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Executioncontroller9.8 (v3.1)Critical340007
CVE-2021-33544Geutebruck - Remote Command Injectiong-cam ebc-21107.2 (v3.1)High340014 , 340193 , 344364 , 344370 , 393655
CVE-2021-24510WordPress MF Gig Calendar <=1.1 - Cross-Site Scriptingmf gig calendar6.1 (v3.1)Medium341266 , 346755
CVE-2020-19282Jeesns 1.4.2 - Cross-Site Scriptingjeesns6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2020-19283Jeesns 1.4.2 - Cross-Site Scriptingjeesns6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-19295Jeesns 1.4.2 - Cross-Site Scriptingjeesns6.1 (v3.1)Medium341266
CVE-2020-19515qdPM 9.1 - Cross-site Scriptingqdpm6.1 (v3.1)Medium340099 , 341099 , 346755 , 347198
CVE-2021-38704ClinicCases 7.3.3 Cross-Site Scriptingcliniccases6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24435WordPress Titan Framework plugin <= 1.12.1 - Cross-Site Scriptingtitan framework6.1 (v3.1)Medium333141 , 340149 , 341245 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-39322WordPress Easy Social Icons Plugin < 3.0.9 - Cross-Site Scriptingeasy social icons6.1 (v3.1)Medium341266 , 346755
CVE-2021-39320WordPress Under Construction <1.19 - Cross-Site Scriptingunderconstruction6.1 (v3.1)Medium341266 , 346755
CVE-2021-39316WordPress DZS Zoomsounds <=6.50 - Local File Inclusionzoomsounds7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2021-27909Mautic <3.3.4 - Cross-Site Scriptingmautic6.1 (v3.1)Medium346755
CVE-2021-37416Zoho ManageEngine ADSelfService Plus <=6103 - Cross-Site Scriptingmanageengine adselfservice plus6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 390585
CVE-2021-39165Cachet <=2.3.18 - SQL Injectioncachet6.5 (v3.1)Medium340145 , 340156 , 341145 , 380026 , 380122
CVE-2021-37538PrestaShop SmartBlog <4.0.6 - SQL Injectionsmartblog9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2021-39144XStream 1.4.18 - Remote Code Executionxstream8.5 (v3.1)High344363
CVE-2021-24554WordPress Paytm Donation <=1.3.2 - Authenticated SQL Injectionpaytm-pay7.2 (v3.1)High380122
CVE-2021-36748PrestaHome Blog for PrestaShop <1.7.8 - SQL Injectionblog7.5 (v3.1)High341245
CVE-2021-20792WordPress Quiz and Survey Master <7.1.14 - Cross-Site Scriptingquiz and survey master6.1 (v3.1)Medium341266 , 346755
CVE-2021-38702Cyberoam NetGenie Cross-Site Scriptingnetgenie c0101b1-20141120-ng11vo firmware6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24527Profile Builder < 3.4.9 - Improper Authenticationprofile builder9.8 (v3.1)Critical340130
CVE-2021-35395RealTek Jungle SDK - Arbitrary Command Injectionrealtek jungle sdk9.8 (v3.1)Critical340014 , 340029 , 344361 , 344363
CVE-2021-34643WordPress Skaut Bazar <1.3.3 - Cross-Site Scriptingskaut-bazar6.1 (v3.1)Medium341266 , 346755
CVE-2021-26086Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Readjira data center5.3 (v3.1)Medium345113 , 390727 , 392301 , 392648
CVE-2021-36380Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injectionsureline9.8 (v3.1)Critical392301
CVE-2020-20988DomainMOD 4.13.0 - Cross-Site Scriptingdomainmod5.4 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-34640WordPress Securimage-WP-Fixed <=3.5.4 - Cross-Site Scriptingsecurimage-wp-fixed6.1 (v3.1)Medium341266 , 346755
CVE-2021-37425Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)mobiletogether server9.1 (v3.1)Critical330791 , 340152
CVE-2021-24499WordPress Workreap - Remote Code Executionworkreap9.8 (v3.1)Critical330791 , 340152 , 382238
CVE-2021-24495Wordpress Marmoset Viewer <1.9.3 - Cross-Site Scriptingmarmoset viewer6.1 (v3.1)Medium333141 , 340147 , 340148 , 340162 , 340163 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148
CVE-2021-24522ProfilePress < 3.1.11 - Cross-Site Scriptingprofilepress6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-37573Tiny Java Web Server - Cross-Site Scriptingtiny java web server6.1 (v3.1)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2021-35265MaxSite CMS > V106 - Cross-Site Scriptingmaxsite cms6.1 (v3.1)Medium346755 , 347198
CVE-2021-37833Hotel Druid 3.0.2 - Cross-Site Scriptinghoteldruid6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-26085Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Readconfluence data center5.3 (v3.1)Medium390727 , 392301 , 392648
CVE-2021-24472Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgerykentharadio9.8 (v3.1)Critical340162 , 340163
CVE-2021-24488WordPress Post Grid <2.1.8 - Cross-Site Scriptingpost grid6.1 (v3.1)Medium333141 , 340149 , 346755 , 347198
CVE-2021-24498WordPress Calendar Event Multi View <1.4.01 - Cross-Site Scriptingcalendar event multi view6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2021-37593PEEL Shopping 9.3.0 - 'id' Time-based SQL Injectionpeel shopping9.1 (v3.1)Critical340016 , 380026 , 380122 , 390727 , 392301 , 392648
CVE-2021-34630GTranslate < 2.8.65 - Cross-Site Scriptinggtranslate6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-32789WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injectionwoocommerce blocks7.5 (v3.1)High360150
CVE-2021-30049SysAid Technologies 20.3.64 b14 - Cross-Site Scriptingsysaid6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-22145Elasticsearch 7.10.0-7.13.3 - Information Disclosureelasticsearch6.5 (v3.1)Medium330791 , 340152
CVE-2021-24436WordPress W3 Total Cache <2.1.4 - Cross-Site Scriptingw3 total cache6.1 (v3.1)Medium341266 , 346755
CVE-2021-24452WordPress W3 Total Cache <2.1.5 - Cross-Site Scriptingw3 total cache6.1 (v3.1)Medium346755 , 377360
CVE-2021-21799Advantech R-SeeNet 2.4.12 - Cross-Site Scriptingr-seenet6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-21800Advantech R-SeeNet 2.4.12 - Cross-Site Scriptingr-seenet6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-21801Advantech R-SeeNet - Cross-Site Scriptingr-seenet6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-21802Advantech R-SeeNet - Cross-Site Scriptingr-seenet6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-21803Advantech R-SeeNet - Cross-Site Scriptingr-seenet6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-34429Eclipse Jetty 11.0.5 - Sensitive File Disclosurejetty5.3 (v3.1)Medium390703
CVE-2020-26153Event Espresso Core-Reg 4.10.7.p - Cross-Site Scriptingevent espresso6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2021-24442Wordpress Polls Widget < 1.5.3 - SQL Injectionpoll, survey, questionnaire and voting system9.8 (v3.1)Critical380122
CVE-2021-33807Cartadis Gespage 8.2.1 - Directory Traversalgespage7.5 (v3.1)High340007 , 344360
CVE-2021-24409Prismatic < 2.8 - Cross-Site Scriptingprismatic6.1 (v3.1)Medium346755 , 347198
CVE-2021-30118Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Executionvsa9.8 (v3.1)Critical344365 , 392301
CVE-2021-34621WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weaknessprofilepress9.8 (v3.1)Critical377360
CVE-2021-34624WordPress ProfilePress 3.0-3.1.3 - Arbitrary File Uploadprofilepress9.8 (v3.1)Critical382238
CVE-2021-24405WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSSeasy cookies policy6.5 (v3.1)Medium346755 , 390585 , 390726 , 392647
CVE-2021-24387WordPress Pro Real Estate 7 Theme <3.1.1 - Cross-Site Scriptingreal estate 76.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2021-24389WordPress FoodBakery <2.2 - Cross-Site Scriptingfoodbakery6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24407WordPress Jannah Theme <5.4.5 - Cross-Site Scriptingjannah6.1 (v3.1)Medium392301
CVE-2021-35956AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)sensorprobe2 firmware5.4 (v3.1)Medium333141 , 341256 , 342259 , 350147
CVE-2021-34187Chamilo model.ajax.php - SQL Injectionchamilo9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2020-18662Gnuboard5 5.3.2.8 - SQL Injectiongnuboard9.8 (v3.1)Critical344366 , 380122
CVE-2020-22165PHPGurukul Hospital Management System 4.0 - SQL Injectionhospital management system7.5 (v3.1)High340016 , 340017 , 340145 , 340157 , 340159 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2021-24364WordPress Jannah Theme <5.4.4 - Cross-Site Scriptingjannah6.1 (v3.1)Medium341266 , 346755
CVE-2020-2220874cms - ajax_street.php 'x' SQL Injection74cms9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2020-2220974cms - ajax_common.php SQL Injection74cms9.8 (v3.1)Critical341250 , 390703
CVE-2020-2221074cms - ajax_officebuilding.php SQL Injection74cms9.8 (v3.1)Critical340145
CVE-2020-2221174cms - ajax_street.php 'key' SQL Injection74cms9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2020-29214Alumni Management System 1.0 - SQL Injectionalumni management system9.8 (v3.1)Critical340156
CVE-2021-24347WordPress SP Project & Document Manager <4.22 - Authenticated Shell Uploadsp project &amp; document manager8.8 (v3.1)High377360
CVE-2021-24351WordPress The Plus Addons for Elementor <4.1.12 - Cross-Site Scriptingthe plus addons for elementor6.1 (v3.1)Medium346755
CVE-2021-23394elFinder < 2.1.58 - Remote Code Executionelfinder9.8 (v3.1)Critical393781
CVE-2021-22175GitLab CI Lint API - Server-Side Request Forgerygitlab9.8 (v3.1)Critical344362 , 344370
CVE-2021-33357RaspAP <=2.6.5 - Remote Command Injectionraspap9.8 (v3.1)Critical344363 , 344364 , 344366 , 344370
CVE-2021-34369Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR)civic platform6.5 (v3.1)Medium390727 , 392301 , 392648
CVE-2021-33829Drupal 7 CKEditor XSSckeditor6.1 (v3.1)Medium333141
CVE-2021-34370Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS)civic platform6.1 (v3.1)Medium341245 , 390727 , 392301 , 392648
CVE-2021-22214Gitlab CE/EE 10.5 - Server-Side Request Forgerygitlab8.6 (v3.1)High344362
CVE-2021-24340WordPress Statistics <13.0.8 - Blind SQL Injectionwp statistics7.5 (v3.1)High380122
CVE-2020-18268Z-Blog <=1.5.2 - Open Redirectz-blogphp6.1 (v3.1)Medium390500 , 390501
CVE-2021-24342WordPress JNews Theme <8.0.6 - Cross-Site Scriptingjnews6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-33904Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS)civic platform6.1 (v3.1)Medium341245 , 390727 , 392301 , 392648
CVE-2021-31249CHIYU TCP/IP Converter - Carriage Return Line Feed Injectionbf-430 firmware6.5 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 , 390722
CVE-2021-31250CHIYU TCP/IP Converter - Cross-Site Scriptingbf-430 firmware5.4 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2020-6950Eclipse Mojarra - Local File Readmojarra6.5 (v3.1)Medium340007
CVE-2021-27828In4Suit ERP 3.2.74.1370 - 'txtLoginId' SQL injectionin4suite erp9.1 (v3.1)Critical392301
CVE-2021-24316WordPress Mediumish Theme <=1.0.47 - Cross-Site Scriptingmediumish6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24320WordPress Bello Directory & Listing Theme <1.6.0 - Cross-Site Scriptingbello6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24335WordPress Car Repair Services & Auto Mechanic Theme <4.0 - Cross-Site Scriptingcar repair services &amp; auto mechanic6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24298WordPress Simple Giveaways <2.36.2 - Cross-Site Scriptingsimple giveaways6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-24300WordPress WooCommerce <1.13.22 - Cross-Site Scriptingproduct slider for woocommerce6.1 (v3.1)Medium333141 , 340149 , 346755 , 347198
CVE-2020-35580SearchBlox <9.2.2 - Local File Inclusionsearchblox7.5 (v3.1)High344360 , 347009 , 390709
CVE-2021-29625Adminer <=4.8.0 - Cross-Site Scriptingadminer6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-31316CentOS Web Panel - SQL Injectionwebpanel9.8 (v3.1)Critical340016 , 340017 , 341245
CVE-2021-31324CentOS Web Panel - OS Command Injectionwebpanel9.8 (v3.1)Critical340016 , 340017 , 341245
CVE-2021-32305Websvn <2.6.1 - Remote Code Executionwebsvn9.8 (v3.1)Critical340014 , 340193 , 344364 , 344366 , 344370
CVE-2021-24284WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File Uploadkaswara9.8 (v3.1)Critical382238
CVE-2021-24285WordPress Car Seller - Auto Classifieds Script - SQL Injectioncars-seller-auto-classifieds-script9.8 (v3.1)Critical340016 , 340017 , 340144 , 360147 , 360148
CVE-2021-32819Nodejs Squirrelly - Remote Code Executionsquirrelly8.8 (v3.1)High340014 , 340087 , 340095 , 340193 , 344370 , 345240 , 380026
CVE-2021-32820Express-handlebars - Local File Inclusionexpress handlebars8.6 (v3.1)High344360 , 347009 , 390709
CVE-2021-24286WordPress Plugin Redirect 404 to Parent 1.3.0 - Cross-Site Scriptingredirect 404 to parent6.1 (v3.1)Medium346755 , 377360
CVE-2021-24287WordPress Select All Categories and Taxonomies <1.3.2 - Cross-Site Scriptingselect all categories and taxonomies, change checkbox to radio buttons6.1 (v3.1)Medium346755 , 377360
CVE-2021-24291WordPress Photo Gallery by 10Web <1.5.69 - Cross-Site Scriptingphoto gallery6.1 (v3.1)Medium347198
CVE-2021-28799QNAP HBS 3 - Broken Access Controlhybrid backup sync9.8 (v3.1)Critical344360 , 390904
CVE-2021-30213Knowage Suite 7.3 - Cross-Site Scriptingknowage6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-31195Microsoft Exchange Server - Cross-Site Scriptingexchange server6.5 (v3.1)Medium346755 , 350148
CVE-2021-31537SIS Informatik REWE GO SP17 <7.7 - Cross-Site Scriptingsis-rewe go6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2020-23575Kyocera Printer d-COPIA253MF - Directory Traversald-copia253mf plus firmware7.5 (v3.1)High347009
CVE-2021-31755Tenda Router AC11 - Remote Command Injectionac11 firmware9.8 (v3.1)Critical340014
CVE-2021-1498Cisco HyperFlex HX Data Platform - Remote Command Executionhyperflex hx data platform9.8 (v3.1)Critical340014 , 344364 , 344366 , 344370
CVE-2021-28151Hongdian H8922 3.0.5 - Remote Command Injectionh8922 firmware8.8 (v3.1)High330925 , 392301
CVE-2021-28149Hongdian H8922 3.0.5 Devices - Local File Inclusionh8922 firmware6.5 (v3.1)Medium330925 , 340007 , 344360 , 347009 , 390709
CVE-2021-24214WordPress OpenID Connect Generic Client 3.8.0-3.8.1 - Cross-Site Scriptingopenid connect generic client6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-24245WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS)stop spammers6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 398005
CVE-2021-28150Hongdian H8922 3.0.5 - Information Disclosureh8922 firmware5.5 (v3.1)Medium330925
CVE-2020-36333ThemeGrill Demo Importer < 1.6.2 - Database Resetthemegrill demo importer9.1 (v3.1)Critical375357
CVE-2021-24274WordPress Supsystic Ultimate Maps <1.2.5 - Cross-Site Scriptingultimate maps6.1 (v3.1)Medium341266 , 346755
CVE-2021-24275Popup by Supsystic <1.10.5 - Cross-Site scriptingpopup6.1 (v3.1)Medium341266 , 346755
CVE-2021-24276WordPress Supsystic Contact Form <1.7.15 - Cross-Site Scriptingcontact form6.1 (v3.1)Medium341266 , 346755
CVE-2021-31856Layer5 Meshery 0.5.2 - SQL Injectionmeshery9.8 (v3.1)Critical341245 , 344366
CVE-2021-29460Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS)kirby5.4 (v3.1)Medium330791 , 340152
CVE-2021-20086Odoo Apps - Cross-Site Scripting via Prototype Pollutionjquery-bbq8.8 (v3.1)High333141 , 340099 , 340147 , 341099 , 341256 , 346755 , 347198
CVE-2021-25899Void Aural Rec Monitor 9.0.0.1 - SQL Injectionaurall rec monitor7.5 (v3.1)High341245 , 380026 , 380122
CVE-2021-24235WordPress Goto Tour & Travel Theme <2.0 - Cross-Site Scriptinggoto6.1 (v3.1)Medium333141 , 340099 , 340149 , 341099 , 341256 , 342259 , 344370 , 346755 , 347198 , 350148 , 390722
CVE-2021-24237WordPress Realteo <=1.2.3 - Cross-Site Scriptingfindeo6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2020-25864HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site Scriptingconsul6.1 (v3.1)Medium392301
CVE-2021-26812Moodle Jitsi Meet 2.7-2.8.3 - Cross-Site Scriptingmeet6.1 (v3.1)Medium346755
CVE-2021-24215Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalationcontrolled admin access9.8 (v3.1)Critical377360
CVE-2020-24285INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusiontip2007.5 (v3.1)High344360 , 347009 , 390709
CVE-2021-24227Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusionpatreon wordpress7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2021-24213GiveWP <= 2.9.7 - Cross-Site Scriptinggivewp6.1 (v3.1)Medium340148 , 341266 , 346755 , 377360
CVE-2021-1472Cisco Small Business RV Series - OS Command Injectionrv160 firmware9.8 (v3.1)Critical340014 , 340149 , 344364 , 344366 , 344370 , 350147
CVE-2021-30151Sidekiq <=6.2.0 - Cross-Site Scriptingsidekiq6.1 (v3.1)Medium346755
CVE-2021-24212WooCommerce Help Scout - Arbitrary File Uploadhelp scout9.8 (v3.1)Critical330791 , 340152 , 382238
CVE-2021-24170User Profile Picture < 2.5.0 - Sensitive Information Disclosureuser profile picture7.5 (v3.1)High377360
CVE-2021-24155WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Uploadbackup guard7.2 (v3.1)High377360
CVE-2021-24165WordPress Ninja Forms <3.4.34 - Open Redirectninja forms6.1 (v3.1)Medium377360
CVE-2021-24169WordPress Advanced Order Export For WooCommerce <3.1.8 - Authenticated Cross-Site Scriptingadvanced order export6.1 (v3.1)Medium341266 , 346755
CVE-2021-24210WordPress PhastPress <1.111 - Open Redirectphastpress6.1 (v3.1)Medium340162 , 340163
CVE-2021-28918Netmask NPM Package - Server-Side Request Forgerynetmask9.1 (v3.1)Critical340162 , 344360 , 347009 , 398003
CVE-2020-24391Mongo-Express - Remote Code Executionmongo-express9.8 (v3.1)Critical345240 , 380026
CVE-2021-25161Aruba Instant Access Point (IAP) - Cross-Site Scriptingaruba-instant-access-point6.1 (v3.1)Medium344370 , 346755 , 390722
CVE-2020-19625Gridx 1.3 - Remote Code Executiongridx9.8 (v3.1)Critical341250
CVE-2020-23517Aryanic HighMail (High CMS) - Cross-Site Scriptinghigh cms6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-27316Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system7.5 (v3.1)High340016 , 340156 , 341245 , 380026 , 380122
CVE-2021-27319Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system7.5 (v3.1)High340016 , 340156 , 380122
CVE-2021-27320Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system7.5 (v3.1)High340016 , 340156 , 341245 , 380026 , 380122
CVE-2021-21345XStream < 1.4.16 - Remote Code Executionxstream9.9 (v3.1)Critical344363 , 344366
CVE-2021-21351XStream <1.4.16 - Remote Code Executionxstream9.1 (v3.1)Critical344380
CVE-2021-21402Jellyfin <10.7.0 - Local File Inclusionjellyfin6.5 (v3.1)Medium344365 , 347019
CVE-2021-27309Clansphere CMS 2011.4 - Cross-Site Scriptingclansphere6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-27310Clansphere CMS 2011.4 - Cross-Site Scriptingclansphere6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-27519FUDForum 3.1.0 - Cross-Site Scriptingfudforum6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-27520FUDForum 3.1.0 - Cross-Site Scriptingfudforum6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2021-2413910Web Photo Gallery < 1.5.55 - SQL Injectionphoto gallery9.8 (v3.1)Critical341245 , 380026 , 380122
CVE-2021-24145WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Uploadmodern events calendar lite7.2 (v3.1)High382238
CVE-2021-27695openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scriptingopenmaint6.1 (v3.1)Medium330791 , 333141 , 340147 , 340148 , 340149 , 340152 , 341256 , 342259 , 346755
CVE-2021-27314Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system9.8 (v3.1)Critical340016 , 340156 , 380026 , 380122
CVE-2020-29047WP Hotel Booking < 1.10.4 - PHP Object Injectionwp hotel booking9.8 (v3.1)Critical330889
CVE-2021-21978VMware View Planner <4.6 SP1- Remote Code Executionview planner9.8 (v3.1)Critical330791 , 340007 , 340152
CVE-2021-27931LumisXP <10.0.0 - Blind XML External Entity Attacklumis experience platform9.1 (v3.1)Critical344372 , 392301
CVE-2021-26475EPrints 3.4.2 - Cross-Site Scriptingeprints6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2021-26702EPrints 3.4.2 - Cross-Site Scriptingeprints6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2021-25281SaltStack Salt <3002.5 - Auth Bypasssalt9.8 (v3.1)Critical340007
CVE-2021-27132Sercomm VD625 Smart Modems - CRLF Injectionagcombo vd625 firmware9.8 (v3.1)Critical330708 , 390714
CVE-2021-27330Triconsole Datepicker Calendar <3.77 - Cross-Site Scriptingdatepicker calendar6.1 (v3.1)Medium340147 , 341266 , 346755
CVE-2020-28429geojson2kml - Command Injectiongeojson2kml9.8 (v3.1)Critical344361 , 344363
CVE-2020-21224Inspur ClusterEngine 4.0 - Remote Code Executionclusterengine9.8 (v3.1)Critical340023 , 344360 , 344361 , 344363 , 344370
CVE-2021-27124Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system6.5 (v3.1)Medium340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2021-21315Node.JS System Information Library <5.3.1 - Remote Command Injectionsysteminformation7.8 (v3.1)High340029 , 344360 , 344364 , 344370 , 347009 , 393655
CVE-2021-3239E-Learning System 1.0 - SQL Injectione-learning system9.8 (v3.1)Critical340016 , 340017 , 340157 , 360147 , 360148
CVE-2021-21307Lucee Admin - Remote Code Executionlucee server9.8 (v3.1)Critical340149 , 342259 , 344364 , 344366 , 350147
CVE-2020-13117Wavlink Multiple AP - Remote Command Injectionwn575a49.8 (v3.1)Critical340014 , 344364 , 344366 , 344370
CVE-2021-21479SCIMono <0.0.19 - Remote Code Executionscimono9.1 (v3.1)Critical337209 , 337211 , 340087 , 346755
CVE-2021-22502Micro Focus Operations Bridge Reporter - Remote Code Executionoperation bridge reporter9.8 (v3.1)Critical344364 , 344366
CVE-2021-22122FortiWeb - Cross Site Scriptingfortiweb6.1 (v3.1)Medium346755
CVE-2021-26723Jenzabar 9.2x-9.2.2 - Cross-Site Scriptingjenzabar6.1 (v3.1)Medium340147 , 341266 , 342259 , 350147 , 350148
CVE-2021-26710Redwood Report2Web 4.3.4.5 & 4.5.3 - Cross-Site Scriptingreport2web6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-29164PacsOne Server <7.1.1 - Cross-Site Scriptingpacsone server6.1 (v3.1)Medium333141 , 340099 , 340147 , 341099 , 346755 , 360030
CVE-2020-25506D-Link DNS-320 - Unauthenticated Remote Code Executiondns-320 firmware9.8 (v3.1)Critical344363 , 392301
CVE-2021-3378FortiLogger 4.4.2.2 - Arbitrary File Uploadfortilogger9.8 (v3.1)Critical330791 , 340152
