| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-7437 | AzonPost <= 1.3 - Reflected Cross-Site Scripting | moch-a | AzonPost | Medium | 6.1 | 2026-05-12 07:48:20 | Deep Dive |
| CVE-2026-6663 | GWD Connect <= 2.9 - Unauthenticated Limited Code Execution via update_agent | thewebsitesupply | GWD Conex | Medium | 4.8 | 2026-05-12 07:48:20 | Deep Dive |
| CVE-2026-7661 | Bootstrap Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'box' Shortcode | shamim_d | Bootstrap Shortcode | Medium | 6.4 | 2026-05-12 07:48:19 | Deep Dive |
| CVE-2026-3604 | WP SEO Structured Data Schema <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_kcseo_ative_tab' Parameter | kcseopro | WP SEO Structured Data Schema | Medium | 4.9 | 2026-05-12 07:48:19 | Deep Dive |
| CVE-2026-7562 | WP-Redirection <= 1.0.3 - Cross-Site Request Forgery to Settings Update | phkcorp2005 | WP-Redirection | Medium | 4.3 | 2026-05-12 07:48:18 | Deep Dive |
| CVE-2026-5340 | Fancy Image Show <= 9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | gopi_plus | Fancy Image Show | Medium | 6.4 | 2026-05-12 07:48:18 | Deep Dive |
| CVE-2026-6808 | Pricing Tables for WP <= 1.1.0 - Reflected Cross-Site Scripting via 'page' Parameter | optimalplugins | Pricing Tables for WP | Medium | 6.1 | 2026-05-12 07:48:17 | Deep Dive |
| CVE-2026-4301 | Rate Star Review Vote <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'rating_id' Parameter | videowhisper | Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings | Medium | 4.3 | 2026-05-12 07:48:17 | Deep Dive |
| CVE-2026-6913 | Shortcodely <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_area' Shortcode Attribute | patilswapnilv | Shortcodely | Medium | 6.4 | 2026-05-12 07:48:16 | Deep Dive |
| CVE-2026-6708 | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Classroom Deletion via 'id' Parameter | higheredlab | HEL Online Classroom: AI-powered Online Classrooms | Medium | 5.3 | 2026-05-12 07:48:16 | Deep Dive |
| CVE-2026-6402 | webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins | webpack-dev-server | webpack-dev-server | Medium | 5.3 | 2026-05-12 07:45:21 | Deep Dive |
| CVE-2026-35227 | Improper resource management in CODESYS Modbus TCP Server | CODESYS | CODESYS Modbus | 中危 | - | 2026-05-12 07:14:42 | Deep Dive |
| CVE-2026-1185 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS OS | Medium | 5.4 | 2026-05-12 05:49:47 | Deep Dive |
| CVE-2026-0804 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS OS | Medium | 6.7 | 2026-05-12 05:46:45 | Deep Dive |
| CVE-2026-0802 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS OS | Medium | 6.0 | 2026-05-12 05:44:59 | Deep Dive |
| CVE-2026-0541 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS OS | Medium | 6.7 | 2026-05-12 05:42:28 | Deep Dive |
| CVE-2026-1681 | net: Stack Overflow with Ping (to own IP Address) via Shell | zephyrproject-rtos | Zephyr | Medium | 6.1 | 2026-05-12 05:39:03 | Deep Dive |
| CVE-2026-41872 | Kura Sushi Official App 信任管理问题漏洞 | EPG, Inc. | "Kura Sushi Official App" for Android | - | - | 2026-05-12 05:21:43 | Deep Dive |
| CVE-2026-41530 | Chitora Lhaz 路径遍历漏洞 | Chitora soft | Lhaz | - | - | 2026-05-12 05:21:11 | Deep Dive |
| CVE-2026-45430 | Backdrop CMS Salesforce 跨站请求伪造漏洞 | Backdrop CMS contributed projects | backdrop-contrib/salesforce | High | 7.1 | 2026-05-12 04:06:24 | Deep Dive |