| CVE-2026-73570 | critical | U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog | 1d ago |
| CVE-2024-3094 | high | Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain | 2d ago |
| CVE-2026-69836 | critical | Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) | 2d ago |
| CVE-2026-19478 | critical | GitLab Critical GraphQL Flaw Actively Exploited | 2d ago |
| CVE-2026-73570 | critical | Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw | 2d ago |
| CVE-2026-19490 | critical | Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) | 2d ago |
| CVE-2026-12569 | critical | Cl0p Targets 40+ Organizations Through PTC Windchill Flaw | 2d ago |
| CVE-2026-19478 | critical | GitLab Code Injection Vulnerability Actively Exploited | 2d ago |
| CVE-2026-69836 | high | Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution | 2d ago |
| CVE-2026-73570 | | Hackers Target Zimbra Servers in Active Exploitation Campaign | 3d ago |
| CVE-2026-69414 | | CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days | 3d ago |
| CVE-2026-19489 | critical | Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers | 3d ago |
| CVE-2026-73570 | critical | Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution | 3d ago |
| CVE-2026-14456 | high | CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification | 3d ago |
| CVE-2026-64849 | critical | U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog | 3d ago |
| CVE-2026-19478 | critical | Critical GitLab Flaw Exploited Shortly After Disclosure | 3d ago |
| CVE-2026-32475 | critical | Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code | 3d ago |
| CVE-2024-39943 | high | Operation CameraSwarm Compromised 14,000+ Dahua Cameras | 4d ago |
| CVE-2026-19490 | critical | CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway | 4d ago |
| CVE-2021-33044 | high | Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P | 4d ago |
| CVE-2026-65400 | critical | Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation | 4d ago |
| CVE-2026-76034 | critical | Critical Chrome Update Fixes Two Buffer Overflow Vulnerabilities | 4d ago |
| CVE-2026-33824 | | U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog | 4d ago |
| CVE-2026-68820 | high | CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now | 5d ago |
| CVE-2026-19478 | critical | Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) | 5d ago |
| CVE-2026-19478 | critical | Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects | 6d ago |
| CVE-2026-15748 | critical | Forminator WordPress Plugin Vulnerable to Remote Code Execution | 6d ago |
| CVE-2026-68820 | high | 17th August – Threat Intelligence Report | 6d ago |
| CVE-2026-69414 | high | ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw | 6d ago |
| CVE-2026-15826 | critical | WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover | 6d ago |
| CVE-2026-58231 | critical | Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure | 6d ago |
| CVE-2026-58231 | high | Crooks Buy Expired Domains for Malware Delivery, Other Threats Detailed | 7d ago |
| CVE-2026-58231 | critical | SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild | 8d ago |
| CVE-2026-65400 | critical | macOS Screen Sharing Flaw Exploited to Deploy Monero Miners | 8d ago |
| CVE-2025-3248 | | The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure | 8d ago |
| CVE-2026-46300 | high | Metasploit Wrap Up: Lot of summer shells and fit http profiles | 9d ago |
| CVE-2026-71362 | critical | Critical Adobe Commerce Flaw Exploited After Disclosure | 10d ago |
| CVE-2026-20349 | | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | 10d ago |
| CVE-2026-20349 | critical | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | 10d ago |
| CVE-2026-59310 | critical | Critical VMware vCenter RCE flaw exploited for reverse SSH access | 10d ago |
| CVE-2026-71362 | | Adobe Commerce Bug Targeted Immediately After Disclosure | 10d ago |
| CVE-2026-55040 | critical | Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) | 10d ago |
| CVE-2026-55040 | critical | SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit | 10d ago |
| CVE-2026-20349 | high | Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) | 10d ago |
| CVE-2026-55040 | critical | Attackers Exploit SharePoint Authentication Bypass After Public PoC Release | 10d ago |
| CVE-2026-20147 | high | Cisco Identity Services Engine Vulnerable to Command Injection | 10d ago |
| CVE-2026-4890 | high | Dnsmasq DNSSEC Vulnerability Leads to Denial-of-Service | 10d ago |
| CVE-2026-20215 | high | ClamAV Vulnerability Allows Remote Code Execution | 10d ago |
| CVE-2026-20148 | medium | Cisco Identity Services Engine Vulnerability Discloses Sensitive Information | 10d ago |
| CVE-2026-20181 | high | Cisco Identity Services Engine Vulnerable to RCE via Directory Traversal | 10d ago |
| CVE-2026-20190 | high | Cisco Identity Services Engine Leaks Information Due to Missing Authentication | 10d ago |
| CVE-2026-71362 | critical | Hackers exploit critical Adobe Commerce flaw to hijack customer accounts | 11d ago |
| CVE-2026-68820 | high | Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor | 11d ago |
| CVE-2026-68820 | | Lazarus hackers exploited Windows zero-day to target defense firms | 11d ago |