CVE-2020-15568TerraMaster TOS <.1.29 - Remote Code Executiontos9.8 (v3.1)Critical340023 , 344360 , 347009
CVE-2021-25646Apache Druid - Remote Code Executiondruid8.8 (v3.1)High337209 , 337210 , 337211 , 340095 , 344360 , 344361 , 344370 , 380026
CVE-2021-3278Local Service Search Engine Management System 1.0 - SQLi Authentication Bypasslocal services search engine management system9.8 (v3.1)Critical340156 , 345493
CVE-2021-25864Hue Magic 3.0.0 - Local File Inclusionhuemagic7.5 (v3.1)High347009
CVE-2021-3223Node RED Dashboard <2.26.2 - Local File Inclusionnode-red-dashboard7.5 (v3.1)High347009
CVE-2020-27735Wing FTP 6.4.4 - Cross-Site Scriptingwing ftp server6.1 (v3.1)Medium346755 , 350148
CVE-2021-3110PrestaShop 1.7.7.0 - SQL Injectionprestashop9.8 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2020-19360FHEM 6.0 - Local File Inclusionfhem7.5 (v3.1)High344360 , 347009 , 390709
CVE-2020-35749WordPress Simple Job Board <2.9.4 - Local File Inclusionsimple board job7.7 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2021-20617Acmailer - Improper Access Control to OS Command Injectionacmailer,acmailer db9.8 (v3.1)Critical340014 , 344363
CVE-2021-3129Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Executionignition9.8 (v3.1)Critical340007 , 340077 , 340162 , 344365 , 398007
CVE-2020-24701OX Appsuite - Cross-Site Scriptingopen-xchange appsuite6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2020-35131Cockpit CMS 0.6.1 - Remote Code Executioncockpit9.8 (v3.1)Critical340095
CVE-2020-24902Quixplorer <=2.4.1 - Cross-Site Scriptingquixplorer6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2020-24903Cute Editor for ASP.NET 6.4 - Cross-Site Scriptingcute editor6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2021-23241MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusionmercury x18g firmware5.3 (v3.1)Medium347009
CVE-2021-3018IPeakCMS 3.5 - SQL Injectionipeakcms9.8 (v3.1)Critical380122
CVE-2021-21234Spring Boot Actuator Logview Directory Traversalspring-boot-actuator-logview7.7 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2020-17519Apache Flink - Local File Inclusionflink7.5 (v3.1)High390709
CVE-2021-3002Seo Panel 4.8.0 - Cross-Site Scriptingseo panel6.1 (v3.1)Medium333141 , 340147 , 346755
CVE-2020-29233WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scriptingwondercms5.4 (v3.1)Medium345493
CVE-2020-29477Invision Community 4.5.4 - 'Field Name' Stored Cross-Site Scriptingcommunity4.8 (v3.1)Medium340147 , 340148 , 342259 , 346755 , 390585
CVE-2020-35241Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scriptingflatpress4.8 (v3.1)Medium344370 , 346755 , 390724
CVE-2020-10148SolarWinds Orion API - Auth Bypassorion platform9.8 (v3.1)Critical390709
CVE-2020-35774twitter-server Cross-Site Scriptingtwitter-server5.4 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-29470OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scriptingopencart4.8 (v3.1)Medium340247 , 340248 , 340476 , 340477 , 341245 , 342259 , 346755 , 390585
CVE-2020-29475nopCommerce Store 4.30 - 'name' Stored Cross-Site Scriptingstore4.8 (v3.1)Medium346755
CVE-2020-35729Klog Server <=2.41 - Unauthenticated Command Injectionklog server9.8 (v3.1)Critical392301
CVE-2020-35736GateOne 1.1 - Local File Inclusiongateone7.5 (v3.1)High347009
CVE-2020-35713Belkin Linksys RE6500 <1.0.012.001 - Remote Command Executionre6500 firmware9.8 (v3.1)Critical392301
CVE-2020-28188TerraMaster TOS - Unauthenticated Remote Command Executiontos9.8 (v3.1)Critical340014 , 340193 , 344363 , 344370
CVE-2020-35598Advanced Comment System 1.0 - Local File Inclusionadvanced comment system7.5 (v3.1)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2020-24579D-Link DSL 2888a - Authentication Bypass/Remote Command Executiondsl2888a firmware8.8 (v3.1)High344360 , 347009 , 390904 , 392301
CVE-2020-35151Online Marriage Registration System 1.0 - 'searchdata' SQL Injectiononline marriage registration system8.8 (v3.1)High345493
CVE-2020-20300WeiPHP 5.0 - SQL Injectionweiphp9.8 (v3.1)Critical340157 , 340159 , 360147 , 360148
CVE-2020-25494SCO Openserver 5.0.7 - 'outputform' Command Injectionopenserver9.8 (v3.1)Critical344364 , 344366
CVE-2020-25495SCO Openserver 5.0.7 - 'section' Reflected XSSopenserver6.1 (v3.1)Medium340147 , 341266 , 342259 , 390585
CVE-2020-20285ZZcms - Cross-Site Scriptingzzcms5.4 (v3.1)Medium333141 , 340003 , 340099 , 341099 , 342259
CVE-2020-35545Spotweb 1.4.9 - 'search' SQL Injectionspotweb9.8 (v3.1)Critical340016 , 341245 , 380026 , 380122
CVE-2020-35476OpenTSDB <=2.4.0 - Remote Code Executionopentsdb9.8 (v3.1)Critical340014 , 340087 , 340095 , 340193 , 344370
CVE-2020-35416PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting)phpjabbers appointment scheduler6.1 (v3.1)Medium340003 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 , 390585
CVE-2020-29227Car Rental Management System 1.0 - Local File Inclusioncar rental management system9.8 (v3.1)Critical340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2020-17530Apache Struts 2.0.0-2.5.25 - Remote Code Executionstruts9.8 (v3.1)Critical344360 , 347009
CVE-2020-13945Apache APISIX - Insufficiently Protected Credentialsapisix6.5 (v3.1)Medium344363 , 380026
CVE-2020-26248PrestaShop Product Comments <4.2.0 - SQL Injectionproductcomments8.2 (v3.1)High341245 , 380026 , 380122
CVE-2020-2927974CMS - Remote File Inclusion74cms9.8 (v3.1)Critical340128 , 344363 , 380018
CVE-2020-29240LEPTON CMS 4.7.0 - 'URL' Persistent Cross-Site Scriptingleptoncms4.8 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 398005
CVE-2020-29390Zeroshell 3.9.3 - Command Injectionzeroshell9.8 (v3.1)Critical340023 , 341245 , 344360 , 344361 , 344363 , 344370 , 347009
CVE-2020-29395Wordpress EventON Calendar 3.0.5 - Cross-Site Scriptingeventon6.1 (v3.1)Medium333141 , 342259 , 347198 , 350148
CVE-2020-12262Intelbras TIP200/TIP200LITE/TIP300 - Cross-Site Scriptingtip3005.4 (v3.1)Medium340147 , 341266 , 342259
CVE-2020-13886Intelbras TIP 200/200 LITE/300 - Local File Inclusiontip200 firmware5.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2020-13942Apache Unomi <1.5.2 - Remote Code Executionunomi9.8 (v3.1)Critical340095
CVE-2020-26217XStream <1.4.14 - Remote Code Executionxstream8.8 (v3.1)High344363 , 344366
CVE-2020-27191LionWiki <3.2.12 - Local File Inclusionlionwiki7.5 (v3.1)High344360 , 347009
CVE-2020-27481Good Layers LMS Plugin <= 2.1.4 - SQL Injectiongood learning management system9.8 (v3.1)Critical322102 , 340016 , 380122
CVE-2020-28351Mitel ShoreTel 19.46.1802.0 Devices - Cross-Site Scriptingshoretel6.1 (v3.1)Medium341266
CVE-2020-14750Oracle WebLogic Server - Remote Command Executionfusion middleware9.8 (v3.1)Critical337209 , 337210 , 337211 , 340014 , 340029 , 340095 , 344361 , 344362 , 344370 , 380026
CVE-2020-24881OsTicket < 1.14.3 - Server Side Request Forgeryosticket9.8 (v3.1)Critical340147 , 340148
CVE-2020-27982IceWarp WebMail 11.4.5.0 - Cross-Site Scriptingmail server6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2020-27533DedeCMS v.5.8 - keyword Cross-Site Scriptingdedecms5.4 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 345493 , 346755 , 350147 , 350148 , 390585
CVE-2020-27615WordPress Loginizer < 1.6.4 – Unauthenticated SQL Injection via log Parameterloginizer9.8 (v3.1)Critical340156 , 341245 , 380026 , 380122
CVE-2020-14864Oracle Fusion - Directory Traversal/Local File Inclusionbusiness intelligence7.5 (v3.1)High344360 , 347009 , 390709 , 390716
CVE-2020-14883Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Executionweblogic server7.2 (v3.1)High380026
CVE-2020-3580Cisco ASA/FTD Software - Cross-Site Scriptingfirepower threat defense6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2020-7318McAfee ePolicy Orchestrator <5.10.9 Update 9 - Cross-Site Scriptingepolicy orchestrator4.3 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198
CVE-2020-26935phpMyAdmin < 5.0.3 - SQL Injectionphpmyadmin9.8 (v3.1)Critical340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2020-26919NETGEAR ProSAFE Plus - Unauthenticated Remote Code Executionjgs516pe firmware9.8 (v3.1)Critical392301
CVE-2020-25760Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)visitor management system8.8 (v3.1)High390727 , 392301 , 392648
CVE-2020-25223Sophos UTM Preauth - Remote Code Executionunified threat management9.8 (v3.1)Critical340014 , 344364 , 344366
CVE-2020-11991Apache Cocoon 2.1.12 - XML Injectioncocoon7.5 (v3.1)High344372
CVE-2020-25213WordPress File Manager Plugin - Remote Code Executionfile manager9.8 (v3.1)Critical393781
CVE-2020-2036Palo Alto Networks PAN-OS Web Interface - Cross Site-Scriptingpan-os8.8 (v3.1)High347198
CVE-2020-24963Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated)best support system5.4 (v3.1)Medium333141 , 344370 , 360151
CVE-2020-24193Daily Tracker System 1.0 - Authentication Bypassdaily tracker system9.8 (v3.1)Critical340145 , 340156 , 341145 , 345493 , 390572
CVE-2020-24949PHP-Fusion 9.03.50 - Remote Code Executionphp-fusion8.8 (v3.1)High393655
CVE-2020-23814XXL-JOB v2.2.0 — Stored Cross Site Scriptingxxl-job6.1 (v3.1)Medium333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2020-5776MAGMI - Cross-Site Request Forgerymagmi8.8 (v3.1)High344364 , 344366 , 344370 , 345490
CVE-2020-24223Mara CMS 7.5 - Cross-Site Scriptingmara cms6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2020-24609Savsoft Quiz 5 - Stored Cross-Site Scriptingsavsoft quiz6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2020-24589WSO2 API Manager <=3.1.0 - Blind XML External Entity Injectionapi manager9.1 (v3.1)Critical341256 , 344370 , 344372 , 380018
CVE-2020-5775Canvas LMS v2020-07-29 - Blind Server-Side Request Forgerycanvas learning management service5.8 (v3.1)Medium340162 , 340163
CVE-2020-17456SEOWON INTECH SLC-130 & SLR-120S - Unauthenticated Remote Code Executionslc-1309.8 (v3.1)Critical340014 , 344363 , 344370
CVE-2020-8209Citrix XenMobile Server - Local File Inclusionxenmobile server7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2019-6112WordPress Sell Media 2.4.1 - Cross-Site Scriptingsell media6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2020-17463Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)fuel cms9.8 (v3.1)Critical340016 , 341245 , 380026 , 380122 , 390727 , 392301 , 392648
CVE-2020-17496vBulletin 5.5.4 - 5.6.2- Remote Command Executionvbulletin9.8 (v3.1)Critical340007 , 344360 , 344370 , 390709
CVE-2020-17506Artica Web Proxy 4.30 - Authentication Bypass/SQL Injectionweb proxy9.8 (v3.1)Critical340017 , 340157 , 341245 , 360147 , 360148
CVE-2020-17505Artica Web Proxy 4.30 - OS Command Injectionweb proxy8.8 (v3.1)High340017 , 340157 , 341245 , 344364 , 344366 , 360147 , 360148
CVE-2020-17362Nova Lite < 1.3.9 - Cross-Site Scriptingnova lite6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-11984Apache HTTP Server - Remote Code Executionhttp server9.8 (v3.1)Critical344363 , 390614 , 390626 , 390724
CVE-2020-9036Jeedom <=4.0.38 - Cross-Site Scriptingjeedom6.1 (v3.1)Medium346755
CVE-2020-13820Extreme Management Center 8.4.1.24 - Cross-Site Scriptingextreme management center6.1 (v3.1)Medium333141 , 340149 , 342259 , 346755
CVE-2020-11110Grafana <= 6.7.1 - Cross-Site Scriptinggrafana5.4 (v3.1)Medium346755 , 350148
CVE-2020-15920Mida eFramework <=2.9.0 - Remote Command Executioneframework9.8 (v3.1)Critical340023 , 344360 , 344361 , 344363 , 347009
CVE-2020-15895D-Link DIR-816L 2.x - Cross-Site Scriptingdir-816l firmware6.1 (v3.1)Medium346755
CVE-2020-11978Apache Airflow <=1.10.10 - Remote Code Executionairflow8.8 (v3.1)High344364
CVE-2020-15718RosarioSIS 6.7.2 - Cross-Site Scriptingrosariosis6.1 (v3.1)Medium333141 , 340149 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2020-11546SuperWebmailer 7.21.0.01526 - Remote Code Executionsuperwebmailer9.8 (v3.1)Critical340095 , 393655
CVE-2020-10987Tenda AC15 AC1900 version 15.03.05.19 - Command Injectionac15 firmware9.8 (v3.1)Critical340014 , 344364 , 344366 , 344370
CVE-2020-5766SRS Simple Hits Counter 1.0.3-1.0.4 - Unauthenticated Blind SQL Injectionsrs simple hits counter7.5 (v3.1)High340016 , 340017 , 340144 , 360147 , 360148 , 380122 , 380123
CVE-2020-8191Citrix ADC/Gateway - Cross-Site Scriptingapplication delivery controller firmware6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2020-15505MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Executioncore9.8 (v3.1)Critical391213
CVE-2020-15599Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scriptingvictor cms6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 345493 , 346755 , 350148
CVE-2020-8163Ruby on Rails <5.0.1 - Remote Code Executionrails8.8 (v3.1)High340023 , 344360 , 344370 , 347009 , 390724
CVE-2020-5902F5 BIG-IP TMUI - Remote Code Executionbig-ip access policy manager9.8 (v3.1)Critical344360 , 347009 , 390709 , 390714 , 392301
CVE-2020-15500TileServer GL <=3.0.0 - Cross-Site Scriptingtileservergl6.1 (v3.1)Medium333141 , 341245 , 341256 , 342259 , 346755 , 350147
CVE-2020-15415DrayTek Vigor - Command Injectionvigor9.8 (v3.1)Critical390700
CVE-2020-9483SkyWalking SQLIskywalking7.5 (v3.1)High341250
CVE-2020-14413NeDi 1.9C - Cross-Site Scriptingnedi6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2020-13483Bitrix24 <=20.0.0 - Cross-Site Scriptingbitrix246.1 (v3.1)Medium344363 , 344370 , 346755 , 390722
CVE-2020-15038Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scriptingcoming soon page, under construction &amp; maintenance mode5.4 (v3.1)Medium345493
CVE-2020-9480Apache Spark - Authentication Bypassspark9.8 (v3.1)Critical340162 , 340163
CVE-2020-13158Artica Proxy Community Edition <4.30.000000 - Local File Inclusionartica proxy7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2020-13640wpDiscuz <= 5.3.5 - SQL Injectionwpdiscuz9.8 (v3.1)Critical331028 , 340016 , 340155 , 341155 , 360147 , 360148 , 380026
CVE-2020-14408Agentejo Cockpit 0.10.2 - Cross-Site Scriptingcockpit6.1 (v3.1)Medium346755
CVE-2020-13851Artica Pandora FMS 7.44 - Remote Code Executionpandora fms8.8 (v3.1)High344360 , 347009
CVE-2020-11798Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversalmicollab audio, web &amp; video conferencing5.3 (v3.1)Medium340007 , 344360 , 347009
CVE-2020-12800WordPress Contact Form 7 <1.3.3.3 - Remote Code Executiondrag and drop multiple file upload - contact form 79.8 (v3.1)Critical300018
CVE-2020-11975Apache Unomi - Remote Code Executionunomi9.8 (v3.1)Critical337210
CVE-2020-10546rConfig 3.9.4 - SQL Injectionrconfig9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380123
CVE-2020-10547rConfig 3.9.4 - SQL Injectionrconfig9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380123
CVE-2020-10548rConfig 3.9.4 - SQL Injectionrconfig9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380123
CVE-2020-10549rConfig <=3.9.4 - SQL Injectionrconfig9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148 , 380123
CVE-2020-13379Grafana 3.0.1-7.0.1 - Server-Side Request Forgerygrafana8.2 (v3.1)High340165
CVE-2020-5410Spring Cloud Config Server - Local File Inclusionspring cloud config7.5 (v3.1)High390709
CVE-2020-1106Microsoft Office SharePoint XSS Vulnerabilitysharepoint enterprise server6.1 (v3.1)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2020-13258Contentful <=2020-05-21 - Cross-Site Scriptingpython example6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-13167Netsweeper <=6.4.3 - Python Code Injectionnetsweeper9.8 (v3.1)Critical340087 , 340095 , 390810
CVE-2020-12256rConfig 3.9.4 - Cross-Site Scriptingrconfig5.4 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-12259rConfig 3.9.4 - Cross-Site Scriptingrconfig5.4 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-13121Submitty <= 20.04.01 - Open Redirectsubmitty6.1 (v3.1)Medium340162 , 340163
CVE-2020-12832WordPress Simple File List - Path TraversalSimple File List WordPress Plugin9.8 (v3.1)Critical382238
CVE-2020-9314Oracle iPlanet Web Server 7.0.x - Image Injectioniplanet web server4.8 (v3.1)Medium340162 , 340163
CVE-2020-11530WordPress Chop Slider 3 - Blind SQL Injectionchop slider9.8 (v3.1)Critical340016 , 380026 , 380122
CVE-2020-12720vBulletin SQL Injectionvbulletin9.8 (v3.1)Critical340016 , 340017 , 340155 , 340157 , 340159 , 341155 , 341245 , 360147 , 360148
CVE-2020-10973WAVLINK - Access Controlwn530hg4 firmware7.5 (v3.1)High390716
CVE-2020-8982Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Readsharefile storagezones controller7.5 (v3.1)High340007
CVE-2020-12707LeptonCMS 4.5.0 - Persistent Cross-Site Scriptinglepton cms6.1 (v3.1)Medium345493
CVE-2020-12706php-fusion 9.03.50 - Persistent Cross-Site Scriptingphp-fusion5.4 (v3.1)Medium340147 , 340148 , 341256 , 346755
CVE-2020-12641Roundcube Webmail - Command Injectionwebmail9.8 (v3.1)Critical340014
CVE-2020-6010WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated)learnpress8.8 (v3.1)High341245 , 345493 , 380026 , 380122
CVE-2020-12447Onkyo TX-NR585 Web Interface - Directory Traversaltx-nr585 firmware7.5 (v3.1)High347009
CVE-2020-12054WordPress Catch Breadcrumb <1.5.4 - Cross-Site Scriptingcatch breadcrumb6.1 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2020-11930WordPress GTranslate <2.8.52 - Cross-Site Scriptingtranslate wordpress with gtranslate6.1 (v3.1)Medium340147 , 341266 , 346755
CVE-2020-11738WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusionduplicator7.5 (v3.1)High323769 , 336461 , 340748 , 344360 , 347006 , 347009 , 381206 , 390709
CVE-2020-6171CLink Office 2.0 - Cross-Site Scriptingclink office6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-8639TestLink 1.9.20 - Unrestricted File Upload (Authenticated)testlink8.8 (v3.1)High345493
CVE-2019-17231WordPress OneTone theme <= 3.0.6 – Unauthenticated Stored XSSonetone6.1 (v3.1)Medium346755
CVE-2019-17564Apache Dubbo 2.5.x-2.7.4 - Insecure Deserializationdubbo9.8 (v3.1)Critical344370 , 344380 , 390614 , 390626 , 390724
CVE-2020-11455LimeSurvey 4.1.11 - Local File Inclusionlimesurvey9.8 (v3.1)Critical344360 , 347009
CVE-2020-1943Apache OFBiz <=16.11.07 - Cross-Site Scriptingofbiz6.1 (v3.1)Medium347198
CVE-2020-11456LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scriptinglimesurvey5.4 (v3.1)Medium333141 , 340147 , 340148 , 342259 , 346755
CVE-2020-11457pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scriptingpfsense5.4 (v3.1)Medium333141 , 342259 , 345493
CVE-2020-9467Piwigo 2.10.1 - Cross Site Scriptingpiwigo5.4 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755
CVE-2020-10385WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scriptingcontact form5.4 (v3.1)Medium345493 , 346755
CVE-2020-5722Grandstream UCM6200 - SQL Injectionucm6200 firmware9.8 (v3.1)Critical340145 , 340156 , 341145 , 341245 , 344364 , 344366 , 390572 , 393655
CVE-2019-16072Enigma NMS < 65.0.0 - Authenticated OS Command Injectionenigma network management solution9.8 (v3.1)Critical344364
CVE-2020-9344Jira Subversion ALM for Enterprise <8.8.2 - Cross-Site Scriptingsubversion application lifecycle management6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-10257ThemeREX Addons - Remote Code Executionthemerex9.8 (v3.1)Critical377360
CVE-2019-20504Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Remote Code Executionkace systems management9.8 (v3.1)Critical340014 , 340029 , 344363
CVE-2020-10221rConfig <= 3.9.4 - Authenticated OS Command Injectionrconfig8.8 (v3.1)High344364 , 344366
CVE-2020-10220rConfig 3.9 - SQL Injectionrconfig9.8 (v3.1)Critical340016 , 340017 , 340144 , 340157 , 341245 , 360147 , 360148
CVE-2020-10189ManageEngine Desktop Central Java Deserializationmanageengine desktop central9.8 (v3.1)Critical340007 , 344365 , 344380 , 347019
CVE-2020-10173Comtrend VR-3033 - Command Injectionvr-3033 firmware8.8 (v3.1)High344361 , 344363
CVE-2019-20499D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High330791 , 340152 , 344361 , 344363 , 344364 , 344366 , 390726 , 392647
CVE-2019-20500D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High330791 , 340152 , 344361 , 344363 , 344364 , 344366 , 390726 , 392647
CVE-2019-20501D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High330791 , 340152 , 344361 , 344363 , 344364 , 344366 , 390726 , 392647
CVE-2020-5405Spring Cloud Config - Local File Inclusionspring cloud config6.5 (v3.1)Medium390709
CVE-2020-9054Zyxel NAS Firmware 5.21- Remote Code Executionnas326 firmware9.8 (v3.1)Critical312659 , 340023 , 344360 , 344361 , 344363 , 344370 , 347009
CVE-2020-9547FasterXML jackson-databind - Deserialization Remote Code Executionjackson-databind9.8 (v3.1)Critical398008
CVE-2020-9548FasterXML Jackson Databind <=2.9.10.4 - Remote Code Executionjackson-databind9.8 (v3.1)Critical398008
CVE-2019-19134WordPress Hero Maps Premium <=2.2.1 - Cross-Site Scriptinghero maps premium6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2020-8813Cacti v1.2.8 - Remote Code Executioncacti8.8 (v3.1)High340014
CVE-2014-9614Netsweeper 4.0.5 - Default Weak Accountnetsweeper9.8 (v3.1)Critical392301
CVE-2014-9606Netsweeper 4.0.8 - Cross-Site Scriptingnetsweeper6.1 (v3.1)Medium341266 , 346755
CVE-2014-9607Netsweeper 4.0.4 - Cross-Site Scriptingnetsweeper6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-9608Netsweeper 4.0.3 - Cross-Site Scriptingnetsweeper6.1 (v3.1)Medium341266
CVE-2014-9615Netsweeper 4.0.4 - Cross-Site Scriptingnetsweeper6.1 (v3.1)Medium341266 , 346755
CVE-2014-9609Netsweeper 4.0.8 - Directory Traversalnetsweeper5.3 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2015-6970Bosch Security Systems Dinion NBN-498 - Web Interface XML Injectionnbn-498 dinion2x day/night ip cameras firmware9.8 (v3.1)Critical390726 , 392301 , 392647 , 392648
CVE-2013-2679Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmware6.1 (v3.1)Medium392301
CVE-2020-9043WordPress wpCentral <1.5.1 - Information Disclosurewpcentral8.8 (v3.1)High377360
CVE-2020-7209LinuxKI Toolset <= 6.01 - Remote Command Executionlinuxki9.8 (v3.1)Critical340029 , 344360 , 344361 , 344363 , 347009
