| CVE-2026-66066 | Ruby on Rails Active Storage >= 7.2.3.2 / 8.0.5.1 / 8.1.3.1 | Arbitrary File Read / RCE |
| CVE-2026-63219 | GeoNetwork >= 4.2.17 / 4.4.12 | Unauthenticated File Upload |
| CVE-2026-58400 | GeoNetwork >= 4.2.17 / 4.4.12 | Unsafe XSLT Execution |
| CVE-2026-57582 | GeoNetwork >= 4.2.17 / 4.4.12 | Reflected XSS |
| CVE-2026-56730 | Zammad >= 7.0.1 | Missing Authorization |
| CVE-2026-56728 | Zammad >= 7.0.1 | Broken Access Control |
| CVE-2026-55864 | GeoNetwork >= 4.2.17 / 4.4.12 | Server-Side Request Forgery |
| CVE-2023-33970 | Kanboard Management Software >= 1.2.29 | Broken Access Control |
| CVE-2023-33969 | Kanboard Management Software >= 1.2.29 | Stored XSS |
| CVE-2023-33968 | Kanboard Management Software >= 1.2.29 | Broken Access Control |
| CVE-2022-23912 | Wordpress AP Custom Testimonial Plugin >= 1.4.7 | Reflected XSS |
| CVE-2022-23911 | Wordpress AP Custom Testimonial Plugin >= 1.4.7 | SQL Injection |
| CVE-2022-0478 | Wordpress WooCommerce Event Manager Plugin >= 3.5.7 | SQL Injection |