| CVE-2026-20349 | | Cisco Patches Firewall Zero-Day Exploited for DoS Attacks | 11d ago |
| CVE-2026-68820 | | Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack | 12d ago |
| CVE-2026-18577 | | N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 | 13d ago |
| CVE-2026-8037 | critical | CISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog | 15d ago |
| CVE-2023-38646 | critical | Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication | 15d ago |
| CVE-2026-18577 | high | N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist | 15d ago |
| CVE-2026-8037 | critical | Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts | 15d ago |
| CVE-2026-63077 | critical | Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) | 16d ago |
| CVE-2026-64638 | high | New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP | 16d ago |
| CVE-2021-44228 | high | Growing Up The Hard Way | 16d ago |
| CVE-2026-64564 | high | 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers | 16d ago |
| CVE-2026-63078 | high | AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day | 16d ago |
| CVE-2026-12537 | critical | Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets | 16d ago |
| CVE-2008-4128 | high | July 2026 CVE Landscape | 17d ago |
| CVE-2017-16740 | high | Thousands of US water system controllers remain exposed online | 17d ago |
| CVE-2026-64561 | | New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts | 17d ago |
| CVE-2026-63077 | critical | Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability | 17d ago |
| CVE-2026-68742 | medium | Indian Cybersecurity Firm Uses Homegrown AI to Discover Three Security Flaws in Enterprise Linux | 18d ago |
| CVE-2026-18577 | | N-able warns of N-central auth bypass flaw exploited in attacks | 20d ago |
| CVE-2026-66066 | critical | KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) | 20d ago |
| CVE-2026-48449 | critical | Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic | 22d ago |
| CVE-2026-48449 | | Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction | 22d ago |
| CVE-2026-33017 | high | Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits | 23d ago |
| CVE-2026-8233 | high | Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw | 23d ago |
| CVE-2025-66376 | high | Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes | 31d ago |
| CVE-2026-16232 | high | New Check Point Zero-Day Vulnerability Exploited in the Wild | 31d ago |
| CVE-2026-8933 | high | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | 32d ago |
| CVE-2026-48294 | | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | 32d ago |
| CVE-2026-64600 | | RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) | 32d ago |
| CVE-2026-50522 | critical | Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) | 32d ago |
| CVE-2026-50522 | critical | Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522 | 33d ago |
| CVE-2026-50522 | critical | Critical SharePoint RCE flaw exploited to steal machine keys | 33d ago |
| CVE-2026-0257 | high | Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access | 33d ago |
| CVE-2026-60137 | | 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover | 34d ago |
| CVE-2026-42533 | critical | Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution | 35d ago |
| CVE-2026-15409 | critical | SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access | 35d ago |
| CVE-2026-63030 | critical | Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits | 35d ago |
| CVE-2026-60137 | high | Two High-Severity WordPress Vulnerabilities Require Immediate Patching | 36d ago |
| CVE-2026-25089 | critical | CISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List | 36d ago |
| CVE-2026-63030 | critical | Critical RCE Vulnerability in WordPress Core Affects Millions of Sites | 37d ago |
| CVE-2026-60137 | critical | Cloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws | 37d ago |
| CVE-2026-58644 | critical | Microsoft SharePoint Server RCE Vulnerability Exploited in the Wild | 37d ago |
| CVE-2026-28739 | high | Multiple Vulnerabilities Found in WolfSSL, GeoVision, and VTK-DICOM | 45d ago |
| CVE-2026-11405 | critical | Tenda Firmware Vulnerability Allows Unauthenticated Admin Access | 45d ago |
| CVE-2026-50746 | critical | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | 46d ago |
| CVE-2026-24858 | high | FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices | 46d ago |
| CVE-2026-55255 | critical | Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) | 46d ago |
| CVE-2026-12958 | high | Bug in top AI coding agents shows that Unix-era security headaches never really die | 46d ago |
| CVE-2026-48282 | critical | U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog | 46d ago |
| CVE-2026-43499 | critical | 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros | 46d ago |
| CVE-2026-48282 | high | CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV | 46d ago |
| CVE-2026-20896 | critical | Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets | 47d ago |
| CVE-2026-20896 | critical | Critical Gitea Flaw Under Active Exploitation, Researchers Warn | 47d ago |
| CVE-2026-48282 | critical | Critical Adobe ColdFusion Vulnerability Exploited in Attacks | 47d ago |
| CVE-2024-42009 | high | Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities | 47d ago |