CVE-2014-8739WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File Uploadcreative contact form9.8 (v3.1)Critical300016
CVE-2020-8656EyesOfNetwork - Hardcoded API Key & SQL Injectioneyesofnetwork9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 360147 , 360148 , 380026 , 380122
CVE-2020-8771WordPress Time Capsule < 1.21.16 - Authentication Bypasswp time capsule9.8 (v3.1)Critical392301
CVE-2013-2684Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmware6.1 (v3.1)Medium392301
CVE-2013-2683Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmware5.3 (v3.1)Medium392301
CVE-2013-2681Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmware9.8 (v3.1)Critical392301
CVE-2020-8641Lotus Core CMS 1.0.1 - Local File Inclusionlotus core cms8.8 (v3.1)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2013-2680Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmware7.5 (v3.1)High392301
CVE-2013-2682Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmware4.3 (v3.1)Medium392301
CVE-2012-5686ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Resetzpanel9.8 (v3.1)Critical340016 , 340017 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 360147 , 360148 , 390704
CVE-2013-2678Cisco Linksys E4200 - Multiple Vulnerabilitieslinksys e4200 firmware8.1 (v3.1)High392301
CVE-2020-8615Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgerytutor lms6.5 (v3.1)Medium345490 , 377360
CVE-2020-8115Revive Adserver <=5.0.3 - Cross-Site Scriptingrevive adserver6.1 (v3.1)Medium346755 , 350148
CVE-2013-2621Telaen => v1.3.1 - Open Redirecttelaen6.1 (v3.1)Medium320007
CVE-2020-8549WordPress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scriptingstrong testimonials6.1 (v3.1)Medium345493 , 346755
CVE-2020-8515Multiple DrayTek Products - Pre-authentication Remote Root Code Executionvigor2960 firmware9.8 (v3.1)Critical392301
CVE-2020-8512IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scriptingicewarp server6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198
CVE-2013-4864MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware9.8 (v3.1)Critical330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2013-4863MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware8.8 (v3.1)High330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2013-4862MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware8.1 (v3.1)High330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2013-4861MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware6.5 (v3.1)Medium330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2013-4865MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmware6.5 (v3.1)Medium330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2019-19824TOTOLINK Realtek SD Routers - Remote Command Injectiona3002ru firmware8.8 (v3.1)High340014
CVE-2019-19822TOTOLINK/Realtek Routers - Information Disclosurea3002ru firmware7.5 (v3.1)High390716
CVE-2019-19823TOTOLINK/Realtek Routers - Information Disclosurea3002ru firmware7.5 (v3.1)High390716
CVE-2020-7991Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)framework8.8 (v3.1)High340147 , 340148 , 342259 , 345490 , 345493 , 346755 , 350147 , 350148 , 398001
CVE-2020-7980Satellian Intellian Aptus Web <= 1.24 - Remote Command Executionaptus web9.8 (v3.1)Critical344360
CVE-2019-19411Huawei Firewall - Local File Inclusionusg95003.7 (v3.1)Low347009 , 390709
CVE-2020-7107WordPress Ultimate FAQ <1.8.30 - Cross-Site Scriptingultimate faq6.1 (v3.1)Medium333140 , 333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2020-7108WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scriptinglearndash5.4 (v3.1)Medium340003 , 341266 , 346755 , 390585 , 390727 , 392301 , 392648
CVE-2019-16469Adobe Experience Manager - Expression Language Injectionexperience manager7.5 (v3.1)High393655
CVE-2011-4336Tiki Wiki CMS Groupware 7.0 Cross-Site Scriptingtikiwiki cms/groupware6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2020-2096Jenkins Gitlab Hook <=1.4.2 - Cross-Site Scriptinggitlab hook6.1 (v3.1)Medium341266
CVE-2019-20210WordPress CTHthemes - Cross-Site Scriptingcitybook6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-4561Ultimate Weather Plugin <= 1.0 - Cross-Site Scriptingultimate-weather6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2012-1259Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilitiesscrutinizer netflow &amp; sflow analyzer9.8 (v3.1)Critical340003 , 340147 , 340148 , 340156 , 341245 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585 , 390727 , 392301 , 392648
CVE-2019-20224Pandora FMS 7.0NG - Remote Command Injectionpandora fms8.8 (v3.1)High344363
CVE-2020-5504phpMyAdmin 5.0.0 - SQL Injectionphpmyadmin8.8 (v3.1)High340145 , 340156 , 341145 , 390727 , 392301 , 392648
CVE-2012-1258Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilitiesscrutinizer netflow &amp; sflow analyzer6.5 (v3.1)Medium340003 , 340147 , 340148 , 340156 , 341245 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585 , 390727 , 392301 , 392648
CVE-2012-1260Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilitiesscrutinizer netflow &amp; sflow analyzer6.1 (v3.1)Medium340003 , 340147 , 340148 , 340156 , 341245 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585 , 390727 , 392301 , 392648
CVE-2012-1261Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilitiesscrutinizer netflow &amp; sflow analyzer6.1 (v3.1)Medium340003 , 340147 , 340148 , 340156 , 341245 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585 , 390727 , 392301 , 392648
CVE-2019-18859Digi AnywhereUSB 14 - Reflective Cross-Site Scriptinganywhereusb/14 firmware6.1 (v3.1)Medium340147 , 341266 , 346755 , 390727 , 392301 , 392648
CVE-2014-8673SO Planning 1.32 - Multiple Vulnerabilitiessoplanning9.8 (v3.1)Critical331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647
CVE-2020-5307PHPGurukul Dairy Farm Shop Management System 1.0 - SQL Injectiondairy farm shop management system9.8 (v3.1)Critical340145 , 340156 , 341145
CVE-2020-5192Hospital Management System 4.0 - 'searchdata' SQL Injectionhospital management system8.8 (v3.1)High331028 , 340016 , 340017 , 340144 , 340157 , 345493 , 360147 , 360148 , 390727 , 392301 , 392648
CVE-2020-5191Hospital Management System 4.0 - Persistent Cross-Site Scriptinghospital management system6.1 (v3.1)Medium342259 , 345493
CVE-2014-8674SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.4 (v3.1)Medium331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647
CVE-2019-9553Bolt CMS 3.6.4 - Cross-Site Scriptingbolt6.1 (v3.1)Medium340148 , 341256 , 346755
CVE-2019-9556Fiberhome AN5506-04-F RP2669 - Persistent Cross-Site Scriptingan5506-04-f firmware5.4 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2019-20141WordPress Laborator Neon Theme 2.0 - Cross-Site Scriptingneon6.1 (v3.1)Medium333141 , 340099 , 340147 , 341099 , 342259 , 347198 , 350147 , 350148
CVE-2019-19781Citrix ADC and Gateway - Directory Traversalapplication delivery controller firmware9.8 (v3.1)Critical390716
CVE-2014-4535Import Legacy Media <= 0.1 - Cross-Site Scriptingimport legacy media6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-4536Infusionsoft Gravity Forms Add-on < 1.5.7 - Cross-Site Scriptinginfusionsoft gravity forms6.1 (v3.1)Medium333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-4539Movies <= 0.6 - Cross-Site Scriptingmovies6.1 (v3.1)Medium333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-4544Podcast Channels < 0.28 - Cross-Site Scriptingpodcast channels6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-4550Shortcode Ninja <= 1.4 - Cross-Site Scriptingninja6.1 (v3.1)Medium340147 , 341266
CVE-2014-4558WooCommerce Swipe <= 2.7.1 - Cross-Site Scriptingswipehq-payment-gateway-woocommerce6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 350147 , 350148
CVE-2014-4592WP Planet <= 0.1 - Cross-Site Scriptingwp-planet6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2019-10758mongo-express Remote Code Executionmongo-express9.9 (v3.1)Critical345240 , 360151 , 380026
CVE-2019-19908phpMyChat-Plus 1.98 - Cross-Site Scriptingphpmychat-plus6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-19742D-Link DIR-615 Wireless Router - Persistent Cross-Site Scriptingdir-615 firmware4.8 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 344370 , 350147
CVE-2019-7481SonicWall SRA 4600 VPN - SQL Injectionsma 100 firmware7.5 (v3.1)High340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2019-19731Roxy Fileman 1.4.5 - Directory Traversalroxy fileman7.5 (v3.1)High340007
CVE-2019-19743D-Link DIR-615 - Privilege Escalationdir-615 t1 firmware6.5 (v3.1)Medium345493
CVE-2019-19368Rumpus FTP Web File Manager 8.2.9.1 - Cross-Site Scriptingrumpus6.1 (v3.1)Medium342259 , 350147
CVE-2019-19740Octeth Oempro 4.8 - 'CampaignID' SQL Injectionoempro9.8 (v3.1)Critical392301
CVE-2019-17270Yachtcontrol Webapplication 1.0 - Remote Command Injectionyachtcontrol9.8 (v3.1)Critical344360 , 347009 , 390904
CVE-2019-14251T24 Web Server - Local File Inclusiont247.5 (v3.1)High344360 , 347009 , 390709
CVE-2018-7282TITool PrintMonitor - Blind SQL Injectionprintmonitor9.8 (v3.1)Critical344370
CVE-2019-7194QNAP Photo Station < 6.0.3 - Remote Code Executionphoto station9.8 (v3.1)Critical340128 , 380018 , 380026 , 390801
CVE-2019-17554Apache Olingo OData 4.0 - XML External Entity Injectionolingo5.5 (v3.1)Medium344372 , 345493
CVE-2019-18922Allied Telesis AT-GS950/8 - Local File Inclusionat-gs950/8 firmware7.5 (v3.1)High347009
CVE-2011-3600Apache OFBiz - XML External Entity Injectionofbiz7.5 (v3.1)High344372
CVE-2014-8356ZHONE < S3.0.501 - Multiple Vulnerabilitiesznid 2426a firmware8.8 (v3.1)High390726 , 392301 , 392647 , 392648
CVE-2019-16758Lexmark Services Monitor 2.27.4.0.39 - Directory Traversalservices monitor firmware7.5 (v3.1)High346019
CVE-2019-18957MicroStrategy Library <11.1.3 - Cross-Site Scriptingmicrostrategy library6.1 (v3.1)Medium346755 , 347198
CVE-2012-5193Bitweaver 2.8.1 - Multiple Vulnerabilitiesbitweaver6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 380026
CVE-2019-18665DOMOS 5.5 - Local File Inclusiondomos7.5 (v3.1)High344360 , 347009 , 390709
CVE-2019-18396Technicolor TD5130.2 - Remote Command Executiontd5130v2 firmware7.2 (v3.1)High344361 , 344363
CVE-2019-9757LabKey Server 19.1.0 - XML External Entity (XXE)labkey server7.5 (v3.1)High340029 , 341256 , 342259 , 344360 , 344372 , 380018
CVE-2010-4239Tiki Wiki CMS Groupware 5.2 - Local File Inclusiontikiwiki cms/groupware9.8 (v3.1)Critical340007 , 390109
CVE-2019-11043PHP-FPM Path Info Buffer Underflow - Remote Code Executionphp9.8 (v3.1)Critical390714
CVE-2019-16662rConfig 3.9.2 - Remote Code Executionrconfig9.8 (v3.1)Critical340029 , 344360 , 344361 , 344363 , 347009
CVE-2019-8086Adobe Experience Manager - XML External Entity Injectionexperience manager7.5 (v3.1)High330925
CVE-2019-18393Ignite Realtime Openfire <4.42 - Local File Inclusionopenfire5.3 (v3.1)Medium344365 , 347019
CVE-2019-18371Xiaomi Mi WiFi R3G Routers - Local file Inclusionmillet router 3g firmware7.5 (v3.1)High347009 , 390709
CVE-2019-10475Jenkins build-metrics 1.3 - Cross-Site Scriptingbuild-metrics6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2015-9499WordPress ShowBiz Pro <= 1.7.1 - Authenticated Arbitrary File Upload to RCEshowbiz pro9.8 (v3.1)Critical300019 , 300029
CVE-2019-11253Kubernetes API Server - YAML Parsing DoS (Billion Laughs)kubernetes7.5 (v3.1)High391213
CVE-2019-13392MindPalette NateMail 3.0.15 - Cross-Site Scriptingnatemail6.1 (v3.1)Medium342259 , 350147 , 350148
CVE-2019-16278nostromo 1.9.6 - Remote Code Executionnostromo nhttpd9.8 (v3.1)Critical390714 , 392301
CVE-2019-17538Jiangnan Online Judge 0.8.0 - Local File Inclusionjiangnan online judge7.5 (v3.1)High340007 , 344360 , 347009
CVE-2019-17506D-Link DIR-868L/817LW - Information Disclosuredir-868l b1 firmware9.8 (v3.1)Critical330791 , 340152
CVE-2019-17504Kirona-DRS 5.5.3.5 - Information Disclosuredynamic resource scheduling6.1 (v3.1)Medium312863 , 340147 , 340148 , 341266 , 342259 , 344370 , 346755 , 390716
CVE-2019-17503Kirona-DRS 5.5.3.5 - Information Disclosuredynamic resource scheduling5.3 (v3.1)Medium312863 , 340147 , 340148 , 341266 , 342259 , 344370 , 346755 , 390716
CVE-2015-9480WordPress RobotCPA 5 - Directory Traversalrobotcpa7.5 (v3.1)High320006
CVE-2019-17418MetInfo 7.0.0 beta - SQL Injectionmetinfo7.2 (v3.1)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2019-16931WordPress Visualizer <3.3.1 - Cross-Site Scriptingvisualizer6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2019-16932Visualizer <3.3.1 - Blind Server-Side Request Forgeryvisualizer10.0 (v3.1)Critical344362
CVE-2019-16996Metinfo 7.0.0 beta - SQL Injectionmetinfo7.2 (v3.1)High340016 , 340017 , 340157 , 360147 , 360148
CVE-2019-16997Metinfo 7.0.0 beta - SQL Injectionmetinfo7.2 (v3.1)High340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2019-16920D-Link Routers - Remote Code Executiondir-655 firmware9.8 (v3.1)Critical340023 , 344360 , 344361 , 344363 , 344365 , 344366
CVE-2015-9414WordPress Symposium <=15.8.1 - Cross-Site Scriptingwp-symposium6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-10092Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scriptinghttp server6.1 (v3.1)Medium344365
CVE-2019-16759vBulletin 5.0.0-5.5.4 - Remote Command Executionvbulletin9.8 (v3.1)Critical341245
CVE-2019-16383MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injectionmoveit transfer9.4 (v3.1)Critical344366 , 361149 , 380026 , 380122
CVE-2019-16693phpIPAM 1.4 - SQL-Injectionphpipam9.8 (v3.1)Critical340016 , 340017 , 340157
CVE-2015-9406mTheme Unus < 2.3 - Directory Traversalmtheme-unus7.5 (v3.1)High336461 , 340007 , 344360 , 381206
CVE-2019-16525WordPress Checklist <1.1.9 - Cross-Site Scriptingchecklist6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-10976Safe Editor Plugin < 1.2 - CSS/JS-injectionsafe editor6.1 (v3.1)Medium346755
CVE-2016-10993ScoreMe Theme - Cross-Site Scriptingscoreme5.4 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-10960WordPress wSecure Lite < 2.4 - Remote Code Executionwsecure8.8 (v3.1)High392301
CVE-2016-10956WordPress Mail Masta 1.0 - Local File Inclusionmail-masta7.5 (v3.1)High344360 , 347009 , 390709
CVE-2016-10973Brafton WordPress Plugin < 3.4.8 - Cross-Site Scriptingbrafton6.1 (v3.1)Medium346755 , 347198
CVE-2019-16332WordPress API Bearer Auth <20190907 - Cross-Site Scriptingapi bearer auth6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-10940WordPress zm-gallery plugin 1.0 SQL Injectionzm-gallery7.2 (v3.1)High340017 , 340156 , 340157
CVE-2019-3759RSA IG&L Aveksa 7.1.1 - Remote Code Executionrsa identity governance and lifecycle8.1 (v3.1)High330791 , 340152
CVE-2017-18598WordPress Qards - Cross-Site Scriptingqards6.1 (v3.1)Medium393749
CVE-2019-16123PilusCart <=1.4.1 - Local File Inclusionpiluscart7.5 (v3.1)High344360 , 347009 , 390709
CVE-2019-6793GitLab Enterprise Edition - Server-Side Request Forgerygitlab7.0 (v3.1)High390616
CVE-2019-15813Sentrifugo 3.2 - File Upload Restriction Bypasssentrifugo8.8 (v3.1)High345493
CVE-2019-14470WordPress UserPro 4.9.32 - Cross-Site Scriptinginstagram-php-api6.1 (v3.0)Medium333141 , 347198
CVE-2019-15889WordPress Download Manager <2.9.94 - Cross-Site Scriptingwordpress download manager6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2019-15829Gallery Photoblocks < 1.1.43 - Cross-Site Scriptinggallery photoblocks4.8 (v3.0)Medium346755 , 347198
CVE-2019-13608Citrix StoreFront Server - XML External Entitystorefront server7.5 (v3.1)High344372 , 391213
CVE-2019-15811DomainMOD <=4.13.0 - Cross-Site Scriptingdomainmod6.1 (v3.0)Medium333141 , 340149 , 341256 , 342259 , 346755
CVE-2019-15713WordPress My Calendar <= 3.1.9 - Cross-Site Scriptingmy calendar6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2017-18590Timesheet Plugin < 0.1.5 - Cross-Site Scriptingtimesheet6.1 (v3.0)Medium341266 , 346755 , 377360
CVE-2019-13237Alkacon OpenCMS 10.5.x - Local File inclusionopencms apollo template4.3 (v3.1)Medium392301
CVE-2019-15642Webmin < 1.920 - Authenticated Remote Code Executionwebmin8.8 (v3.0)High344362 , 344366
CVE-2019-15501L-Soft LISTSERV <16.5-2018a - Cross-Site Scriptinglistserv6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-8446Jira Improper Authorizationjira server5.3 (v3.1)Medium392301
CVE-2017-18580WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Executionshortcodes ultimate9.8 (v3.0)Critical377360
CVE-2018-20985WordPress Payeezy Pay <=2.97 - Local File Inclusionwp payeezy pay9.8 (v3.0)Critical392301
CVE-2016-10924Wordpress Zedna eBook download <1.2 - Local File Inclusionzedna ebook download7.5 (v3.0)High336461 , 340007 , 344360 , 381206
CVE-2019-11013Nimble Streamer <=3.5.4-9 - Local File Inclusionnimble streamer6.5 (v3.0)Medium347009
CVE-2019-1935Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilitiesintegrated management controller supervisor9.8 (v3.1)Critical344362 , 344363 , 344370 , 345493 , 350147 , 360151 , 390724 , 390727 , 392301 , 392648
CVE-2019-1937Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilitiesintegrated management controller supervisor9.8 (v3.0)Critical344362 , 344363 , 344370 , 345493 , 350147 , 360151 , 390724 , 390727 , 392301 , 392648
CVE-2019-1936Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilitiesintegrated management controller supervisor7.2 (v3.1)High344362 , 344363 , 344370 , 345493 , 350147 , 360151 , 390724 , 390727 , 392301 , 392648
CVE-2017-18516LinkedIn by BestWebSoft < 1.0.5 - Cross-Site Scriptinglinkedin6.1 (v3.0)Medium341266 , 346755
CVE-2017-18536WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scriptingstop user enumeration6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2017-18537Visitors Online by BestWebSoft < 1.0.0 - Cross-Site Scriptingvisitors online6.1 (v3.0)Medium341266 , 346755
CVE-2017-18556Google Analytics by BestWebSoft < 1.7.1 - Cross-Site Scriptinggoogle analytics6.1 (v3.0)Medium341266 , 346755
CVE-2017-18557Google Maps by BestWebSoft < 1.3.6 - Cross-Site Scriptinggoogle maps6.1 (v3.0)Medium341266 , 346755
CVE-2017-18558Testimonials by BestWebSoft < 0.1.9 - Cross-Site Scriptingtestimonials6.1 (v3.0)Medium341266 , 346755
CVE-2017-18562Error Log Viewer by BestWebSoft < 1.0.6 - Cross-Site Scriptingerror log viewer6.1 (v3.0)Medium341266 , 346755
CVE-2017-18564Sender by BestWebSoft < 1.2.1 - Cross-Site Scriptingsender6.1 (v3.0)Medium341266 , 346755
CVE-2017-18565Updater by BestWebSoft < 1.35 - Cross-Site Scriptingupdater6.1 (v3.0)Medium341266 , 346755
CVE-2017-18517Pinterest by BestWebSoft < 1.0.5 - Cross-Site Scriptingpinterest6.1 (v3.0)Medium341266 , 346755
CVE-2017-18518SMTP by BestWebSoft < 1.1.0 - Cross-Site Scriptingsmtp6.1 (v3.0)Medium341266 , 346755
CVE-2017-18527Pagination by BestWebSoft < 1.0.7 - Cross-Site Scriptingpagination6.1 (v3.0)Medium341266 , 346755
CVE-2017-18528PDF & Print by BestWebSoft < 1.9.4 - Cross-Site Scriptingpdf &amp; print6.1 (v3.0)Medium341266 , 346755
CVE-2017-18529PromoBar by BestWebSoft < 1.1.1 - Cross-Site Scriptingpromobar6.1 (v3.0)Medium341266 , 346755
CVE-2017-18530Rating by BestWebSoft < 0.2 - Cross-Site Scriptingrating6.1 (v3.0)Medium341266 , 346755
CVE-2017-18532Realty by BestWebSoft < 1.1.0 - Cross-Site Scriptingrealty6.1 (v3.0)Medium341266 , 346755
CVE-2017-18566User Role by BestWebSoft < 1.5.6 - Cross-Site Scriptinguser role6.1 (v3.0)Medium341266 , 346755
CVE-2019-14430YouPHPTube 7.2 - 'userCreate.json.php' SQL Injectionyouphptube5.3 (v3.0)Medium392301
CVE-2015-9323404 to 301 <= 2.0.2 - Authenticated Blind SQL Injection404 to 3019.8 (v3.1)Critical340017 , 380122
CVE-2019-15107Webmin <= 1.920 - Unauthenticated Remote Command Executionwebmin9.8 (v3.1)Critical340023 , 344360 , 344361 , 344363
CVE-2017-18542Zendesk Help Center by BestWebSoft < 1.0.5 - Cross-Site Scriptingzendesk help center6.1 (v3.0)Medium341266 , 346755
CVE-2019-14789Custom 404 Pro < 3.2.8 - Cross-Site Scriptingcustom 404 pro6.1 (v3.0)Medium346755 , 347198
CVE-2015-9312NewStatPress <=1.0.4 - Cross-Site Scriptingnewstatpress6.1 (v3.0)Medium340099 , 341099 , 346755 , 347198
CVE-2019-14427Ultimate Loan Manager 2.0 - Cross-Site Scriptingultimate loan manager6.1 (v3.0)Medium345493 , 390585
CVE-2019-14974SugarCRM Enterprise 9.0.0 - Cross-Site Scriptingsugarcrm6.1 (v3.0)Medium340112 , 346755 , 350148
CVE-2019-14530OpenEMR <5.0.2 - Local File Inclusionopenemr8.8 (v3.1)High344360 , 347009 , 390709
CVE-2017-18487AdPush < 1.44 - Cross-Site Scriptinggoogle adsense6.1 (v3.0)Medium341266 , 346755
CVE-2017-18490Contact Form Multi by BestWebSoft < 1.2.1 - Cross-Site Scriptingcontact form multi6.1 (v3.0)Medium341266 , 346755
CVE-2017-18491Contact Form by BestWebSoft < 4.0.6 - Cross-Site Scriptingcontact form6.1 (v3.0)Medium341266 , 346755
CVE-2017-18492Contact Form to DB by BestWebSoft < 1.5.7 - Cross-Site Scriptingcontact form to db6.1 (v3.0)Medium341266 , 346755
CVE-2017-18493Custom Admin Page by BestWebSoft < 0.1.2 - Cross-Site Scriptingcustom admin page6.1 (v3.0)Medium341266 , 346755
CVE-2017-18494Custom Search by BestWebSoft < 1.36 - Cross-Site Scriptingcustom search6.1 (v3.0)Medium341266 , 346755
CVE-2017-18496Htaccess by BestWebSoft < 1.7.6 - Cross-Site Scriptinghtaccess6.1 (v3.0)Medium341266 , 346755
CVE-2019-13462Lansweeper Unauthenticated SQL Injectionlansweeper9.1 (v3.0)Critical331028 , 340016 , 340155 , 340157 , 341155 , 341245 , 344361 , 360147 , 360148
CVE-2017-18500Social Buttons Pack by BestWebSof < 1.1.1 - Cross-Site Scriptingsocial buttons pack6.1 (v3.0)Medium341266 , 346755
CVE-2017-18501Social Login by BestWebSoft < 0.2 - Cross-Site Scriptingsocial login6.1 (v3.0)Medium341266 , 346755
CVE-2017-18502Subscriber by BestWebSoft < 1.3.5 - Cross-Site Scriptingsubscriber6.1 (v3.0)Medium341266 , 346755
CVE-2017-18505BestWebSoft's Twitter < 2.55 - Cross-Site Scriptingtwitter button6.1 (v3.0)Medium341266 , 346755
CVE-2019-14950WP Live Chat Support <= 8.0.27 — Stored Cross-Site Scriptinglive chat6.1 (v3.0)Medium344370 , 346755 , 380026
CVE-2019-11581Atlassian Jira Server-Side Template Injectionjira9.8 (v3.1)Critical311299
CVE-2019-14312Aptana Jaxer 1.0.3.4547 - Local File inclusionjaxer6.5 (v3.0)Medium344360 , 347009 , 390709
CVE-2019-14750osTicket < 1.12.1 - Cross-Site Scriptingosticket6.1 (v3.0)Medium346755
CVE-2019-14696Open-School 3.0/Community Edition 2.3 - Cross-Site Scriptingopen-school6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-18570Planon <Live Build 41 - Cross-Site Scriptingplanon6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2019-14322Pallets Werkzeug <0.15.5 - Local File InclusionWindows7.5 (v3.1)High390716
CVE-2019-10266Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injectioncloud backup suite7.5 (v3.0)High344372
CVE-2019-10263Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injectioncloud backup suite6.1 (v3.0)Medium344372
CVE-2019-2767Oracle Business Intelligence Publisher - XML External Entity Injectionbi publisher7.2 (v3.0)High344370 , 380018
CVE-2019-14205WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusionadaptive images7.5 (v3.1)High336461 , 340007 , 344360 , 381206
CVE-2019-14206Nevma Adaptive Images - Arbitrary File Deletionadaptive images7.5 (v3.1)High340007 , 377360
CVE-2019-12725Zeroshell 3.9.0 - Remote Command Executionzeroshell9.8 (v3.0)Critical340023 , 340029 , 344360 , 344361 , 344363 , 344370 , 347009 , 390722
CVE-2019-1010287Timesheet Next Gen <=1.5.3 - Cross-Site Scriptingtimesheet next gen6.1 (v3.0)Medium340147 , 342259 , 346755 , 350147 , 350148
CVE-2019-1943CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilitiessg200-50 firmware6.1 (v3.0)Medium390727 , 392301 , 392648
CVE-2019-12985Citrix SD-WAN Center - Remote Command Injectionnetscaler sd-wan9.8 (v3.0)Critical340014 , 340029 , 344364 , 344366 , 344370
CVE-2019-12986Citrix SD-WAN Center - Remote Command Injectionnetscaler sd-wan9.8 (v3.0)Critical340014 , 340029 , 344364 , 344366 , 344370
CVE-2019-12987Citrix SD-WAN Center - Remote Command Injectionnetscaler sd-wan9.8 (v3.0)Critical340014
CVE-2019-12988Citrix SD-WAN Center - Remote Command Injectionnetscaler sd-wan9.8 (v3.0)Critical393655
CVE-2019-12989Citrix SD-WAN and NetScaler SD-WAN - SQL Injectionnetscaler sd-wan9.8 (v3.1)Critical340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2019-13372D-Link Central WiFi Manager CWM(100) - Remote Code Executioncentral wifimanager9.8 (v3.1)Critical344370
CVE-2018-11686FlexPaper/FlowPaper 2.3.6 - Remote Code Executionflowpaper9.8 (v3.0)Critical340029 , 344361 , 344364
CVE-2018-15811DotNetNuke 9.2 - 9.2.1 - Weak Encryption & Cookie Deserializationdotnetnuke7.5 (v3.1)High344365 , 344370
CVE-2018-18325DotNetNuke 9.2 - 9.2.2 - Weak Encryption & Cookie Deserializationdotnetnuke7.5 (v3.1)High344365 , 344370
CVE-2019-10717BlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversalblogengine.net7.1 (v3.0)High340007
CVE-2018-11227Monstra CMS <=3.0.4 - Cross-Site Scriptingmonstra cms6.1 (v3.0)Medium333141 , 340248 , 342259 , 346755
CVE-2019-7256eMerge E3 1.00-06 - Remote Code Executionlinear emerge essential firmware9.8 (v3.1)Critical340029 , 344360 , 344361 , 344363 , 344370 , 347009
CVE-2019-7254eMerge E3 1.00-06 - Local File Inclusionlinear emerge essential firmware7.5 (v3.1)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2019-7255Linear eMerge E3 - Cross-Site Scriptinglinear emerge essential firmware6.1 (v3.1)Medium340147 , 341266 , 342259
CVE-2018-14916Loytec LGATE-902 <6.4.2 - Local File Inclusionlgate-9029.1 (v3.0)Critical340007 , 344360 , 347009 , 390709
CVE-2018-14918LOYTEC LGATE-902 6.3.2 - Local File Inclusionlgate-902 firmware7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2019-12581Zyxel ZyWal/USG/UAG Devices - Cross-Site Scriptinguag21006.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2019-12935Shopware < 5.5.8 - Cross-Site Scriptingshopware6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2019-2729Oracle WebLogic Server Administration Console - Remote Code Executioncommunications diameter signaling router9.8 (v3.1)Critical344361 , 344370 , 393655
CVE-2018-20470Tyto Sahi pro 7.x/8.x - Local File Inclusionsahi pro7.5 (v3.1)High340007
CVE-2019-7315Genie Access WIP3BVAF IP Camera - Local File Inclusionwip3bvaf7.5 (v3.0)High347009
CVE-2019-11269Spring Security OAuth - Open Redirectorspring security oauth5.4 (v3.1)Medium390703 , 390727 , 392301 , 392648
CVE-2019-9880WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosurewpgraphql9.1 (v3.0)Critical344361 , 344363
CVE-2019-7671Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scriptingflexair9.0 (v3.1)Critical340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390726 , 392647
CVE-2019-9189Prima Access Control 2.3.35 - Arbitrary File Uploadflexair8.8 (v3.0)High342259 , 344360 , 344363 , 344364 , 344366 , 350147 , 390724 , 390726 , 392647
CVE-2019-12276GrandNode 4.40 - Local File Inclusiongrandnode7.5 (v3.0)High344360 , 347009 , 390709
CVE-2019-12616phpMyAdmin 4.8 - Cross-Site Request Forgeryphpmyadmin6.5 (v3.0)Medium390727 , 392301 , 392648
CVE-2018-13379Fortinet FortiOS - Credentials Disclosurefortios9.8 (v3.1)Critical340007
CVE-2018-13380Fortinet FortiOS - Cross-Site Scriptingfortios6.1 (v3.1)Medium333141 , 340147 , 341266 , 342259 , 347198
CVE-2019-11580Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Executioncrowd9.8 (v3.1)Critical391213
CVE-2018-5406KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilitieskace systems management appliance firmware8.8 (v3.1)High390727 , 392301 , 392648
CVE-2019-12593IceWarp Mail Server <=10.4.4 - Local File Inclusionmail server7.5 (v3.0)High340007 , 344360 , 344365 , 347019
CVE-2018-5404KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilitieskace systems management appliance firmware6.5 (v3.0)Medium390727 , 392301 , 392648
CVE-2018-5405KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilitieskace systems management appliance firmware5.4 (v3.0)Medium390727 , 392301 , 392648
CVE-2019-11370Carel pCOWeb <B1.2.4 - Cross-Site Scriptingpcoweb card firmware5.4 (v3.0)Medium342259
CVE-2019-12461WebPort 1.19.1 - Cross-Site Scriptingweb port6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-9670Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injectionzimbra collaboration suite9.8 (v3.1)Critical344372
CVE-2018-14013Synacor Zimbra Collaboration Suite Collaboration <8.8.11 - Cross-Site Scriptingzimbra collaboration suite6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-0221Apache Tomcat - Cross-Site Scriptingtomcat6.1 (v3.0)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350148
CVE-2019-12314Deltek Maconomy 2.2.5 - Local File Inclusionmaconomy9.8 (v3.0)Critical347009
CVE-2019-10685Prinect Archive System 2015 Release 2.6 - Cross-Site Scriptingprinect archiver6.1 (v3.0)Medium340147 , 341256 , 341266 , 346755 , 390585
CVE-2018-7841Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injectionu.motion builder9.8 (v3.1)Critical344364 , 344366
CVE-2019-3402Jira < 8.1.1 - Cross-Site Scriptingjira6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148 , 390585
CVE-2019-8937HotelDruid 2.3.0 - Cross-Site Scriptinghoteldruid6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2013-7285XStream <1.4.6/1.4.10 - Remote Code Executionxstream9.8 (v3.1)Critical344363
CVE-2018-18800PayPal-Credit Card-Debit Card Payment 1.0 - SQL Injectionwelcome to our resort9.8 (v3.0)Critical331028 , 340016 , 340157 , 341245 , 360147 , 380123
CVE-2019-11844RICOH SP 4520DN Printer - HTML Injectionsp 4520dn firmware6.1 (v3.0)Medium350147
CVE-2019-11845RICOH SP 4510DN Printer - HTML Injectionsp 4510dn firmware6.1 (v3.0)Medium350147
CVE-2019-11846dotCMS 5.1.1 - HTML Injectiondotcms6.1 (v3.0)Medium345493
CVE-2019-8390qdPM 9.1 - 'search[keywords]' Cross-Site Scriptingqdpm6.1 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 350147
CVE-2019-9618WordPress GraceMedia Media Player 1.0 - Local File Inclusiongracemedia media player9.8 (v3.0)Critical340007 , 344360 , 347009 , 390709
CVE-2018-12300Seagate NAS OS 4.3.15.1 - Open Redirectnas os6.1 (v3.0)Medium340163
CVE-2018-16139BIBLIOsoft BIBLIOpac 2008 - Cross-Site Scriptingbibliopac6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147
CVE-2019-11510Pulse Connect Secure SSL VPN Arbitrary File Readconnect secure10.0 (v3.1)Critical347009
CVE-2019-11398UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scriptingulicms6.1 (v3.0)Medium340247 , 340248 , 342259 , 344370 , 346755
CVE-2019-11507Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)connect secure6.1 (v3.1)Medium333141 , 341256 , 342259 , 346755 , 347198 , 350148 , 390722
CVE-2018-20503SirsiDynix e-Library 3.5.x - Cross-Site Scripting8100l/8 firmware6.1 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2019-5434Revive Adserver 4.2 - Remote Code Executionrevive adserver9.8 (v3.0)Critical344362 , 344365 , 344370
CVE-2019-3799Spring Cloud Config Server - Local File Inclusionspring cloud config6.5 (v3.1)Medium347009 , 390709
CVE-2018-20824Atlassian Jira WallboardServlet <7.13.1 - Cross-Site Scriptingjira6.1 (v3.0)Medium346755 , 347198
CVE-2018-16716NCBI ToolBox - Directory Traversalncbi toolbox9.1 (v3.0)Critical344360 , 347009 , 390709
CVE-2018-10383Lantronix SecureLinx Spider (SLS) 2.2+ - Cross-Site Scriptingsecurelinx spider firmware6.1 (v3.0)Medium333141 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2019-9621Zimbra Collaboration Suite - SSRFcollaboration server7.5 (v3.1)High344372
CVE-2019-2616Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injectionbusiness intelligence publisher7.2 (v3.1)High330791 , 340152
CVE-2019-2588Oracle Business Intelligence - Path Traversalbusiness intelligence publisher4.9 (v3.0)Medium340007 , 344365 , 347019
CVE-2019-9955Zyxel - Cross-Site Scriptingatp200 firmware6.1 (v3.0)Medium346755
CVE-2019-7219Zarafa WebApp <=2.0.1.47791 - Cross-Site Scriptingwebaccess6.1 (v3.0)Medium342259 , 346755 , 347198 , 350147 , 350148
CVE-2019-4013IBM Bigfix Platform 9.5.9.62 - Arbitrary File Uploadbigfix platform9.9 (v3.0)Critical392301
CVE-2019-7139Magento - SQL Injectionmagento9.8 (v3.0)Critical340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026
CVE-2019-10647ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)zzzphp9.8 (v3.0)Critical340162 , 340163
CVE-2019-9922Joomla! Harmis Messenger 1.2.2 - Local File Inclusionje messenger7.5 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2019-10232Teclib GLPI <= 9.3.3 - Unauthenticated SQL Injectiongestionnaire libre de parc informatique9.8 (v3.0)Critical340016 , 340017 , 340144 , 340155 , 340157 , 341155 , 341245 , 360147 , 360148
CVE-2019-5418Rails File Content Disclosurerails7.5 (v3.1)High390719
CVE-2019-10068Kentico CMS Insecure Deserialization Remote Code Executionkentico9.8 (v3.1)Critical341256
CVE-2019-3396Atlassian Confluence Server - Path Traversalconfluence9.8 (v3.1)Critical392301
CVE-2019-9912WP Google Maps < 7.10.43 - Cross-Site Scriptingwp go maps6.1 (v3.1)Medium340099 , 341099 , 346755 , 347198
CVE-2018-18798School Attendance Monitoring System 1.0 - SQL Injectionschool attendance monitoring system9.8 (v3.0)Critical331028 , 340016 , 340017 , 340157 , 360147 , 360148
CVE-2018-19276OpenMRS Platform < 2.24.0 - Insecure Object Deserializationopenmrs9.8 (v3.1)Critical330791 , 340152 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2018-20526Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversalroxy fileman9.8 (v3.0)Critical330791 , 340152
CVE-2019-7238Sonatype Nexus Repository Manager <3.15.0 - Remote Code Executionnexus9.8 (v3.1)Critical344360 , 344363 , 344370
CVE-2019-9083SQLiteManager 1.2.0 / 1.2.4 - Blind SQL Injectionsqlitemanager9.8 (v3.0)Critical341145 , 341245
CVE-2018-19365Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversalstreaming engine9.1 (v3.1)Critical340007 , 344360 , 347009 , 390709
CVE-2018-20525Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversalroxy fileman9.1 (v3.1)Critical330791 , 340152
CVE-2018-10093AudioCodes 420HD - Remote Code Execution420hd ip phone firmware8.8 (v3.0)High344360 , 347009
CVE-2018-18762SaltOS Erp Crm 3.1 r8126 - Database File Downloadsaltos6.5 (v3.0)Medium390716
CVE-2019-7439JioFi 4G M2S 1.0.2 - Denial of Servicejiofi 4g m2s firmware6.5 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 350147 , 350148
CVE-2019-7438JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scriptingjiofi 4g m2s firmware6.1 (v3.0)Medium340149 , 341256 , 342259 , 344361 , 344364 , 344370 , 350147
CVE-2019-9762PHPSHE 1.7 - SQL Injectionphpshe9.8 (v3.0)Critical340016 , 340017 , 340145 , 340156 , 340157 , 340159 , 360147 , 360148
CVE-2018-18809TIBCO JasperReports Library - Directory Traversaljasperreports library6.5 (v3.1)Medium340007
CVE-2019-3778Spring Security OAuth - Open Redirectorspring security oauth6.5 (v3.1)Medium390703 , 390727 , 392301 , 392648
CVE-2019-9591ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilitiesconnect onsite6.1 (v3.1)Medium340003 , 340147 , 341266 , 342259 , 390585 , 390727 , 392301 , 392648
CVE-2019-9592ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilitiesconnect onsite6.1 (v3.1)Medium340003 , 340147 , 341266 , 342259 , 390585 , 390727 , 392301 , 392648
CVE-2019-9593ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilitiesconnect onsite6.1 (v3.1)Medium340003 , 340147 , 341266 , 342259 , 390585 , 390727 , 392301 , 392648
CVE-2019-9194elFinder <= 2.1.47 - Command Injectionelfinder9.8 (v3.0)Critical390700 , 393781
CVE-2019-9082ThinkPHP < 3.2.4 - Remote Code Executionthinkphp8.8 (v3.1)High344361 , 393753
CVE-2019-9041ZZZCMS 1.6.1 - Remote Code Executionzzzphp7.2 (v3.0)High360153 , 380026
CVE-2019-8982Wavemaker Studio 6.6 - Local File Inclusion/Server-Side Request Forgerywavemarker studio9.6 (v3.0)Critical344360 , 347009
CVE-2019-6340Drupal - Remote Code Executiondrupal8.1 (v3.1)High392301
CVE-2019-8903Totaljs <3.2.3 - Local File Inclusiontotal.js7.5 (v3.0)High346019
CVE-2019-8394Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Uploadmanageengine servicedesk plus6.5 (v3.1)Medium345493
CVE-2018-17431Comodo Unified Threat Management Web Console - Remote Code Executionunified threat management firewall9.8 (v3.1)Critical344361 , 344362 , 344364 , 390722
CVE-2019-3911LabKey Server Community Edition <18.3.0 - Cross-Site Scriptinglabkey server6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-6802Pypiserver <1.2.5 - Carriage Return Line Feed Injectionpypiserver6.1 (v3.0)Medium330708 , 390714
CVE-2019-5893OpenSource ERP 6.3.1. - SQL Injectionopen source erp9.8 (v3.0)Critical341250 , 344366
CVE-2018-16167LogonTracer <=1.2.0 - Remote Command Injectionlogontracer9.8 (v3.0)Critical340014 , 344364 , 344366
CVE-2018-20463WordPress JSmol2WP <=1.07 - Local File Inclusionjsmol2wp7.5 (v3.0)High340007 , 340077 , 340165 , 344360 , 381206
CVE-2018-20462WordPress JSmol2WP <=1.07 - Cross-Site Scriptingjsmol2wp6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2018-20418Craft CMS 3.0.25 - Cross-Site Scriptingcraft cms4.8 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 344365 , 346755
CVE-2018-20367WSTMart 2.0.8 - Cross-Site Scriptingwstmart6.1 (v3.0)Medium345493
CVE-2018-17246Kibana - Local File Inclusionkibana9.8 (v3.0)Critical340007 , 344360 , 347009 , 390709
CVE-2018-1000856DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2018-19933Bolt CMS < 3.6.2 - Cross-Site Scriptingbolt cms6.1 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755
CVE-2018-18923Ticketly 1.0 - 'kind_id' SQL Injectionticketly9.8 (v3.0)Critical340156 , 380122
CVE-2018-1821IBM Operational Decision Manager 8.x - XML External Entity Injectionoperational decision manager9.1 (v3.0)Critical330791 , 340152 , 345493
CVE-2018-8033Apache OFBiz - XML External Entity Injectionofbiz7.5 (v3.0)High341256 , 344370 , 344372
CVE-2018-7690Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosurefortify software security center6.5 (v3.0)Medium390727 , 392301 , 392648
CVE-2018-7691Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2)fortify software security center6.5 (v3.0)Medium330791 , 340152
CVE-2018-19439Oracle Secure Global Desktop Administration Console 4.4 - Cross-Site Scriptingsecure global desktop6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 390585
CVE-2018-1000861Jenkins - Remote Command Injectionjenkins9.8 (v3.1)Critical344370 , 390722
CVE-2018-20009DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2018-20010DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2018-20011DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 342259 , 346755 , 350148
CVE-2018-19892DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 342259 , 346755 , 350148
CVE-2018-19914DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2018-19915DomainMOD <=4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2018-19753Tarantella Enterprise <3.11 - Local File Inclusiontarantella enterprise7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2018-19877Adiscon LogAnalyzer <4.1.7 - Cross-Site Scriptingloganalyzer6.1 (v3.0)Medium340147 , 341266 , 342259 , 360030
CVE-2018-1002000WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter7.2 (v3.0)High340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002001WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002002WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002003WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002004WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002005WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002006WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002007WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002008WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-1002009WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium340156 , 344370 , 380122 , 390726 , 392647
CVE-2018-19749DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2018-19751DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 342259 , 346755 , 350148
CVE-2018-19752DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod4.8 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2018-19458PHP Proxy 3.0.3 - Local File Inclusionphp-proxy7.5 (v3.0)High340162 , 340165 , 344360 , 347009
CVE-2018-19326Zyxel VMG1312-B10D 5.13AAXA.8 - Local File Inclusionvmg1312-b10d firmware7.5 (v3.0)High347009
CVE-2018-18755K-iwi Framework 1775 - SQL Injectionk-iwi9.8 (v3.1)Critical331028 , 340016 , 340155 , 340157 , 341155 , 341245 , 344361 , 360147 , 360148 , 380026
CVE-2018-18761SaltOS Erp Crm 3.1 r8126 - SQL Injectionsaltos9.8 (v3.1)Critical331028 , 340016 , 340155 , 340156 , 340157 , 341155 , 341245 , 360147 , 380026
CVE-2018-18763SaltOS Erp Crm 3.1 r8126 - SQL Injection (2)saltos9.8 (v3.0)Critical331028 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026
CVE-2018-18795School Event Management System 1.0 - SQL Injectionschool event management system9.8 (v3.0)Critical331028 , 340016 , 340017 , 340157 , 360147 , 360148
CVE-2018-18801E-Negosyo System 1.0 - SQL Injectionbsen ordering software9.8 (v3.0)Critical331028 , 340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2018-18760RhinOS CMS 3.x - Arbitrary File Downloadrhinos6.5 (v3.0)Medium334168 , 344360
CVE-2018-19287WordPress Ninja Forms <3.3.18 - Cross-Site Scriptingninja forms6.1 (v3.0)Medium333141 , 340099 , 340148 , 341099 , 346755 , 347198
CVE-2018-7357ZTE ZXHN H168N - Improper Access Restrictionszxhn h168n firmware8.8 (v3.0)High330791 , 334168 , 340152
CVE-2018-7358ZTE ZXHN H168N - Improper Access Restrictionszxhn h168n firmware8.8 (v3.0)High330791 , 334168 , 340152
CVE-2018-19136DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 346755
CVE-2018-19137DomainMOD 4.11.01 - Cross-Site Scriptingdomainmod6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 346755
CVE-2018-18925Gogs (Go Git Service) 0.11.66 - Remote Code Executiongogs9.8 (v3.0)Critical344360
CVE-2018-18775Microstrategy Web 7 - Cross-Site Scriptingmicrostrategy web6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2018-18777Microstrategy Web 7 - Local File Inclusionmicrostrategy web4.3 (v3.0)Medium340007 , 344360 , 347009 , 390709
CVE-2017-18349Fastjson Insecure Deserialization - Remote Code Executionfastjson9.8 (v3.0)Critical344380 , 344385 , 398008
CVE-2018-18608DedeCMS 5.7 SP2 - Cross-Site Scriptingdedecms6.1 (v3.0)Medium340147 , 341266 , 346755
CVE-2015-4632Koha 3.20.1 - Directory Traversalkoha7.5 (v3.0)High344360 , 347009 , 390709
CVE-2018-10823D-Link Routers - Remote Command Injectiondwr-116 firmware8.8 (v3.1)High347009
CVE-2018-10822D-Link Routers - Local File Inclusiondwr-116 firmware7.5 (v3.1)High347009
CVE-2018-3238Oracle Fusion Middleware WebCenter Sites 11.1.1.8.0 - Cross-Site Scriptingwebcenter sites6.9 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-3167Oracle E-Business Suite - Blind SSRFapplication management pack5.3 (v3.0)Medium392301
CVE-2018-18308BigTree CMS 4.2.23 - Cross-Site Scriptingbigtree cms6.1 (v3.0)Medium345493
CVE-2018-18323Centos Web Panel 0.9.8.480 - Local File Inclusionwebpanel7.5 (v3.0)High344360 , 347009
CVE-2018-10141Palo Alto Networks PAN-OS GlobalProtect <8.1.4 - Cross-Site Scriptingpan-os6.1 (v3.0)Medium346755
CVE-2018-12596Ektron CMS 9.20 SP2 - Improper Access Restrictionsektron cms9.8 (v3.0)Critical390727 , 392301 , 392648
CVE-2018-12455Intelbras NPLUG 1.0.0.14 - Authentication Bypassnplug8.1 (v3.0)High390716
CVE-2018-8006Apache ActiveMQ <=5.15.5 - Cross-Site Scriptingactivemq6.1 (v3.1)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-17440D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilitiescentral wifimanager9.8 (v3.0)Critical340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2018-17442D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilitiescentral wifimanager8.8 (v3.0)High340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2018-17441D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilitiescentral wifimanager6.1 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2018-17443D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilitiescentral wifimanager6.1 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2018-18069WordPress sitepress-multilingual-cms 3.6.3 - Cross-Site Scriptingwpml6.1 (v3.0)Medium392301