| CVE-2024-42009 | high | Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities | 47d ago |
| CVE-2026-11405 | high | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware | 47d ago |
| CVE-2026-40138 | critical | BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA | 47d ago |
| CVE-2026-53359 | | 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems | 48d ago |
| CVE-2026-20896 | critical | Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure | 48d ago |
| CVE-2025-3248 | critical | Sysdig clocks first documented case of agentic ransomware | 48d ago |
| CVE-2026-46817 | high | Ransomware Attacks Hit Financial, Defense, and Manufacturing Firms | 48d ago |
| CVE-2026-46242 | | New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android | 51d ago |
| CVE-2025-5777 | | Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials | 52d ago |
| CVE-2026-20245 | high | Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches | 53d ago |
| CVE-2026-48558 | critical | 'Djinn' Stealer Targets Cloud, AI Credentials | 55d ago |
| CVE-2026-20245 | high | 29th June – Threat Intelligence Report | 55d ago |
| CVE-2024-21762 | high | AI Creates 457 Million Security Issues for Organizations | 60d ago |
| CVE-2026-35273 | critical | Oracle Releases June Patch Update Addressing 243 Vulnerabilities | 66d ago |
| CVE-2025-54957 | critical | A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens | 102d ago |
| CVE-2025-55182 | high | EtherRat and TukTuk Malware Campaigns Lead to The Gentleman Ransomware | 104d ago |
| CVE-2025-29927 | high | Cloud Worm PCPJack Steals Credentials and Evicts TeamPCP Artifacts | 108d ago |
| CVE-2024-27227 | high | Bringing Rust to the Pixel Baseband | 135d ago |
| CVE-2026-33538 | high | CVE-2026-33538: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 152d ago |
| CVE-2026-33527 | medium | CVE-2026-33527: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 152d ago |
| CVE-2026-33508 | high | CVE-2026-33508: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 152d ago |
| CVE-2026-33498 | high | CVE-2026-33498: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 152d ago |
| CVE-2026-33429 | medium | CVE-2026-33429: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 152d ago |
| CVE-2026-33421 | medium | CVE-2026-33421: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 152d ago |
| CVE-2026-33417 | medium | CVE-2026-33417: Wallos is an open-source, self-hostable personal subscription tracker. | 152d ago |
| CVE-2026-33409 | critical | CVE-2026-33409: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 152d ago |
| CVE-2026-33323 | medium | CVE-2026-33323: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 152d ago |
| CVE-2026-30932 | high | CVE-2026-30932: Froxlor is open source server administration software. | 152d ago |
| CVE-2026-2417 | | CVE-2026-2417: A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware ver | 152d ago |
| CVE-2026-29772 | medium | CVE-2026-29772: Astro is a web framework. | 152d ago |
| CVE-2026-23924 | | CVE-2026-23924: Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding the | 152d ago |
| CVE-2026-23923 | | CVE-2026-23923: An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classe | 152d ago |
| CVE-2026-23921 | | CVE-2026-23921: A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api | 152d ago |
| CVE-2026-23920 | | CVE-2026-23920: Host and event action script input is validated with a regex (set by the administrator), but the validation runs i | 152d ago |
| CVE-2026-23919 | | CVE-2026-23919: For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript | 152d ago |
| CVE-2026-1995 | high | CVE-2026-1995: IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\P | 152d ago |
| CVE-2026-33407 | critical | CVE-2026-33407: Wallos is an open-source, self-hostable personal subscription tracker. | 152d ago |
| CVE-2026-33401 | medium | CVE-2026-33401: Wallos is an open-source, self-hostable personal subscription tracker. | 152d ago |
| CVE-2026-33400 | medium | CVE-2026-33400: Wallos is an open-source, self-hostable personal subscription tracker. | 152d ago |
| CVE-2026-33399 | high | CVE-2026-33399: Wallos is an open-source, self-hostable personal subscription tracker. | 152d ago |
| CVE-2026-33162 | medium | CVE-2026-33162: Craft CMS is a content management system (CMS). | 152d ago |
| CVE-2026-33161 | medium | CVE-2026-33161: Craft CMS is a content management system (CMS). | 152d ago |
| CVE-2026-33160 | medium | CVE-2026-33160: Craft CMS is a content management system (CMS). | 152d ago |
| CVE-2026-33159 | medium | CVE-2026-33159: Craft CMS is a content management system (CMS). | 152d ago |
| CVE-2026-33158 | medium | CVE-2026-33158: Craft CMS is a content management system (CMS). | 152d ago |
| CVE-2026-33157 | high | CVE-2026-33157: Craft CMS is a content management system (CMS). | 152d ago |
| CVE-2026-32854 | high | CVE-2026-32854: LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities | 152d ago |
| CVE-2026-32853 | high | CVE-2026-32853: LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability i | 152d ago |
| CVE-2026-26809 | | CVE-2026-26809: Rejected reason: DO NOT USE THIS CVE RECORD. | 152d ago |
| CVE-2026-33340 | critical | CVE-2026-33340: LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. | 152d ago |