CVE-2018-17587Airties AIR5342 1.0.0.18 - Cross-Site Scriptingair 5750 firmware6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2018-17588Airties AIR5342 1.0.0.18 - Cross-Site Scriptingair 5021 firmware6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2018-17590Airties AIR5342 1.0.0.18 - Cross-Site Scriptingair 5442 firmware6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2018-17591Airties AIR5342 1.0.0.18 - Cross-Site Scriptingair 5343v2 firmware6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2018-17593Airties AIR5342 1.0.0.18 - Cross-Site Scriptingair 5453 firmware6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2018-17310RICOH MP C1803 JPN Printer - Cross-Site Scriptingmp c1803 jpn firmware6.1 (v3.0)Medium350147
CVE-2018-17313RICOH MP C1803 JPN Printer - Cross-Site Scriptingmp c307 firmware6.1 (v3.0)Medium350147
CVE-2018-16283WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusionwechat brodcast9.8 (v3.0)Critical340007 , 344360 , 347009 , 390709
CVE-2018-16299WordPress Localize My Post 1.0 - Local File Inclusionlocalize my post7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2018-17173LG Supersign EZ CMS - Remote Code Executionsupersign cms9.8 (v3.0)Critical340014 , 340029 , 344361 , 344363 , 344370
CVE-2018-16833ManageEngine Desktop Central 10.0.271 - Cross-Site Scriptingmanageengine desktop central6.1 (v3.0)Medium333141 , 342259 , 350147 , 350148
CVE-2018-17254Joomla! JCK Editor SQL Injectionjck editor9.8 (v3.1)Critical340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2018-17153Western Digital MyCloud NAS - Authentication Bypassmy cloud wdbctl0020hwt firmware9.8 (v3.0)Critical344363
CVE-2018-17082Apache2 - Transfer-Encoding Chunked XSSphp6.1 (v3.0)Medium392301
CVE-2018-16288LG SuperSign EZ CMS 2.5 - Local File Inclusionsupersign cms8.6 (v3.0)High347009
CVE-2018-16979Monstra CMS 3.0.4 - HTTP Header Injectionmonstra6.1 (v3.0)Medium330708 , 390722
CVE-2018-16836Rubedo CMS <=3.4.0 - Directory Traversalrubedo9.8 (v3.1)Critical347009
CVE-2018-16763FUEL CMS 1.4.1 - Remote Code Executionfuel cms9.8 (v3.1)Critical340023 , 344360 , 344370 , 347009 , 380026
CVE-2018-16736Roundcube rcfilters plugin 2.1.6 - Cross-Site Scriptingrcfilters5.4 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755
CVE-2018-16363WordPress File Manager < 3.0 - Cross-Site Scriptingfile manager5.4 (v3.0)Medium341266 , 346755 , 377360
CVE-2018-16059WirelessHART Fieldgate SWG70 3.0 - Local File Inclusionwirelesshart fieldgate swg70 firmware5.3 (v3.0)Medium392301
CVE-2018-15917Jorani Leave Management System 0.6.5 - Cross-Site Scriptingjorani5.4 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-16159WordPress Gift Voucher <4.1.8 - Blind SQL Injectiongift vouchers9.8 (v3.0)Critical380122
CVE-2018-15745Argus Surveillance DVR 4.0.0.0 - Local File Inclusiondvr7.5 (v3.0)High340007
CVE-2017-17762Episerver 7 - Blind XML External Entity Injectionepiserver7.5 (v3.0)High344372
CVE-2018-16134Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scriptingcybrohttpserver6.1 (v3.0)Medium340147 , 341266 , 346755
CVE-2018-16133Cybrotech CyBroHttpServer 1.0.3 - Directory Traversalcybrohttpserver5.3 (v3.0)Medium344365 , 347019 , 390716
CVE-2018-15884RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)mp c4504ex firmware8.8 (v3.0)High350147
CVE-2018-15535Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager7.5 (v3.0)High340007 , 344360 , 344370 , 345493 , 347009 , 390709 , 390720 , 390727 , 392301 , 392648
CVE-2018-15536Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager5.5 (v3.0)Medium340007 , 344360 , 344370 , 345493 , 347009 , 390709 , 390720 , 390727 , 392301 , 392648
CVE-2018-11776Apache Struts2 S2-057 - Remote Code Executionstruts8.1 (v3.1)High337209 , 337211 , 340193 , 347009
CVE-2018-15534Geutebrueck re_porter 7.8.974.20 - Credential Disclosurere porter 16 firmware9.8 (v3.0)Critical390727 , 392301 , 392648
CVE-2018-11511ASUSTOR ADM 3.1.0.RFQ3 - SQL Injectionasustor data master9.8 (v3.0)Critical341245 , 380026 , 380122
CVE-2018-15138LG-Ericsson iPECS NMS 30M - Local File Inclusionipecs nms7.5 (v3.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2016-4975Apache mod_userdir CRLF injectionhttp server6.1 (v3.0)Medium330708 , 390714
CVE-2018-15142OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr8.8 (v3.0)High340029 , 344360 , 344370 , 360152 , 390709
CVE-2018-15140OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr6.5 (v3.0)Medium340029 , 344360 , 344370 , 360152 , 390709
CVE-2018-15141OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr6.5 (v3.0)Medium340029 , 344360 , 344370 , 360152 , 390709
CVE-2016-8526Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scriptingairwave8.8 (v3.0)High333141 , 341256 , 342259 , 344370 , 346755 , 350147 , 350148
CVE-2016-8527Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scriptingairwave6.1 (v3.0)Medium333141 , 340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 350147 , 350148
CVE-2018-14728Responsive filemanager 9.13.1 Server-Side Request Forgeryresponsive filemanager9.8 (v3.0)Critical392301
CVE-2018-14912cgit < 1.2.1 - Directory Traversalcgit7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2018-13980Zeta Producer Desktop CMS <14.2.1 - Local File Inclusionzeta producer5.5 (v3.1)Medium340007 , 344360 , 347009 , 390709
CVE-2018-14064VelotiSmart Wifi - Directory Traversalvelotismart wifi firmware9.8 (v3.0)Critical347009
CVE-2018-12463Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injectionfortify software security center9.8 (v3.1)Critical330791 , 340152
CVE-2018-8024Apache Spark UI - Cross-Site Scriptingspark5.4 (v3.0)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-7765Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injectionu.motion builder8.8 (v3.0)High341245 , 344364 , 344366
CVE-2018-12998Zoho manageengine - Cross-Site Scriptingfirewall analyzer6.1 (v3.1)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-12909Webgrind <= 1.5 - Local File Inclusionwebgrind7.5 (v3.0)High344360 , 347009 , 390709
CVE-2018-1306Apache Portals Pluto 3.0.0 - Remote Code Executionpluto7.5 (v3.0)High390727 , 392648
CVE-2018-3760Ruby On Rails - Local File Inclusioncloudforms7.5 (v3.0)High347009
CVE-2018-10956IPConfigure Orchid Core VMS 2.0.5 - Local File Inclusionorchid core vms7.5 (v3.0)High347009
CVE-2018-12613PhpMyAdmin <4.8.2 - Local File Inclusionphpmyadmin8.8 (v3.1)High340007 , 344360 , 347009 , 390709
CVE-2018-8727Mirasys DVMS Workstation <=5.12.6 - Local File Inclusiondvms workstation7.5 (v3.0)High390716
CVE-2015-4664Xceedium Xsuite - Multiple Vulnerabilitiesprivileged access manager9.8 (v3.0)Critical320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2018-11222Pandora FMS <=7.0NG.722 - Remote Code Executionpandora fms7.5 (v3.0)High390726 , 392647
CVE-2018-6671McAfee ePO 5.9.1 - Registered Executable Local Access Bypassepolicy orchestrator6.5 (v3.0)Medium344364 , 344365 , 344366
CVE-2018-6961VMware NSX SD-WAN Edge - Command Injectionnsx sd-wan edge8.1 (v3.1)High344363 , 393655
CVE-2018-12111Canon PrintMe EFI - Cross-Site Scriptingefi printme6.1 (v3.0)Medium340099 , 340147 , 341099 , 346755 , 347198
CVE-2018-12095OEcms 3.1 - Cross-Site Scriptingoecms5.4 (v3.0)Medium340147 , 340148 , 341266 , 346755
CVE-2018-12054Schools Alert Management Script - Arbitrary File Readschools alert management script7.5 (v3.0)High344360
CVE-2018-12031Eaton Intelligent Power Manager 1.6 - Directory Traversalintelligent power manager9.8 (v3.0)Critical340007 , 344360 , 347009 , 390709
CVE-2018-3714node-srv - Local File Inclusionnode-srv6.5 (v3.1)Medium347009
CVE-2018-11709WordPress wpForo Forum <= 1.4.11 - Cross-Site Scriptingwpforo forum6.1 (v3.0)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-11133Quest KACE SMA /common/run_cross_report.php 'fmt' XSSkace system management appliance6.1 (v3.0)Medium346755
CVE-2018-11535Sitemakin SLAC 1.0 - 'my_item_search' SQL Injectionslac9.8 (v3.0)Critical331028 , 340016 , 340155 , 340157 , 340159 , 341155 , 341245 , 342259 , 344370 , 345493 , 360147 , 360148 , 380026
CVE-2018-11442EasyService Billing 1.0 - Cross-Site Request Forgeryeasyservice billing8.8 (v3.0)High340147 , 340148 , 340149 , 341245 , 341256 , 342259 , 344361 , 344362 , 344363 , 344370 , 345490 , 345493 , 350147
CVE-2018-11445EasyService Billing 1.0 - Cross-Site Request Forgeryeasyservice billing8.8 (v3.0)High340147 , 340148 , 340149 , 341245 , 341256 , 342259 , 344361 , 344362 , 344363 , 344370 , 345490 , 345493 , 350147
CVE-2018-11231Opencart Divido - Sql Injectiondivido8.1 (v3.0)High392301
CVE-2018-10095Dolibarr <7.0.2 - Cross-Site Scriptingdolibarr6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2018-10735NagiosXI <= 5.4.12 commandline.php SQL injectionnagios xi7.2 (v3.0)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2018-10736NagiosXI <= 5.4.12 - SQL injectionnagios xi7.2 (v3.0)High340016 , 340017 , 340157 , 340159 , 341245 , 360147 , 360148
CVE-2018-10737NagiosXI <= 5.4.12 logbook.php SQL injectionnagios xi7.2 (v3.0)High331028 , 340155 , 341155 , 341245
CVE-2018-10738NagiosXI <= 5.4.12 menuaccess.php - SQL injectionnagios xi7.2 (v3.0)High331028 , 340016 , 340155 , 340157 , 340159 , 341155 , 341245 , 360147 , 360148 , 380026
CVE-2018-5230Atlassian Jira Confluence - Cross-Site Scriptingjira6.1 (v3.0)Medium340112 , 340147 , 346755
CVE-2015-1503IceWarp Mail Server < 11.1.1 - Directory Traversalmail server7.5 (v3.0)High340007 , 344360 , 347009 , 390709 , 390726 , 390727 , 392301 , 392647 , 392648
CVE-2018-1247RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scriptingauthentication manager7.1 (v3.0)High392301
CVE-2018-10562Dasan GPON Devices - Remote Code Executiongpon router firmware9.8 (v3.1)Critical392301
CVE-2018-9302Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgerycockpit9.1 (v3.0)Critical390727 , 392301 , 392648
CVE-2018-1335Apache Tika < 1.1.8 - Header Command Injectiontika8.1 (v3.0)High340138 , 391213
CVE-2018-10201Ncomputing vSPace Pro 10 and 11 - Directory Traversalvspace pro7.5 (v3.0)High344365 , 390716
CVE-2018-10230Zend Server <9.13 - Cross-Site Scriptingzend server6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-9118WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusionwp background takeover advertisements7.5 (v3.0)High336461 , 344360 , 381206
CVE-2018-1273Spring Data Commons - Remote Code Executionspring data commons9.8 (v3.1)Critical344360 , 344370
CVE-2017-14611Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgerycockpit9.1 (v3.0)Critical390727 , 392301 , 392648
CVE-2018-9038Monstra CMS 3.0.4 - Arbitrary Folder Deletionmonstra6.5 (v3.0)Medium390727 , 392301 , 392648
CVE-2018-1217Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Controlemc avamar9.8 (v3.0)Critical391213
CVE-2018-1271Spring MVC Framework - Local File Inclusionspring framework5.9 (v3.1)Medium390716
CVE-2018-9205Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusionavatar uploader7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2018-9238Yahei PHP Prober 0.4.7 - Cross-Site Scriptingyahei php prober6.1 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2018-9160SickRage < v2018.03.09 - Clear-Text Credentials HTTP Responsesickrage9.8 (v3.0)Critical390727 , 392301 , 392648
CVE-2018-7171TwonkyMedia Server 7.0.11-8.5 - Directory Traversaltwonky server7.5 (v3.0)High390727 , 392301 , 392648
CVE-2018-7203TwonkyMedia Server 7.0.11-8.5 - Persistent Cross-Site Scriptingtwonky server6.1 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2018-7600Drupal - Remote Code Executiondrupal9.8 (v3.1)Critical330791 , 340152
CVE-2018-7700DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Executiondedecms8.8 (v3.0)High344370
CVE-2018-6882zimbra collaboration suite Cross-Site Scripting Vulnerabilityzimbra collaboration suite6.1 (v3.1)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-7192osTicket < 1.10.2 - Cross-Site Scriptingosticket6.1 (v3.0)Medium344361 , 344364 , 346755 , 347198
CVE-2018-7193osTicket < 1.10.2 - Cross-Site Scriptingosticket6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2018-7196osTicket < 1.10.2 - Cross-Site Scriptingosticket6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2018-1213Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon onefs8.8 (v3.0)High330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2017-15715Apache httpd <=2.4.29 - Arbitrary File Uploadhttp server8.1 (v3.0)High344365
CVE-2018-1203Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon onefs6.7 (v3.0)Medium330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-1204Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon onefs6.7 (v3.0)Medium330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-7543WordPress Plugin Duplicator 1.2.32 - Cross-Site Scriptingduplicator6.1 (v3.1)Medium333140 , 340148 , 346755 , 380026
CVE-2018-1186Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-1187Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-1188Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-1189Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-1201Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-1202Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon4.8 (v3.0)Medium330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-7719Acrolinx Server <5.2.5 - Local File Inclusionacrolinx server7.5 (v3.0)High347019
CVE-2018-7422WordPress Site Editor <=1.1.1 - Local File Inclusionsite editor7.5 (v3.0)High336461 , 344360 , 347009 , 381206 , 390709 , 393771
CVE-2018-5233Grav CMS <1.3.0 - Cross-Site Scriptinggrav cms6.1 (v3.0)Medium341266
CVE-2018-6220Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway9.8 (v3.0)Critical333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6223Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway9.8 (v3.0)Critical333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6228Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway9.8 (v3.0)Critical333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6229Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway9.8 (v3.0)Critical333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6224Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway8.8 (v3.0)High333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6221Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway8.1 (v3.0)High333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6222Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway7.8 (v3.0)High333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6230Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway6.8 (v3.0)Medium333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6219Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway6.5 (v3.0)Medium333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6226Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway5.4 (v3.0)Medium333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6227Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway5.4 (v3.0)Medium333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-6225Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gateway4.3 (v3.0)Medium333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-1000130Jolokia Agent - JNDI Code Injectionwebarchive agent8.1 (v3.0)High344362 , 390724
CVE-2018-1000129Jolokia 1.3.7 - Cross-Site Scriptingjolokia6.1 (v3.0)Medium346755 , 347198
CVE-2018-7538Tuleap 9.17.99.189 - Blind SQL Injectiontuleap9.8 (v3.0)Critical341245 , 344370 , 380026 , 380122
CVE-2018-6530D-Link - Unauthenticated Remote Code Executiondir-860l firmware9.8 (v3.1)Critical330791 , 340152 , 344363
CVE-2018-7653YzmCMS v3.6 - Cross-Site Scriptingyzmcms6.1 (v3.0)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2015-4117Vesta Control Panel 0.9.8 - OS Command Injectioncontrol panel8.8 (v3.0)High344370
CVE-2018-7448CMS Made Simple 2.1.6 - Remote Code Executioncms made simple7.5 (v3.0)High344363 , 360152 , 390704 , 390724
CVE-2018-7490uWSGI PHP Plugin Local File Inclusionuwsgi7.5 (v3.0)High347009
CVE-2014-3206Seagate BlackArmor NAS - Command Injectionblackarmor nas 220 firmware9.8 (v3.0)Critical311235 , 340014 , 340193 , 344364 , 344366
CVE-2018-7314Joomla! Component PrayerCenter 3.0.2 - SQL Injectionprayercenter9.8 (v3.0)Critical340157 , 341245 , 360147 , 360148
CVE-2015-6544Combodo iTop <2.2.0-2459 - Cross-Site Scriptingitop6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 390703
CVE-2018-7251Anchor CMS 0.12.3 - Error Log Exposureanchor9.8 (v3.0)Critical390716
CVE-2017-14535Trixbox - 2.8.0.4 OS Command Injectiontrixbox8.8 (v3.1)High340023 , 344360 , 344361 , 344363 , 347009
CVE-2017-14537Trixbox 2.8.0 - Path Traversaltrixbox6.5 (v3.1)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2017-5799HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusionopencall media platform8.8 (v3.0)High390726 , 392301 , 392647 , 392648
CVE-2017-5798HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusionopencall media platform6.1 (v3.0)Medium390726 , 392301 , 392647 , 392648
CVE-2017-12544HPE System Management - Cross-Site Scriptingsystem management homepage5.4 (v3.0)Medium344366
CVE-2018-0127Cisco RV132W/RV134W Router - Information Disclosurerv132w firmware9.8 (v3.1)Critical312863 , 390716
CVE-2018-6605Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injectionzh baidumap9.8 (v3.0)Critical340016 , 340017 , 340144 , 340157 , 360147 , 360148
CVE-2018-6008Joomla! Jtag Members Directory 5.3.7 - Local File Inclusionjtag members directory7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2017-17976PerfexCRM 1.9.7 - Arbitrary File Uploadperfex crm9.8 (v3.0)Critical392301
CVE-2017-14523Wonder CMS 2.3.1 - 'Host' Header Injectionwondercms7.5 (v3.0)High392301
CVE-2018-6184Zeit Next.js < 4.2.3 - Local File Inclusionnext.js7.5 (v3.0)High347009
CVE-2017-17999RISE 1.9 - 'search' SQL Injectionrise ultimate project manager9.8 (v3.0)Critical341245 , 380026 , 380122 , 390724
CVE-2017-14094Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server9.8 (v3.0)Critical330791 , 340007 , 340152
CVE-2017-14097Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server9.8 (v3.0)Critical330791 , 340007 , 340152
CVE-2017-11398Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server8.8 (v3.0)High330791 , 340007 , 340152
CVE-2017-14095Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server8.1 (v3.0)High330791 , 340007 , 340152
CVE-2017-14096Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server6.1 (v3.0)Medium330791 , 340007 , 340152
CVE-2018-5715SugarCRM 3.5.1 - Cross-Site Scriptingsugarcrm6.1 (v3.0)Medium340147 , 340148 , 341245 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2017-17970Muviko 1.1 - SQL Injectionmuviko9.8 (v3.0)Critical340016 , 340017 , 340144 , 340156 , 340157 , 340159 , 341245 , 360147 , 360148 , 380026 , 380122 , 390727 , 392301 , 392648
CVE-2017-18024AvantFAX 3.3.3 - Cross-Site Scriptingavantfax6.1 (v3.0)Medium340147 , 340148 , 342259 , 346755 , 350148
CVE-2018-5316WordPress SagePay Server Gateway for WooCommerce <1.0.9 - Cross-Site Scriptingsagepay server gateway for woocommerce6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2017-9965Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversalpelco videoxpert5.8 (v3.0)Medium344365 , 390716
CVE-2018-3810Oturia WordPress Smart Google Code Inserter <3.5 - Authentication Bypasssmart google code inserter9.8 (v3.0)Critical380026
CVE-2017-18001Trustwave SWG 11.8.0.27 - SSH Unauthorized Accesssecure web gateway9.8 (v3.0)Critical330039 , 330791 , 340152
CVE-2017-16949Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Uploadanonymous post pro9.8 (v3.0)Critical345493
CVE-2017-17731DedeCMS 5.7 - SQL Injectiondedecms9.8 (v3.0)Critical344370
CVE-2017-17672vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletionvbulletin9.8 (v3.0)Critical344370 , 390614
CVE-2017-17451WordPress Mailster <=1.5.4 - Cross-Site Scriptingwp mailster6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 390585
CVE-2017-17092WordPress < 4.9.1 - Authenticated JavaScript File UploadWordPress5.4 (v3.0)Medium377360
CVE-2017-17059WordPress amtyThumb Posts 8.1.3 - Cross-Site Scriptingamtythumb6.1 (v3.0)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148 , 392301
CVE-2017-14186FortiGate FortiOS SSL VPN Web Portal - Cross-Site Scriptingfortios5.4 (v3.0)Medium346755 , 350148
CVE-2017-17043WordPress Emag Marketplace Connector 1.0 - Cross-Site Scriptingemag marketplace connector6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2017-16935Ametys CMS 4.0.2 - Password Resetametys9.8 (v3.0)Critical345493 , 390724
CVE-2015-3934Fiyo CMS 2.0_1.9.1 - SQL Injectionfiyo cms9.8 (v3.0)Critical341245 , 344366 , 380026 , 380122
CVE-2017-16894Laravel <5.5.21 - Information Disclosurelaravel7.5 (v3.0)High390709
CVE-2017-1000170WordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File Inclusionjqueryfiletree7.5 (v3.1)High392301
CVE-2017-16877Nextjs <2.4.1 - Local File Inclusionnext.js7.5 (v3.0)High347009
CVE-2017-1000163Phoenix Framework - Open Redirectphoenix6.1 (v3.0)Medium344365
CVE-2017-12635Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalationcouchdb9.8 (v3.0)Critical392301
CVE-2017-16806Ulterius Server < 1.9.5.0 - Directory Traversalulterius server7.5 (v3.0)High347009 , 390709 , 390716
CVE-2015-7501Red Hat JBoss - Insecure Deserializationjboss enterprise application platform9.8 (v3.0)Critical344380
CVE-2015-3933GeniXCMS 0.0.3 - 'register.php' SQL Injectiongenixcms9.8 (v3.0)Critical331028 , 331702 , 340016 , 340017 , 340155 , 340157 , 340159 , 341155 , 341245 , 344365 , 360147 , 360148 , 360152 , 380026 , 390720 , 390724 , 390726 , 392647
CVE-2017-11512ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrievalservicedesk7.5 (v3.0)High340007 , 344365 , 347019
CVE-2014-1203Eyou E-Mail <3.6 - Remote Code Executioneyou9.8 (v3.1)Critical340023 , 341245 , 344360 , 344361 , 344363 , 344370
CVE-2014-3744Node.js st module Directory Traversalnode.js7.5 (v3.0)High347009
CVE-2017-15687Logitech Media Server - Cross-Site Scriptingmedia server6.1 (v3.0)Medium340099 , 341099 , 346755 , 347198
CVE-2017-10366Oracle PeopleSoft 8.5x - Remote Code Executionpeoplesoft enterprise peopletools9.8 (v3.0)Critical390703 , 392301
CVE-2017-10271Oracle WebLogic Server - Remote Command Executionweblogic server7.5 (v3.1)High344362 , 344363 , 344364 , 344366
CVE-2017-15647FiberHome Routers - Local File Inclusionrouterfiberhome firmware7.5 (v3.0)High344360 , 347009 , 390709
CVE-2017-15643Ikraus Anti Virus 2.16.7 - Remote Code Executionikarus antivirus7.4 (v3.0)High390727 , 392301 , 392648
CVE-2014-8357ZHONE < S3.0.501 - Multiple Vulnerabilitiesznid 2426a firmware8.8 (v3.0)High390726 , 392301 , 392647 , 392648
CVE-2014-9118ZHONE < S3.0.501 - Multiple Vulnerabilitiesznid 2426a firmware8.8 (v3.0)High390726 , 392301 , 392647 , 392648
CVE-2014-9148Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms9.8 (v3.0)Critical340007 , 340156 , 341145 , 344360 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647
CVE-2014-9147Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v3.0)High340007 , 340156 , 341145 , 344360 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647
CVE-2017-15363Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 - Local File Inclusionrestler7.5 (v3.1)High340007
CVE-2017-15287Dreambox WebControl 2.0.0 - Cross-Site Scriptingbouqueteditor6.1 (v3.0)Medium341266 , 346755
CVE-2017-12617Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)tomcat8.1 (v3.1)High345493 , 392301
CVE-2017-6090PhpColl 2.5.1 Arbitrary File Uploadphpcollab8.8 (v3.0)High391746
CVE-2017-14955Check_MK 1.2.8p25 - Information Disclosurecheckmk5.9 (v3.1)Medium330791 , 340152
CVE-2017-14942Intelbras WRN 150 - Authentication Bypasswrn1509.8 (v3.0)Critical390716
CVE-2017-14849Node.js <8.6.0 - Directory Traversalnode.js7.5 (v3.0)High347009
CVE-2017-14622WordPress 2kb Amazon Affiliates Store <2.1.1 - Cross-Site Scripting2kb amazon affiliates store6.1 (v3.0)Medium341266 , 346755
CVE-2015-4667Xceedium Xsuite - Multiple Vulnerabilitiesxsuite9.8 (v3.0)Critical320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2015-4669Xceedium Xsuite - Multiple Vulnerabilitiesxsuite7.8 (v3.0)High320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2015-4668Xceedium Xsuite - Multiple Vulnerabilitiesxsuite6.1 (v3.0)Medium320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2017-14725WordPress < 4.8.2 - Authenticated Open RedirectWordPress5.4 (v3.0)Medium377360
CVE-2017-14651WSO2 Data Analytics Server 3.1.0 - Cross-Site Scriptingapi manager4.8 (v3.1)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350148
CVE-2017-12611Apache Struts2 S2-053 - Remote Code Executionstruts9.8 (v3.0)Critical337207 , 337209 , 337211 , 337218 , 340014 , 340029 , 340193 , 344360 , 344362 , 344363 , 344370 , 347009
CVE-2015-4074Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusionhelpdesk pro7.5 (v3.0)High344360 , 347009 , 390709
CVE-2015-2826WordPress Plugin Simple Ads Manager - Information Disclosuresimple ads manager5.3 (v3.0)Medium344370 , 390904
CVE-2015-4683Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager9.8 (v3.0)Critical330791 , 340152 , 392301
CVE-2017-12615Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)tomcat8.1 (v3.1)High337209 , 337210 , 337211 , 340095 , 340128 , 344360 , 345493 , 347009 , 380018 , 380026 , 390904 , 392301
CVE-2015-4681Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager7.8 (v3.0)High330791 , 340152 , 392301
CVE-2015-4685Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager7.0 (v3.0)High330791 , 340152 , 392301
CVE-2015-4682Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager6.5 (v3.0)Medium330791 , 340152 , 392301
CVE-2015-4684Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilitiesrealpresence resource manager6.5 (v3.0)Medium330791 , 340152 , 392301
CVE-2017-9805Apache Struts2 S2-052 - Remote Code Executionstruts8.1 (v3.1)High344360 , 344364 , 344366
CVE-2017-14335Hanbanggaoke IP Camera - Arbitrary Password Changehb7024xt firmware7.5 (v3.0)High345493
CVE-2017-3132Fortinet FortiOS < 5.6.0 - Cross-Site Scriptingfortios6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148 , 390727 , 392301 , 392648
CVE-2017-3133Fortinet FortiOS < 5.6.0 - Cross-Site Scriptingfortios6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148 , 390727 , 392301 , 392648
CVE-2017-3131Fortinet FortiOS < 5.6.0 - Cross-Site Scriptingfortios5.4 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 344370 , 346755 , 347198 , 350147 , 350148 , 390727 , 392301 , 392648
CVE-2015-8349SourceBans <2.0 - Cross-Site Scriptingsourcebans6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2015-8350WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSScall to action6.1 (v3.0)Medium340148 , 341266 , 346755 , 377360
CVE-2017-9834WordPress Plugin WatuPRO 5.5.1 - SQL Injectionwatupro9.8 (v3.0)Critical340156 , 380122
CVE-2017-12794Django Debug Page - Cross-Site Scriptingdjango6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2017-14135OpenDreambox 2.0.0 - Remote Code Executionopendreambox9.8 (v3.0)Critical344364
CVE-2014-8675SO Planning 1.32 - Multiple Vulnerabilitiessoplanning7.5 (v3.0)High331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647
CVE-2017-7855IceWarp WebMail 11.3.1.5 - Cross-Site Scriptingserver6.1 (v3.0)Medium333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2014-8676SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium331028 , 340007 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344360 , 344363 , 344370 , 347009 , 360147 , 360148 , 360153 , 390709 , 390726 , 392647
CVE-2014-8677SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium331028 , 340016 , 340017 , 340144 , 340155 , 340156 , 340157 , 340159 , 341155 , 341245 , 344363 , 344370 , 360147 , 360148 , 360153 , 390726 , 392647
CVE-2017-9979QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilitiesquantastor6.1 (v3.0)Medium330791 , 340152 , 392301
CVE-2017-9978QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilitiesquantastor5.3 (v3.0)Medium330791 , 340152 , 392301
CVE-2017-9640Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Writei-vu6.3 (v3.0)Medium390727 , 390904 , 392301 , 392648
CVE-2017-11610XML-RPC Server - Remote Code Executionsupervisor8.8 (v3.0)High344364
CVE-2017-9506Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgeryoauth6.1 (v3.0)Medium382291
CVE-2017-10075Oracle Content Server - Cross-Site Scriptingwebcenter content8.2 (v3.0)High333141 , 341256 , 342259 , 346755 , 347198
CVE-2017-12583DokuWiki - Cross-Site Scriptingdokuwiki6.1 (v3.0)Medium333141 , 346755 , 347198
CVE-2017-11629FineCMS <=5.0.10 - Cross-Site Scriptingfinecms6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2017-9413Subsonic 6.1.1 - Server-Side Request Forgerysubsonic8.8 (v3.0)High390726 , 392301 , 392647 , 392648
CVE-2017-9822DotNetNuke 5.0.0 - 9.3.0 - Cookie Deserialization Remote Code Executiondotnetnuke8.8 (v3.1)High344365 , 344370
CVE-2017-11444Subrion CMS <4.1.5.10 - SQL Injectionsubrion cms9.8 (v3.0)Critical341245
CVE-2017-11456Geneko Routers - Path Traversalgwr352 3g router firmware7.5 (v3.0)High346019
CVE-2017-9811Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilitiesanti-virus for linux server9.8 (v3.0)Critical390704 , 390724
CVE-2017-9810Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilitiesanti-virus for linux server8.8 (v3.0)High390704 , 390724
CVE-2017-1000028Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusionglassfish server7.5 (v3.0)High347009 , 390716
CVE-2017-1000029Oracle GlassFish Server Open Source Edition 3.0.1 - Local File Inclusionglassfish server7.5 (v3.0)High347009
CVE-2017-9812Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilitiesanti-virus for linux server7.5 (v3.0)High390704 , 390724
CVE-2017-9813Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilitiesanti-virus for linux server6.1 (v3.0)Medium390704 , 390724
CVE-2017-11165DataTaker DT80 dEX 1.50.012 - Information Disclosuredt80 dex firmware9.8 (v3.1)Critical390716
CVE-2017-9791Apache Struts2 S2-053 - Remote Code Executionstruts9.8 (v3.1)Critical337207
CVE-2017-11107phpLDAPadmin <= 1.2.3 - Reflected XSSphpldapadmin6.1 (v3.1)Medium340147 , 341256 , 341266 , 342259 , 350148
CVE-2017-10974Yaws 1.91 - Local File Inclusionyaws7.5 (v3.0)High350591
CVE-2017-9841PHPUnit - Remote Code Executionphpunit9.8 (v3.1)Critical392648 , 393782
CVE-2017-9833BOA Web Server 0.94.14 - Arbitrary File Accessboa7.5 (v3.1)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2017-9355Subsonic 6.1.1 - XML External Entity Injectionsubsonic7.4 (v3.0)High390726 , 392301 , 392647 , 392648
CVE-2017-9416Odoo 8.0/9.0/10.0 - Local File Inclusionodoo6.5 (v3.0)Medium347009 , 390716
CVE-2017-9288WordPress Raygun4WP <=1.8.0 - Cross-Site Scriptingraygun4wp6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-6256SAP Business One for Android 1.2.3 - XML External Entity Injectionbusiness one9.6 (v3.0)Critical344372
CVE-2017-5868OpenVPN Access Server 2.1.4 - CRLF Injectionopenvpn access server6.1 (v3.0)Medium330708 , 390714
CVE-2016-4977Spring Security OAuth2 Remote Command Executionspring security oauth8.8 (v3.0)High393655
CVE-2015-4455WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Uploadaviary image editor add-on for gravity forms9.8 (v3.0)Critical340007 , 391742 , 391743
CVE-2015-5469WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusionmdc youtube downloader7.5 (v3.0)High344360 , 347009 , 390709
CVE-2017-9140Reflected XSS - Telerik Reporting Moduletelerik reporting6.1 (v3.0)Medium333141 , 341256 , 342259 , 346755
CVE-2017-9072RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scriptingflatcalendarxp6.1 (v3.0)Medium392301
CVE-2017-8917Joomla! <3.7.1 - SQL Injectionjoomla!9.8 (v3.0)Critical340157 , 340159 , 341245 , 360147 , 360148
CVE-2017-8295WordPress Core < 4.7.4 - Unauthorized Password ResetWordPress5.9 (v3.0)Medium377360
CVE-2016-10367Opsview Monitor Pro - Local File Inclusionopsview7.5 (v3.0)High390709
CVE-2017-5689Intel Active Management Technology - System Privilegesproliant ml10 gen9 server firmware9.8 (v3.1)Critical390726 , 392647
CVE-2017-5631KMCIS CaseAware - Cross-Site Scriptingcaseaware6.1 (v3.0)Medium340147 , 341266 , 342259 , 346755 , 350147 , 350148 , 360030
CVE-2017-8225GoAhead Camera - Credential Disclosurewireless ip camera (p2p) firmware9.8 (v3.0)Critical390716
CVE-2015-0104IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Executionchange and configuration management database8.8 (v3.0)High392301
CVE-2015-7245D-Link DVG-N5402SP - Local File Inclusiondvg-n5402sp firmware7.5 (v3.0)High392301
CVE-2017-3546Oracle PeopleSoft - Server-Side Request Forgerypeoplesoft enterprise peopletools6.5 (v3.0)Medium390727 , 392301 , 392648
CVE-2017-3548Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPEpeoplesoft enterprise peopletools6.5 (v3.0)Medium330791 , 340152
CVE-2017-3528Oracle E-Business Suite 12.1.3/12.2.x - Open Redirectapplications framework5.4 (v3.0)Medium344365
CVE-2016-1555NETGEAR WNAP320 Access Point Firmware - Remote Command Injectionwnap320 firmware9.8 (v3.1)Critical340014 , 344364 , 344366
CVE-2016-4337Ktools Photostore 4.7.5 - Blind SQL Injectionphotostore9.8 (v3.0)Critical390726 , 392647
CVE-2017-7462Intellinet NFC-30IR Camera - Multiple Vulnerabilitiesnfc-30ir firmware9.8 (v3.0)Critical330925 , 344360 , 347009
CVE-2017-7461Intellinet NFC-30IR Camera - Multiple Vulnerabilitiesnfc-30ir firmware4.9 (v3.0)Medium330925 , 344360 , 347009
CVE-2017-6190D-Link DWR-116 / DWR-116A1 - Arbitrary File Downloaddwr-116 firmware7.5 (v3.0)High347009 , 390727 , 392648
CVE-2017-7185Cesanta Mongoose OS - Use-After-Freemongoose embedded web server library7.5 (v3.0)High330791 , 340152
CVE-2017-6884Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injectionemg2926 firmware8.8 (v3.1)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2017-6338Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilitiesinterscan web security virtual appliance6.5 (v3.0)Medium340147 , 340148 , 342259 , 345493 , 346755 , 350148 , 390724
CVE-2017-6339Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilitiesinterscan web security virtual appliance6.5 (v3.0)Medium340147 , 340148 , 342259 , 345493 , 346755 , 350148 , 390724
CVE-2017-6340Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilitiesinterscan web security virtual appliance5.4 (v3.0)Medium340147 , 340148 , 342259 , 345493 , 346755 , 350148 , 390724
CVE-2017-7402Pixie 1.0.4 - Arbitrary File Uploadpixie9.8 (v3.0)Critical345493
CVE-2017-7391Magmi 0.7.22 - Cross-Site Scriptingmagmi6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2017-5850OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Serviceopenbsd7.5 (v3.0)High390727 , 392301 , 392648
CVE-2017-6443EPSON TMNet WebConfig 1.00 - Cross-Site Scriptingtmnet webconfig6.1 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2017-6823Fiyo CMS 2.0.6.1 - Privilege Escalationfiyo cms8.8 (v3.0)High345493 , 390724
CVE-2017-5638Apache Struts 2 - Remote Command Executionstruts9.8 (v3.1)Critical332791 , 334168 , 390719
CVE-2017-6478MaNGOSWebV4 < 4.0.8 - Cross-Site Scriptingmangoswebv46.1 (v3.1)Medium341266 , 346755
CVE-2016-9682Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injectionsonicwall secure remote access server9.8 (v3.0)Critical390727 , 392301 , 392648
CVE-2016-9269Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilitiesinterscan web security virtual appliance9.9 (v3.0)Critical340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2016-9315Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilitiesinterscan web security virtual appliance8.8 (v3.0)High340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2016-9314Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilitiesinterscan web security virtual appliance7.8 (v3.0)High340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2016-9316Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilitiesinterscan web security virtual appliance5.4 (v3.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2016-10134Zabbix - SQL Injectionzabbix9.8 (v3.0)Critical340157 , 340159 , 341245 , 360147 , 360148
CVE-2016-10043Radisys MRF - Command Injectionweb panel10.0 (v3.0)Critical341245
CVE-2016-6600WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilitieswebnms framework9.8 (v3.0)Critical390727 , 392301 , 392648
CVE-2016-6602WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilitieswebnms framework9.8 (v3.0)Critical390727 , 392301 , 392648
CVE-2016-6603WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilitieswebnms framework9.8 (v3.0)Critical390727 , 392301 , 392648
CVE-2016-6601WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilitieswebnms framework7.5 (v3.0)High344360 , 347009 , 390709 , 390727 , 392301 , 392648
CVE-2016-7981SPIP <3.1.2 - Cross-Site Scriptingspip6.1 (v3.0)Medium341256 , 341266 , 346755
CVE-2016-4808Web2py 2.14.5 - Multiple Vulnerabilitiesweb2py8.8 (v3.0)High344360 , 344364 , 344366 , 344370
CVE-2016-4806Web2py 2.14.5 - Multiple Vulnerabilitiesweb2py7.5 (v3.0)High344360 , 344364 , 344366 , 344370
CVE-2016-4807Web2py 2.14.5 - Multiple Vulnerabilitiesweb2py4.8 (v3.0)Medium344360 , 344364 , 344366 , 344370
CVE-2016-10108Western Digital MyCloud NAS - Command Injectionmycloud nas9.8 (v3.0)Critical344364 , 344366
CVE-2016-6277NETGEAR Routers - Remote Code Executiond6220 firmware8.8 (v3.1)High347009
CVE-2016-3473Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injectionbusiness intelligence publisher7.7 (v3.0)High330791 , 340152 , 344370 , 344372 , 380018 , 390704 , 392301
CVE-2016-1000126WordPress Admin Font Editor <=1.8 - Cross-Site Scriptingadmin-font-editor6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000127WordPress AJAX Random Post <=2.00 - Cross-Site Scriptingajax-random-post6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000128WordPress anti-plagiarism <=3.60 - Cross-Site Scriptinganti-plagiarism6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000129WordPress defa-online-image-protector <=3.3 - Cross-Site Scriptingdefa-online-image-protector6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000130WordPress e-search <=1.0 - Cross-Site Scriptinge-search6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000131WordPress e-search <=1.0 - Cross-Site Scriptingesearch6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2016-1000132WordPress enhanced-tooltipglossary 3.2.8 - Cross-Site Scriptingtooltip glossary6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000133WordPress forget-about-shortcode-buttons 1.1.1 - Cross-Site Scriptingforget about shortcode buttons6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000134WordPress HDW Video Gallery <=1.2 - Cross-Site Scriptinghdw-tube6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000135WordPress HDW Video Gallery <=1.2 - Cross-Site Scriptinghdw-tube6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000136WordPress heat-trackr 1.0 - Cross-Site Scriptingheat-trackr6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000137WordPress Hero Maps Pro 2.1.0 - Cross-Site Scriptinghero-maps-pro6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000138WordPress Admin Font Editor <=1.8 - Cross-Site Scriptingindexisto6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000139WordPress Infusionsoft Gravity Forms <=1.5.11 - Cross-Site Scriptinginfusionsoft6.1 (v3.0)Medium340147 , 341256 , 341266 , 342259
CVE-2016-1000140WordPress New Year Firework <=1.1.9 - Cross-Site Scriptingnew-year-firework6.1 (v3.0)Medium340147 , 341266
CVE-2016-1000141WordPress Page Layout builder v1.9.3 - Cross-Site Scriptingpage-layout-builder6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2016-1000142WordPress MW Font Changer <=4.2.5 - Cross-Site Scriptingparsi-font6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000143WordPress Photoxhibit 2.1.8 - Cross-Site Scriptingphotoxhibit6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000146WordPress Pondol Form to Mail <=1.1 - Cross-Site Scriptingpondol-formmail6.1 (v3.0)Medium322100 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000148WordPress S3 Video <=0.983 - Cross-Site Scriptings3-video6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2016-1000149WordPress Simpel Reserveren <=3.5.2 - Cross-Site Scriptingsimpel-reserveren6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2016-1000152WordPress Tidio-form <=1.0 - Cross-Site Scriptingtidio-form6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2016-1000153WordPress Tidio Gallery <=1.1 - Cross-Site Scriptingtidio-gallery6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000154WordPress WHIZZ <=1.0.7 - Cross-Site Scriptingwhizz6.1 (v3.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2016-1000155WordPress WPSOLR <=8.6 - Cross-Site Scriptingwpsolr-search-engine6.1 (v3.0)Medium340147 , 341266 , 342259
CVE-2015-2080Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffersfedora7.5 (v3.0)High344361 , 344363 , 344364 , 344365 , 390724
CVE-2015-1000005WordPress Candidate Application Form <= 1.3 - Local File Inclusioncandidate-application-form7.5 (v3.0)High337473 , 344360 , 347009 , 390709
CVE-2015-1000010WordPress Simple Image Manipulator < 1.0 - Local File Inclusionsimple-image-manipulator7.5 (v3.0)High337473 , 344360 , 347009 , 390709
CVE-2015-1000012WordPress MyPixs <=0.3 - Local File Inclusionmypixs7.5 (v3.0)High344360 , 347009 , 390709
CVE-2016-6435Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusionsecure firewall management center6.5 (v3.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2016-5674NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesreadynas surveillance9.8 (v3.0)Critical344363 , 392301
CVE-2016-5675NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesreadynas surveillance9.8 (v3.0)Critical392301
CVE-2016-5678NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesnvrmini 29.8 (v3.0)Critical392301
CVE-2016-5679NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesnvrmini 28.8 (v3.0)High392301
CVE-2016-5680NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesnvrmini 28.8 (v3.0)High392301
CVE-2016-5676NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesreadynas surveillance7.5 (v3.0)High392301
CVE-2016-5677NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesreadynas surveillance7.5 (v3.0)High392301
CVE-2016-5771Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilitiesphp9.8 (v3.1)Critical344365
CVE-2016-5773Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilitiesphp9.8 (v3.0)Critical344365
CVE-2016-1337Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 firmware8.1 (v3.0)High333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2016-1328Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 firmware7.5 (v3.0)High333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2016-1336Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 firmware7.5 (v3.0)High333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2016-4309Symphony CMS 2.6.7 - Session Fixationsymphony7.5 (v3.1)High390727 , 392301 , 392648
CVE-2016-3088Apache ActiveMQ Fileserver - Arbitrary File Writeactivemq9.8 (v3.1)Critical392301
CVE-2015-6834Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilitiesphp9.8 (v3.0)Critical344365
CVE-2016-3081Apache S2-032 Struts - Remote Code Executionstruts8.1 (v3.0)High337209 , 337211 , 344360 , 347009 , 390904
CVE-2016-2386SAP NetWeaver J2EE Engine 7.40 - SQL Injectionnetweaver application server java9.8 (v3.1)Critical340016 , 340156 , 341245 , 380026 , 390704
CVE-2016-2389SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusionnetweaver7.5 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2016-2388SAP NetWeaver J2EE Engine 7.40 - SQL Injectionnetweaver application server java5.3 (v3.1)Medium340016 , 340156 , 341245 , 380026 , 390704
CVE-2016-1910SAP NetWeaver J2EE Engine 7.40 - SQL Injectionnetweaver5.3 (v3.0)Medium340016 , 340156 , 341245 , 380026 , 390704