| CVE-2025-11571 | | CVE-2025-11571: Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. | 152d ago |
| CVE-2026-33700 | medium | CVE-2026-33700: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33680 | high | CVE-2026-33680: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33679 | medium | CVE-2026-33679: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33678 | high | CVE-2026-33678: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33677 | medium | CVE-2026-33677: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33676 | medium | CVE-2026-33676: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33675 | medium | CVE-2026-33675: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33668 | high | CVE-2026-33668: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33474 | medium | CVE-2026-33474: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33473 | medium | CVE-2026-33473: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33336 | high | CVE-2026-33336: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33335 | high | CVE-2026-33335: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33334 | critical | CVE-2026-33334: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-29840 | medium | CVE-2026-29840: JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function with | 152d ago |
| CVE-2026-29839 | high | CVE-2026-29839: DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php. | 152d ago |
| CVE-2025-71275 | | CVE-2025-71275: Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519. | 152d ago |
| CVE-2026-4775 | high | CVE-2026-4775: A flaw was found in the libtiff library. | 152d ago |
| CVE-2026-33554 | high | CVE-2026-33554: ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. | 152d ago |
| CVE-2026-33316 | high | CVE-2026-33316: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33315 | medium | CVE-2026-33315: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-33313 | medium | CVE-2026-33313: Vikunja is an open-source self-hosted task management platform. | 152d ago |
| CVE-2026-32647 | high | CVE-2026-32647: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an atta | 152d ago |
| CVE-2026-30662 | medium | CVE-2026-30662: ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. | 152d ago |
| CVE-2026-30661 | medium | CVE-2026-30661: iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically wit | 152d ago |
| CVE-2026-30655 | medium | CVE-2026-30655: SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remot | 152d ago |
| CVE-2026-30653 | high | CVE-2026-30653: An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function Hand | 152d ago |
| CVE-2026-28755 | medium | CVE-2026-28755: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper hand | 152d ago |
| CVE-2026-28753 | low | CVE-2026-28753: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handl | 152d ago |
| CVE-2026-27784 | high | CVE-2026-27784: The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might | 152d ago |
| CVE-2026-27654 | high | CVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attack | 152d ago |
| CVE-2026-27651 | high | CVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can | 152d ago |
| CVE-2026-33497 | high | CVE-2026-33497: Langflow is a tool for building and deploying AI-powered agents and workflows. | 152d ago |
| CVE-2026-33484 | high | CVE-2026-33484: Langflow is a tool for building and deploying AI-powered agents and workflows. | 152d ago |
| CVE-2026-33418 | high | CVE-2026-33418: DiceBear is an avatar library for designers and developers. | 152d ago |
| CVE-2026-33311 | medium | CVE-2026-33311: DiceBear is an avatar library for designers and developers. | 152d ago |
| CVE-2026-33310 | high | CVE-2026-33310: Intake is a package for finding, investigating, loading and disseminating data. | 152d ago |
| CVE-2026-4729 | critical | CVE-2026-4729: Memory safety bugs present in Firefox 148 and Thunderbird 148. | 152d ago |
| CVE-2026-4728 | medium | CVE-2026-4728: Spoofing issue in the Privacy: Anti-Tracking component. | 152d ago |
| CVE-2026-4727 | high | CVE-2026-4727: Denial-of-service in the Libraries component in NSS. | 152d ago |
| CVE-2026-4726 | high | CVE-2026-4726: Denial-of-service in the XML component. | 152d ago |
| CVE-2026-4725 | critical | CVE-2026-4725: Sandbox escape due to use-after-free in the Graphics: Canvas2D component. | 152d ago |
| CVE-2026-4724 | critical | CVE-2026-4724: Undefined behavior in the Audio/Video component. | 152d ago |
| CVE-2026-4723 | critical | CVE-2026-4723: Use-after-free in the JavaScript Engine component. | 152d ago |
| CVE-2026-4722 | high | CVE-2026-4722: Privilege escalation in the IPC component. | 152d ago |
| CVE-2026-4721 | critical | CVE-2026-4721: Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunder | 152d ago |
| CVE-2026-4720 | critical | CVE-2026-4720: Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. | 152d ago |
| CVE-2026-4719 | high | CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component. | 152d ago |
| CVE-2026-4718 | high | CVE-2026-4718: Undefined behavior in the WebRTC: Signaling component. | 152d ago |
| CVE-2026-4717 | critical | CVE-2026-4717: Privilege escalation in the Netmonitor component. | 152d ago |