CVE-2015-5471Swim Team <= v1.44.10777 - Local File Inclusionswim team5.3 (v3.0)Medium344360 , 347009 , 390709
CVE-2015-4694WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrievalzip attachments8.6 (v3.0)High340007 , 344360 , 347009 , 390709
CVE-2015-6018ZYXEL PMG5318-B20A - OS Command Injectionpmg5318-b20a firmware9.8 (v3.0)Critical330791 , 340152
CVE-2015-4027Acunetix WVS 10 - Local Privilege Escalationweb vulnerability scanner7.2 (v2.0)High330791 , 340152 , 390726 , 392647
CVE-2015-6401Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter7.5 (v2.0)High333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2015-6402Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter4.3 (v2.0)Medium333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2015-7297Joomla! Core SQL Injectionjoomla!7.5 (v2.0)High340157 , 340159 , 341245 , 360147 , 360148
CVE-2015-5285Kallithea 0.2.9 - 'came_from' HTTP Response Splittingkallithea5.0 (v2.0)Medium390722 , 390727 , 392648
CVE-2015-6477Nordex NC2 - Cross-Site Scriptingnordex control 2 scada6.1 (v3.1)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2015-4040F5 Big-IP 10.2.4 Build 595.0 Hotfix HF3 - Directory Traversalenterprise manager4.0 (v2.0)Medium344370 , 390724
CVE-2015-6920WordPress sourceAFRICA <=0.1.3 - Cross-Site Scriptingsourceafrica4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 348476 , 350147 , 350148
CVE-2015-5688Geddy <13.0.8 - Local File Inclusiongeddy5.0 (v2.0)Medium347009
CVE-2015-2807Navis DocumentCloud <0.1.1 - Cross-Site Scriptingnavis documentcloud4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 348476 , 350147 , 350148
CVE-2015-5161Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injectionzend framework6.8 (v2.0)Medium344372 , 390727 , 392301 , 392648
CVE-2015-4425Pimcore CMS Build 3450 - Directory Traversalpimcore4.9 (v2.0)Medium390726 , 392647
CVE-2015-5531ElasticSearch <1.6.1 - Local File Inclusionelasticsearch5.0 (v2.0)Medium347009 , 392301
CVE-2015-4666Xceedium Xsuite - Multiple Vulnerabilitiesxsuite5.0 (v2.0)Medium320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347009 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2015-4665Xceedium Xsuite - Multiple Vulnerabilitiesxsuite4.3 (v2.0)Medium320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2014-9735WordPress RevSlider - Remote Code Execution via File Uploadshowbiz pro7.5 (v2.0)High337469
CVE-2015-3897Bonita BPM Portal <6.5.3 - Local File Inclusionbonita bpm portal5.0 (v2.0)Medium340007 , 344360
CVE-2015-4420Opsview 4.6.2 - Multiple Cross-Site Scripting Vulnerabilitiesopsview4.3 (v2.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2015-4414WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversalse html5 album audio player5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2015-3648ResourceSpace - Local File inclusionresourcespace7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2015-2996SysAid Help Desk <15.2 - Local File Inclusionsysaid8.5 (v2.0)High344360 , 347009 , 390709
CVE-2015-1389Aruba ClearPass Policy Manager - Persistent Cross-Site Scriptingclearpass policy manager4.3 (v2.0)Medium333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2015-4127WordPress Church Admin <0.810 - Cross-Site Scriptingchurch admin4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2015-4062WordPress NewStatPress 0.9.8 - SQL Injectionnewstatpress6.5 (v2.0)Medium341245 , 380122
CVE-2015-4063NewStatPress <0.9.9 - Cross-Site Scriptingnewstatpress3.5 (v2.0)Low341266 , 346755
CVE-2015-1880Fortinet FortiOS <=5.2.3 - Cross-Site Scriptingfortios4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2015-3337Elasticsearch - Local File Inclusionelasticsearch4.3 (v2.0)Medium347009
CVE-2012-5451TVMOBiLi 2.1.0.3557 - Denial of Servicetvmobili5.0 (v2.0)Medium390727 , 392301 , 392648
CVE-2015-3035TP-LINK - Local File Inclusiontl-wr841n (9.0) firmware7.5 (v3.1)High347009
CVE-2015-1635Microsoft Windows 'HTTP.sys' - Remote Code ExecutionWindows 79.8 (v3.1)Critical363434
CVE-2014-9145Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v2.0)High340007 , 340156 , 341145 , 344360 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647
CVE-2014-9146Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms4.3 (v2.0)Medium340007 , 340156 , 341145 , 344360 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647
CVE-2015-2824WordPress Plugin Simple Ads Manager - Multiple SQL Injectionssimple ads manager7.5 (v2.0)High344361 , 344363 , 344364 , 344366 , 344370 , 360152 , 360153 , 380026 , 390720 , 390724 , 390726 , 390904 , 392647
CVE-2015-2166Ericsson Drutt MSDP - Local File Inclusiondrutt mobile service delivery platform5.0 (v2.0)Medium347009
CVE-2015-2755WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scriptingab google map travel6.8 (v2.0)Medium346755 , 377360
CVE-2014-7884ArcSight Logger - Arbitrary File Upload / Code Executionarcsight logger9.0 (v2.0)High390726 , 392647
CVE-2015-2275WoltLab Community Gallery - Persistent Cross-Site Scriptingcommunity gallery4.3 (v2.0)Medium340147 , 340148 , 341256 , 342259 , 344365 , 344370 , 346755 , 390726 , 392647
CVE-2015-2196WordPress Spider Calendar <=1.4.9 - SQL Injectionspider calendar7.5 (v2.0)High340016 , 340156 , 380122
CVE-2015-2067Magento Server MAGMI - Directory Traversalmagmi5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2015-2068Magento Server Mass Importer - Cross-Site Scriptingmagmi4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2015-1427ElasticSearch - Remote Code Executionelasticsearch9.8 (v3.1)Critical344360 , 380026 , 390724
CVE-2015-1518RedaxScript CMS 2.2.0 - SQL Injectionredaxscript7.5 (v2.0)High334073 , 341245 , 344363 , 344364 , 344365 , 344370 , 350147 , 360152 , 360153 , 380026 , 390724 , 390726 , 392647
CVE-2015-1579WordPress Slider Revolution - Local File Disclosuredivi5.0 (v2.0)Medium336461 , 337479 , 344360 , 381206
CVE-2015-1400NPDS CMS REvolution-13 - SQL Injectionrevolution7.5 (v2.0)High334168 , 390726 , 391213 , 392647
CVE-2015-1428Sefrengo CMS 1.6.1 - Multiple SQL Injectionssefrengo7.5 (v2.0)High390704
CVE-2015-0231Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilitiesphp7.5 (v2.0)High344365
CVE-2014-0191eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injectionfusion middleware4.3 (v2.0)Medium390727 , 392301 , 392648
CVE-2014-10037DomPHP 0.83 - Directory Traversaldomphp7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2014-100004Sitecore CMS - Cross-Site Scriptingsitecore.net4.3 (v2.0)Medium333141 , 347198
CVE-2014-9464Microweber CMS 0.95 - SQL Injectionmicroweber7.5 (v2.0)High390726 , 392301 , 392647 , 392648
CVE-2014-9444Frontend Uploader <= 0.9.2 - Cross-Site Scriptingfrontend uploader4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147
CVE-2014-9119WordPress DB Backup <=4.5 - Local File Inclusiondb backup5.0 (v2.0)Medium336461 , 340007 , 344360 , 381206 , 393759
CVE-2013-6041Webuzo 2.1.3 - Multiple Vulnerabilitieswebuzo7.5 (v2.0)High333140 , 333141 , 340149 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 350148 , 390726 , 392647
CVE-2013-6043Webuzo 2.1.3 - Multiple Vulnerabilitieswebuzo5.0 (v2.0)Medium333140 , 333141 , 340149 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 350148 , 390726 , 392647
CVE-2014-8142Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilitiesphp7.5 (v2.0)High344365
CVE-2014-5462OpenEMR 4.1.2(7) - Multiple SQL Injectionsopenemr6.5 (v2.0)Medium392301
CVE-2014-8877WordPress Plugin CM Download Manager 2.0.0 - Code Injectioncm download manager10.0 (v2.0)High340087 , 340095 , 390726 , 392301 , 392647 , 392648
CVE-2014-9215PBBoard CMS 3.0.1 - SQL Injectionpbboard7.5 (v2.0)High340095 , 340213 , 344363 , 344370 , 360153 , 380026 , 390724 , 390726 , 392647
CVE-2014-8799WordPress Plugin DukaPress 2.5.2 - Directory Traversaldukapress5.0 (v2.0)Medium336461 , 340007 , 344360 , 381206
CVE-2014-9094WordPress DZS-VideoGallery Plugin Cross-Site Scriptingvideo gallery4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2014-8682Gogs (Go Git Service) - SQL Injectiongogs7.5 (v2.0)High340016 , 340017 , 340157 , 360147 , 360148 , 380026
CVE-2014-8727F5 BIG-IP 10.1.0 - Directory Traversalbig-ip local traffic manager6.2 (v2.0)Medium340007 , 344360 , 390709
CVE-2014-5258webEdition 6.3.8.0 - Directory Traversalwebedition cms4.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2014-7176Enalean Tuleap 7.4.99.5 - Blind SQL Injectiontuleap6.5 (v2.0)Medium390726 , 392301 , 392647 , 392648
CVE-2014-2531InterWorx Control Panel 5.0.13 build 574 - 'xhr.php?i' SQL Injectionweb control panel6.5 (v2.0)Medium392301
CVE-2014-4577WP AmASIN – The Amazon Affiliate Shop - Local File Inclusionwp amasin - the amazon affiliate shop5.0 (v2.0)Medium344360 , 347009 , 390709
CVE-2014-6308Osclass Security Advisory 3.4.1 - Local File Inclusionosclass5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2014-3704Drupal SQL Injectiondrupal7.5 (v2.0)High392301
CVE-2014-5308TestLink 1.9.11 - Multiple SQL Injectionstestlink9.0 (v2.0)High350147 , 390726 , 392647
CVE-2014-6287HTTP File Server <2.3c - Remote Command Executionhttp file server9.8 (v3.1)Critical390613 , 390614
CVE-2014-6389PHPCompta/NOALYSS 6.7.1 5638 - Remote Command Executionphpcompta/noalyss7.5 (v2.0)High340128 , 344363 , 350147 , 380018 , 390726 , 392301 , 392647 , 392648
CVE-2011-4624GRAND FlAGallery 1.57 - Cross-Site Scriptinggrand flagallery4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-6271ShellShock - Remote Code Executionbash9.8 (v3.1)Critical330701 , 344360 , 390719 , 393134
CVE-2012-4240Group Office Calendar - '/calendar/json.php' SQL Injectiongroupoffice6.5 (v2.0)Medium340016 , 340157 , 341245 , 360147 , 360148
CVE-2012-4768WordPress Plugin Download Monitor < 3.3.5.9 - Cross-Site Scriptingdownload monitor4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2014-5368WordPress Plugin WP Content Source Control - Directory Traversalwp content source control5.0 (v2.0)Medium336461 , 340007 , 344360 , 381206
CVE-2012-5685ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Resetzpanel7.5 (v2.0)High340016 , 340017 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 360147 , 360148 , 390704
CVE-2012-5683ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Resetzpanel6.8 (v2.0)Medium340016 , 340017 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 360147 , 360148 , 390704
CVE-2012-5684ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Resetzpanel4.3 (v2.0)Medium340016 , 340017 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 360147 , 360148 , 390704
CVE-2014-1222Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesvtiger crm4.0 (v2.0)Medium340007 , 340156 , 341145 , 344360 , 345493 , 380026 , 380122 , 390709 , 390720 , 390726 , 392647
CVE-2014-5181Last.fm Rotation 1.0 - Path Traversallastfm-rotation plugin5.0 (v2.0)Medium344360 , 347009 , 390709
CVE-2014-5187Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversaltom-m8te plugin5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2013-5758Yealink VoIP Phone SIP-T38G - Privilege Escalationsip-t38g9.0 (v2.0)High330925 , 344360 , 344370 , 390724 , 390726 , 392647
CVE-2013-5759Yealink VoIP Phone SIP-T38G - Privilege Escalation-N/AN/A330925 , 344360 , 390724 , 390726 , 392647
CVE-2014-3120ElasticSearch v1.1.1/1.2 RCEelasticsearch8.1 (v3.1)High344360 , 344370 , 380026 , 390724
CVE-2014-5111Fonality trixbox - Local File Inclusiontrixbox5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2014-3110Honeywell XL Web Controller - Cross-Site Scriptingfalcon xlweb linux controller4.3 (v2.0)Medium333141 , 340156 , 341245 , 341256 , 342259 , 346755 , 390724
CVE-2013-5755Yealink VoIP Phone SIP-T38G - Remote Command Executionsip-t38g10.0 (v2.0)High344370 , 390724 , 390726 , 392647
CVE-2014-4940WordPress Plugin Tera Charts - Local File Inclusiontera-charts5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2014-4941Cross RSS 1.7 - Local File Inclusionwp-cross-rss5.0 (v2.0)Medium344360 , 347009 , 390709
CVE-2014-3515Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilitiesphp7.5 (v2.0)High344365
CVE-2014-0864IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits6.8 (v2.0)Medium392301
CVE-2014-0867IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits5.8 (v2.0)Medium392301
CVE-2014-0865IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits4.9 (v2.0)Medium392301
CVE-2014-0868IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits4.9 (v2.0)Medium392301
CVE-2014-0866IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits4.3 (v2.0)Medium392301
CVE-2014-0869IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits4.3 (v2.0)Medium392301
CVE-2014-0870IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits4.3 (v2.0)Medium392301
CVE-2014-0871IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits4.3 (v2.0)Medium392301
CVE-2014-0894IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limits3.5 (v2.0)Low392301
CVE-2014-4513ActiveHelper LiveHelp Server 3.1.0 - Cross-Site Scriptingactivehelper livehelp live chat4.3 (v2.0)Medium333140 , 340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2014-2962Belkin N150 Router 1.00.08/1.00.09 - Path Traversaln150 f9k1009 firmware7.8 (v2.0)High344360 , 347009 , 390709
CVE-2012-5876Nero MediaHome 4.5.8.0 - Denial of Servicemediahome5.0 (v2.0)Medium390726 , 390727 , 392301 , 392647 , 392648
CVE-2012-5877Nero MediaHome 4.5.8.0 - Denial of Servicemediahome5.0 (v2.0)Medium390726 , 390727 , 392301 , 392647 , 392648
CVE-2014-2846WD Arkeia Virtual Appliance 10.2.9 - Local File Inclusionarkeia virtual appliance firmware7.5 (v2.0)High344360
CVE-2014-2383Dompdf < v0.6.0 - Local File Inclusiondompdf6.8 (v2.0)Medium340077 , 340165 , 344360 , 347009
CVE-2014-2908Siemens SIMATIC S7-1200 CPU - Cross-Site Scriptingsimatic s7 cpu 1200 firmware4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2013-2287WordPress Plugin Uploader 1.0.4 - Cross-Site Scriptinguploader4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2013-5640Gnew 2013.1 - Multiple Vulnerabilities (2)gnew7.5 (v2.0)High344360 , 390727 , 392301 , 392648
CVE-2013-2642Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilitiesweb appliance firmware9.3 (v2.0)High344362 , 344364 , 344366
CVE-2013-2641Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilitiesweb appliance firmware5.0 (v2.0)Medium344362 , 344364 , 344366
CVE-2013-2643Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilitiesweb appliance firmware4.3 (v2.0)Medium344362 , 344364 , 344366
CVE-2013-5639Gnew 2013.1 - Multiple Vulnerabilities (2)gnew7.5 (v2.0)High344360 , 390727 , 392301 , 392648
CVE-2014-1944Ilch CMS 2.0 - Persistent Cross-Site Scriptingilch cms4.3 (v2.0)Medium344370
CVE-2012-5192Bitweaver 2.8.1 - Multiple Vulnerabilitiesbitweaver5.0 (v2.0)Medium340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 380026
CVE-2013-7137Burden 1.8 - Authentication Bypassburden9.8 (v3.1)Critical390727 , 392301 , 392648
CVE-2014-1206Open Web Analytics 1.5.4 - 'owa_email_address' SQL Injectionopen web analytics7.5 (v2.0)High340016 , 340017 , 340144 , 340157 , 360147 , 360148
CVE-2013-7240WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversaladvanced dewplayer5.0 (v2.0)Medium336461 , 340007 , 344360 , 381206
CVE-2013-7091Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusionzimbra collaboration suite5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2013-6042Webuzo 2.1.3 - Multiple Vulnerabilitieswebuzo4.3 (v2.0)Medium333140 , 333141 , 340149 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 350148 , 390726 , 392647
CVE-2013-6164Project'Or RIA 3.4.0 - 'objectDetail.php?objectId' SQL Injectionprojeqtor7.5 (v2.0)High392301
CVE-2013-5694Opsview pre 4.4.1 - Blind SQL Injectionopsview7.5 (v2.0)High344370 , 390704 , 390726 , 392647
CVE-2013-6281WordPress Spreadsheet - Cross-Site Scriptingdhtmlxspreadsheet4.3 (v2.0)Medium340147 , 341266 , 342259
CVE-2013-5528Cisco Unified Communications Manager 7/8/9 - Directory Traversalunified communications manager4.0 (v2.0)Medium344360 , 347009 , 390709
CVE-2013-5979Xibo 1.2.2/1.4.1 - Directory Traversalxibo5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2013-4625WordPress Plugin Duplicator < 0.4.5 - Cross-Site Scriptingduplicator4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2013-2251Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Executionstruts9.8 (v3.1)Critical337209 , 337211 , 344361 , 393655
CVE-2013-4117WordPress Plugin Category Grid View Gallery 2.3.1 - Cross-Site Scriptingcategory-grid-view-gallery4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2013-1965Apache Struts2 S2-012 RCEstruts9.3 (v2.0)High337207 , 337209 , 337211 , 344360
CVE-2013-3526WordPress Plugin Traffic Analyzer - 'aoid' Cross-Site Scriptingtrafficanalyzer4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2013-0249cURL - Buffer Overflow (PoC)curl7.5 (v2.0)High390727 , 392301 , 392648
CVE-2011-5265Featurific For WordPress 1.6.2 - Cross-Site Scriptingfeaturific-for-wordpress4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2011-4618Advanced Text Widget < 2.0.2 - Cross-Site Scriptingadvanced text widget plugin4.3 (v2.0)Medium340147 , 341266 , 342259
CVE-2012-5875FireFly Mediaserver 1.0.0.1359 - Null Pointer Dereferencefirefly media server5.0 (v2.0)Medium390727 , 392301 , 392648
CVE-2012-6499WordPress Plugin Age Verification v0.4 - Open Redirectage verification5.8 (v2.0)Medium392301
CVE-2012-4982Forescout CounterACT 6.3.4.1 - Open Redirectcounteract5.8 (v2.0)Medium340162 , 340163
CVE-2010-5286Joomla! Component Jstore - 'Controller' Local File Inclusioncom jstore10.0 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-5913WordPress Integrator 1.32 - Cross-Site Scriptingwordpress integrator4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2012-4940Axigen Mail Server Filename Directory Traversalaxigen free mail server6.4 (v2.0)Medium344365 , 347019
CVE-2012-4547AWStats 6.95/7.0 - 'awredir.pl' Cross-Site Scriptingawstats4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2012-3153Oracle Forms & Reports RCE (CVE-2012-3152 & CVE-2012-3153)fusion middleware6.4 (v2.0)Medium340165
CVE-2011-4640WebTitan < 3.60 - Local File Inclusionwebtitan4.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2010-5278MODx manager - Local File Inclusionmodx revolution4.3 (v2.0)Medium340007 , 390613 , 390614
CVE-2012-4242WordPress Plugin MF Gig Calendar 0.9.2 - Cross-Site Scriptingmf gig calendar4.3 (v2.0)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2011-5179Skysa App Bar 1.04 - Cross-Site Scriptingskysa app bar integration plugin4.3 (v2.0)Medium340147 , 341266 , 342259
CVE-2011-5181ClickDesk Live Support Live Chat 2.0 - Cross-Site Scriptingclickdesk live support-live chat plugin4.3 (v2.0)Medium340147 , 341266 , 342259
CVE-2012-4889ManageEngine Firewall Analyzer 7.2 - Cross-Site Scriptingfirewall analyzer4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2011-4448WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki7.5 (v2.0)High331702 , 340007 , 344360 , 344361 , 344362 , 344363 , 344370 , 360152 , 390715 , 390726 , 392647
CVE-2011-4449WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.8 (v2.0)Medium331702 , 340007 , 344360 , 344361 , 344362 , 344363 , 344370 , 360152 , 390715 , 390726 , 392647
CVE-2011-4452WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.8 (v2.0)Medium331702 , 340007 , 344360 , 344361 , 344362 , 344363 , 344370 , 360152 , 390715 , 390726 , 392647
CVE-2011-4450WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.4 (v2.0)Medium331702 , 340007 , 344360 , 344361 , 344362 , 344363 , 344370 , 360152 , 390715 , 390726 , 392647
CVE-2011-4451WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki4.3 (v2.0)Medium331702 , 340007 , 344360 , 344361 , 344362 , 344363 , 344370 , 360152 , 390715 , 390726 , 392647
CVE-2011-4926Adminimize 1.7.22 - Cross-Site Scriptingadminimize4.3 (v2.0)Medium340147 , 341266 , 342259
CVE-2011-5106WordPress Plugin Flexible Custom Post Type < 0.1.7 - Cross-Site Scriptingflexible custom post type4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2011-5107Alert Before Your Post <= 0.1.1 - Cross-Site Scriptingalert before you post4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2012-1835WordPress Plugin All-in-One Event Calendar 1.4 - Cross-Site Scriptingall-in-one event calendar4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2012-2371WP-FaceThumb 0.1 - Cross-Site Scriptingwp-facethumb4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2012-4253MySQLDumper 1.24.4 - Directory Traversalmysqldumper4.3 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-42732 Click Socialmedia Buttons < 0.34 - Cross-Site Scripting2-click-social-media-buttons4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2012-3350Webmatic 3.1.1 - Blind SQL Injectionwebmatic6.8 (v2.0)Medium341245 , 390727 , 392301 , 392648
CVE-2012-1823PHP CGI v5.3.12/5.4.2 Remote Code Executionphp9.8 (v3.1)Critical340165 , 378491
CVE-2009-5114WebGlimpse 2.18.7 - Directory Traversalwebglimpse5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2012-099611in1 CMS 1.2.1 - Local File Inclusion (LFI)11in15.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-1226Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilitiesdolibarr erp/crm7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2012-0991OpenEMR 4.1 - Local File Inclusionopenemr3.5 (v2.0)Low340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2012-0981phpShowtime 2.0 - Directory Traversalphpshowtime5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2011-4899WordPress Core 3.3.1 - Multiple VulnerabilitiesWordPress7.5 (v2.0)High340147 , 340148 , 344370 , 346755 , 381209 , 381210 , 390727 , 392301 , 392648
CVE-2011-4898WordPress Core 3.3.1 - Multiple VulnerabilitiesWordPress5.0 (v2.0)Medium340147 , 340148 , 344370 , 346755 , 381209 , 381210 , 390727 , 392301 , 392648
CVE-2012-0782WordPress Core 3.3.1 - Multiple VulnerabilitiesWordPress4.3 (v2.0)Medium340147 , 340148 , 344370 , 346755 , 381209 , 381210 , 390727 , 392301 , 392648
CVE-2012-0286stoneware webnetwork6 - Multiple Vulnerabilitieswebnetwork6.8 (v2.0)Medium390726 , 392301 , 392647 , 392648
CVE-2012-0285stoneware webnetwork6 - Multiple Vulnerabilitieswebnetwork4.3 (v2.0)Medium390726 , 392301 , 392647 , 392648
CVE-2012-0896Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Accesscount per day5.0 (v2.0)Medium344360 , 347009 , 390709
CVE-2012-0901YouSayToo auto-publishing 1.0 - Cross-Site Scriptingyousaytoo4.3 (v2.0)Medium340147 , 341266 , 342259
CVE-2012-0392Apache Struts2 S2-008 RCEstruts6.8 (v2.0)Medium337207 , 337209 , 337210 , 337211 , 344360 , 344370 , 347009
CVE-2011-4804Joomla! Component com_kp - 'Controller' Local File Inclusioncom obsuggest5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-5028Joomla! Component JE Job 1.0 - Local File Inclusioncom jejob7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-4977Joomla! Component Canteen 1.0 - Local File Inclusioncom canteen7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2011-3315Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversalunified ip interactive voice response7.8 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2011-2744Chyrp 2.x - Local File Inclusionchyrp6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2011-2780Chyrp 2.x - Local File Inclusionchyrp5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2011-1669WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI)wp custom pages5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2010-4769Joomla! Component Jimtawl 1.0.2 - Local File Inclusioncom jimtawl7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2011-0049Majordomo2 - SMTP/HTTP Directory Traversalmajordomo 25.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2010-4719Joomla! Component JRadio - Local File Inclusioncom jradio7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2011-0518LotusCMS 3.0 - Remote Code Executionfraise5.1 (v2.0)Medium340095 , 393655
CVE-2010-4617Joomla! Component JotLoader 2.2.1 - Local File Inclusioncom jotloader6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-4275Radius Manager 3.8.0 - Multiple Cross-Site Scripting Vulnerabilitiesradius manager3.5 (v2.0)Low346755
CVE-2010-4297VMware Tools - Update OS Command Injectionworkstation7.2 (v2.0)High392301
CVE-2010-4282Pandora Fms < 3.1.1 - Directory Traversalpandora fms7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2010-4231Camtron CMNC-200 IP Camera - Directory Traversalcmnc-200 firmware7.8 (v2.0)High347009
CVE-2010-3486SmarterMail < 7.2.3925 - Persistent Cross-Site Scriptingsmartermail5.0 (v2.0)Medium392301
CVE-2010-3426Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusioncom jphone7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-3203Joomla! Component PicSell 1.0 - Arbitrary File Retrievalcom picsell5.0 (v2.0)Medium340007 , 344360
CVE-2010-2861Adobe ColdFusion - Directory Traversalcoldfusion9.8 (v3.1)Critical340007 , 344360 , 347009 , 390613 , 390614 , 390704 , 390709
CVE-2010-2918Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusioncom joomla visites7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2010-2920Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusioncom foobla suggestions6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2857Joomla! Component Music Manager - Local File Inclusioncom music6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2682Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusioncom realtyna7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2680Joomla! Component jesectionfinder - Local File Inclusioncom jesectionfinder6.8 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2010-2507Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusioncom picasa2gallery6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2307Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversalsurfboard sbv6120e5.0 (v2.0)Medium347009
CVE-2010-2259Joomla! Component com_bfsurvey - Local File Inclusioncom bfsurvey profree7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2128Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusioncom jequoteform7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2122Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrievalcom simpledownload6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2033Joomla! Percha Categories Tree 0.6 - Local File Inclusioncom perchacategoriestree7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2034Joomla! Component Percha Image Attach 1.1 - Directory Traversalcom perchaimageattach7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2035Joomla! Component Percha Gallery 1.6 Beta - Directory Traversalcom perchagallery7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2036Joomla! Component Percha Fields Attach 1.0 - Directory Traversalcom perchafieldsattach7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2037Joomla! Component Percha Downloads Attach 1.1 - Directory Traversalcom perchadownloadsattach7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2045Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusioncom dioneformwizard7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2050Joomla! Component MS Comment 0.8.0b - Local File Inclusioncom mscomment7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-2018Lokomedia CMS - Local File Inclusionlokomedia cms5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2010-1952Joomla! Component BeeHeard 1.0 - Local File Inclusioncom beeheard7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1953Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusioncom multimap7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1954Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusioncom multiroot7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1955Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusioncom blogfactory7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1956Joomla! Component Gadget Factory 1.0.0 - Local File Inclusioncom gadgetfactory7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1957Joomla! Component Love Factory 1.3.4 - Local File Inclusioncom lovefactory7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1977Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusioncom jwhmcs7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1980Joomla! Component Joomla! Flickr 1.0 - Local File Inclusioncom joomlaflickr7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1983Joomla! Component redTWITTER 1.0 - Local File Inclusioncom redtwitter7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1979Joomla! Component Affiliate Datafeeds 880 - Local File Inclusioncom datafeeds6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1981Joomla! Component Fabrik 2.0 - Local File Inclusionfabrik6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1982Joomla! Component JA Voice 2.0 - Local File Inclusioncom javoice5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1875Joomla! Component Property - Local File Inclusioncom properties7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1878Joomla! Component OrgChart 1.0.0 - Local File Inclusioncom orgchart7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1858Joomla! Component SMEStorage - Local File Inclusioncom smestorage5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1717Joomla! Component iF surfALERT 1.2 - Local File Inclusionif surfalert7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1715Joomla! Component Online Exam 1.5.0 - Local File Inclusioncom onlineexam6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1718Joomla! Component Archery Scores 1.0.6 - Local File Inclusioncom archeryscores6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1719Joomla! Component MT Fire Eagle 1.2 - Local File Inclusioncom mtfireeagle6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1722Joomla! Component Online Market 2.x - Local File Inclusioncom market6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1723Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusioncom drawroot6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1714Joomla! Component Arcade Games 1.0 - Local File Inclusioncom arcadegames5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1653Joomla! Component Graphics 1.0.6 - Local File Inclusioncom graphics7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1657Joomla! Component SmartSite 1.0.0 - Local File Inclusioncom smartsite5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1658Joomla! Component NoticeBoard 1.3 - Local File Inclusioncom noticeboard5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1659Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusioncom ultimateportfolio5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1602Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusioncom zimbcomment7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1603Joomla! Component ZiMBCore 0.1 - Local File Inclusioncom zimbcore7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1607Joomla! Component WMI 1.5.0 - Local File Inclusioncom wmi6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1601Joomla! Component JA Comment - Local File Inclusioncom jacomment5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1429Red Hat JBoss Enterprise Application Platform - Sensitive Information Disclosurejboss enterprise application platform5.0 (v2.0)Medium382240
CVE-2010-1531Joomla! Component redSHOP 1.0 - Local File Inclusioncom redshop7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1533Joomla! Component TweetLA 1.0.1 - Local File Inclusioncom tweetla7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1535Joomla! Component TRAVELbook 1.0.1 - Local File Inclusioncom travelbook7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1532Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusioncom powermail5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1534Joomla! Component Shoutbox Pro - Local File Inclusioncom shoutbox5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1540Joomla! Component com_blog - Directory Traversalcom myblog5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1495Joomla! Component Matamko 1.01 - Local File Inclusioncom matamko7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1491Joomla! Component MMS Blog 2.3.0 - Local File Inclusioncom mmsblog5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1494Joomla! Component AWDwall 1.5.4 - Local File Inclusioncom awdwall5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1470Joomla! Component Web TV 1.0 - Local File Inclusioncom webtv7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1471Joomla! Component Address Book 1.5.0 - Local File Inclusioncom addressbook7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1472Joomla! Component Horoscope 1.5.0 - Local File Inclusioncom horoscope7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1469Joomla! Component JProject Manager 1.0 - Local File Inclusioncom jprojectmanager6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1473Joomla! Component Advertising 0.25 - Local File Inclusioncom advertising6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1474Joomla! Component Sweetykeeper 1.5 - Local File Inclusioncom sweetykeeper6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1475Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusioncom preventive6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1476Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusioncom alphauserpoints6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1478Joomla! Component Jfeedback 1.2 - Local File Inclusioncom jfeedback6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1461Joomla! Component Photo Battle 1.0.1 - Local File Inclusioncom photobattle5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1352Joomla! Component Juke Box 1.7 - Local File Inclusioncom jukebox5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1353Joomla! Component LoginBox - Local File Inclusioncom loginbox5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1354Joomla! Component VJDEO 1.0 - Local File Inclusioncom vjdeo5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1340Joomla! Component com_jresearch - 'Controller' Local File Inclusioncom jresearch5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1345Joomla! Component Cookex Agency CKForms - Local File Inclusioncom ckforms5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1306Joomla! Component Picasa 2.0 - Local File Inclusioncom joomlapicasa27.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1304Joomla! Component User Status - Local File Inclusioncom userstatus5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1305Joomla! Component JInventory 1.23.02 - Local File Inclusioncom jinventory5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1307Joomla! Component Magic Updater - Local File Inclusioncom joomlaupdater5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1308Joomla! Component SVMap 1.1.1 - Local File Inclusioncom svmap5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1312Joomla! Component News Portal 1.5.x - Local File Inclusioncom news portal5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1314Joomla! Component Highslide 1.5 - Local File Inclusioncom hsconfig5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1315Joomla! Component webERPcustomer - Local File Inclusioncom weberpcustomer5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1313Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusioncom sebercart4.3 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1302Joomla! Component DW Graph - Local File Inclusioncom dwgraphs5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1219Joomla! Component com_janews - Local File Inclusioncom janews6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1217Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusionje form creator4.3 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1056Joomla! Component com_rokdownloads - Local File Inclusioncom rokdownloads6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-1081Joomla! Component com_communitypolls 1.5.2 - Local File Inclusioncom communitypolls5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0972Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusioncom gcalendar7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0985Joomla! Component com_abbrev - Local File Inclusioncom abbrev7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0982Joomla! Component com_cartweberp - Local File Inclusioncom cartweberp4.3 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2009-4679Joomla! Portfolio Nexus - Remote File Inclusioncom if nexus7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2010-0942Joomla! Component com_jvideodirect - Directory Traversalcom jvideodirect5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0943Joomla! Component com_jashowcase - Directory Traversalcom jashowcase5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0944Joomla! Component com_jcollection - Directory Traversalcom jcollection5.0 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0759Joomla! Plugin Core Design Scriptegrator - Local File Inclusionscriptegrator plugin7.5 (v2.0)High344360 , 347009 , 390709
CVE-2010-0696Joomla! Component Jw_allVideos - Arbitrary File Retrievaljw allvideos5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2010-0467Joomla! Component CCNewsLetter - Local File Inclusioncom ccnewsletter5.8 (v3.1)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2010-0157Joomla! Component com_biblestudy - Local File Inclusionjoomla!7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2009-4223KR-Web <=1.1b2 - Remote File Inclusionkr-php web content server7.5 (v2.0)High340162 , 340163
CVE-2009-4202Joomla! Omilen Photo Gallery 0.5b - Local File Inclusionjoomla!7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2009-1479boxalino 09.05.25-0421 - Directory Traversalboxalino7.5 (v2.0)High340007 , 344360 , 390709
CVE-2009-3318Joomla! Roland Breedveld Album 1.14 - Local File InclusionJoomla!7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2009-3053Joomla! Agora 3.0.0b - Local File InclusionJoomla!6.8 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2008-6982Devalcms 1.4a - Cross-Site Scriptingdevalcms4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350148
CVE-2009-1872Adobe Coldfusion <=8.0.1 - Cross-Site Scriptingcoldfusion4.3 (v2.0)Medium340147 , 340148 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2009-2100Joomla! JoomlaPraise Projectfork 2.0.10 - Local File InclusionJoomla!5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2009-2015Joomla! MooFAQ 1.0 - Local File InclusionJoomla!7.5 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2009-1558Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusionwvc54gca7.8 (v2.0)High344360 , 347009 , 390709
CVE-2009-1496Joomla! Cmimarketplace 0.1 - Local File InclusionJoomla!5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2008-6668nweb2fax <=0.2.7 - Local File Inclusionnweb2fax5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2009-1151PhpMyAdmin Scripts - Remote Code Executionphpmyadmin9.8 (v3.1)Critical340029 , 344360
CVE-2009-0932Horde/Horde Groupware - Local File Inclusionhorde6.4 (v2.0)Medium340007 , 340029 , 344360 , 390613 , 390614 , 390709
CVE-2008-6465Parallels H-Sphere 3.0.0 P9/3.1 P1 - Cross-Site Scriptingh-sphere4.3 (v2.0)Medium333141 , 340149 , 342259 , 346755 , 347198 , 360030
CVE-2008-6222Joomla! ProDesk 1.0/1.2 - Local File Inclusionpro desk support center5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2008-6172Joomla! Component RWCards 3.0.11 - Local File Inclusionrwcards6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2009-0545ZeroShell <= 1.0beta11 Remote Code Executionzeroshell10.0 (v2.0)High312657 , 340007 , 340029 , 344360 , 344370 , 347009 , 390709
CVE-2008-6080Joomla! ionFiles 4.4.2 - Local File Inclusioncom ionfiles5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2008-5587phpPgAdmin <=4.2.1 - Local File Inclusionphppgadmin4.3 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2008-4764Joomla! <=2.0.0 RC2 - Local File Inclusioncom extplorer5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2008-4668Joomla! Image Browser 0.1.5 rc2 - Local File Inclusioncom imagebrowser9.0 (v2.0)High340007 , 344360 , 347009 , 390709
CVE-2008-1547Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirectionexchange server4.3 (v2.0)Medium390716
CVE-2008-2938toutvirtual virtualiq pro 3.2 - Multiple Vulnerabilitiestomcat4.3 (v2.0)Medium392301
CVE-2008-2650CMSimple 3.1 - Local File Inclusioncmsimple6.8 (v2.0)Medium340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2008-2398AppServ Open Project <=2.5.10 - Cross-Site Scriptingappserv4.3 (v2.0)Medium333141 , 341256 , 342259 , 346755
CVE-2008-1059WordPress Sniplets 1.1.2 - Local File Inclusionsniplets plugin7.5 (v2.0)High336461 , 340007 , 344360 , 381206
CVE-2008-1061WordPress Sniplets <=1.2.2 - Cross-Site Scriptingsniplets plugin4.3 (v2.0)Medium340147 , 341266
CVE-2007-5728phpPgAdmin <=4.1.1 - Cross-Site Scriptingphppgadmin4.3 (v2.0)Medium340147 , 341266 , 346755
CVE-2007-4556OpenSymphony XWork/Apache Struts2 - Remote Code Executionxwork6.8 (v2.0)Medium337207 , 337209 , 337211 , 344360
CVE-2007-4504Joomla! RSfiles <=1.0.2 - Local File Inclusionrsfiles5.0 (v2.0)Medium340007 , 344360 , 347009 , 390709
CVE-2007-3385Apache Tomcat 6.0.15 - Cookie Quote Handling Remote Information Disclosuretomcat4.3 (v2.0)Medium390727 , 392301 , 392648
CVE-2007-2449Apache Tomcat 4.x-7.x - Cross-Site Scriptingtomcat4.3 (v2.0)Medium340147 , 341266 , 346755
CVE-2007-0885Jira Rainbow.Zen - Cross-Site Scriptingrainbow.zen6.8 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2006-3835toutvirtual virtualiq pro 3.2 - Multiple Vulnerabilitiestomcat5.0 (v2.0)Medium392301
CVE-2006-3392Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosurewebmin5.0 (v2.0)Medium347009
CVE-2006-2842Squirrelmail <=1.4.6 - Local File Inclusionsquirrelmail7.5 (v2.0)High340007 , 340029 , 344360 , 347009 , 390613 , 390614 , 390709
CVE-2006-2826PHPLib < 7.4 - SQL Injectionphplib7.5 (v2.0)High340017 , 340181 , 341245 , 344370 , 360147 , 360148
CVE-2006-1681Cherokee HTTPD <=0.5 - Cross-Site Scriptingcherokee httpd4.3 (v2.0)Medium341266
CVE-2006-0887PHPLib < 7.4 - SQL Injectionphplib7.5 (v2.0)High340017 , 340181 , 341245 , 344370 , 360147 , 360148
CVE-2005-4385Cofax <=2.0RC3 - Cross-Site Scriptingcofax4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2005-3128SquirrelMail Address Add 1.4.2 - Cross-Site Scriptingaddress add plugin4.3 (v2.0)Medium340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2004-0519SquirrelMail 1.4.x - Folder Name Cross-Site Scriptingpropack6.8 (v2.0)Medium341266 , 346755
CVE-2002-1131SquirrelMail 1.2.6/1.2.7 - Cross-Site Scriptingsquirrelmail7.5 (v2.0)High340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2001-1341Solare Datensysteme Solar-Log Devices 2.8.4-56/3.5.2-85 - Multiple Vulnerabilitiesipc at chip embedded-webserver5.0 (v2.0)Medium390716 , 392301
CVE-2000-0760Jakarta Tomcat 3.1 and 3.0 - Information Disclosuretomcat6.4 (v2.0)Medium310094
CVE-2000-0114Microsoft FrontPage Extensions - Information Disclosureinternet information server5.0 (v2.0)Medium310226 , 392301
CVE-2026-53629GLPI - Blind SQL Injection in History Log Filter (LogBleed)-8.8 (v3.1)High380026
CVE-2024-23167GestSup - Cross-Site Scriptinggestsup8.6High333141
CVE-2026-57582GeoNetwork - Reflected Cross-Site Scriptingcore-geonetwork8.2 (v3.1)High346755
CVE-2024-25669CaseAware a360inc - Cross-Site Scriptingcaseaware6.1Medium347198
CVE-2018-10818LG NAS Devices - Remote Code Execution-N/AN/A340014
CVE-2019-8962FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)-N/AN/A345490
CVE-2023-1434Odoo - Cross-Site ScriptingodooN/AN/A341266
CVE-2023-46391WEBIGniter v28.7.23 - Stored Cross Site Scripting (XSS)-N/AN/A340147 , 340148 , 346755 , 390585
CVE-2025-32101UNA CMS <= 14.0.0-RC4 - PHP Object Injection-N/AN/A390501 , 390614