| CVE-2026-4716 | critical | CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. | 152d ago |
| CVE-2026-4715 | critical | CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component. | 152d ago |
| CVE-2026-4714 | high | CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component. | 152d ago |
| CVE-2026-4713 | high | CVE-2026-4713: Incorrect boundary conditions in the Graphics component. | 152d ago |
| CVE-2026-4712 | high | CVE-2026-4712: Information disclosure in the Widget: Cocoa component. | 152d ago |
| CVE-2026-4711 | critical | CVE-2026-4711: Use-after-free in the Widget: Cocoa component. | 152d ago |
| CVE-2026-4710 | critical | CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component. | 152d ago |
| CVE-2026-4709 | high | CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component. | 152d ago |
| CVE-2026-4708 | high | CVE-2026-4708: Incorrect boundary conditions in the Graphics component. | 152d ago |
| CVE-2026-4707 | high | CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component. | 152d ago |
| CVE-2026-4706 | high | CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component. | 152d ago |
| CVE-2026-4705 | critical | CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component. | 152d ago |
| CVE-2026-4704 | high | CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component. | 152d ago |
| CVE-2026-4702 | critical | CVE-2026-4702: JIT miscompilation in the JavaScript Engine component. | 152d ago |
| CVE-2026-4701 | critical | CVE-2026-4701: Use-after-free in the JavaScript Engine component. | 152d ago |
| CVE-2026-4700 | critical | CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. | 152d ago |
| CVE-2026-4699 | high | CVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component. | 152d ago |
| CVE-2026-4698 | critical | CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. | 152d ago |
| CVE-2026-4697 | high | CVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component. | 152d ago |
| CVE-2026-4696 | critical | CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. | 152d ago |
| CVE-2026-4695 | high | CVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component. | 152d ago |
| CVE-2026-4694 | high | CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component. | 152d ago |
| CVE-2026-4693 | high | CVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component. | 152d ago |
| CVE-2026-4692 | critical | CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. | 152d ago |
| CVE-2026-4691 | critical | CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. | 152d ago |
| CVE-2026-4690 | high | CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. | 152d ago |
| CVE-2026-4689 | critical | CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. | 152d ago |
| CVE-2026-4688 | critical | CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. | 152d ago |
| CVE-2026-4687 | high | CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component. | 152d ago |
| CVE-2026-4686 | high | CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component. | 152d ago |
| CVE-2026-4685 | high | CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component. | 152d ago |
| CVE-2026-4684 | high | CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component. | 152d ago |
| CVE-2026-33475 | critical | CVE-2026-33475: Langflow is a tool for building and deploying AI-powered agents and workflows. | 152d ago |
| CVE-2026-33309 | critical | CVE-2026-33309: Langflow is a tool for building and deploying AI-powered agents and workflows. | 152d ago |
| CVE-2025-64998 | high | CVE-2025-64998: Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote s | 152d ago |
| CVE-2019-25647 | high | CVE-2019-25647: PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated | 152d ago |
| CVE-2019-25646 | critical | CVE-2019-25646: Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote | 152d ago |
| CVE-2019-25645 | medium | CVE-2019-25645: WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to | 152d ago |
| CVE-2019-25644 | medium | CVE-2019-25644: WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog t | 152d ago |
| CVE-2019-25643 | high | CVE-2019-25643: eNdonesia Portal v8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to exec | 152d ago |
| CVE-2019-25642 | high | CVE-2019-25642: Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb | 152d ago |
| CVE-2019-25641 | high | CVE-2019-25641: Netartmedia Vlog System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulat | 152d ago |
| CVE-2019-25640 | high | CVE-2019-25640: Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate d | 152d ago |
| CVE-2019-25639 | high | CVE-2019-25639: Matrimony Website Script M-Plus contains multiple SQL injection vulnerabilities that allow unauthenticated attacke | 152d ago |
| CVE-2019-25638 | high | CVE-2019-25638: Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to e | 152d ago |
| CVE-2019-25637 | high | CVE-2019-25637: X-NetStat Pro 5.63 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary | 152d ago |
| CVE-2019-25636 | high | CVE-2019-25636: Zeeways Jobsite CMS contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da | 152d ago |
| CVE-2019-25635 | high | CVE-2019-25635: Zeeways Matrimony CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to mani | 152d ago |
| CVE-2019-25634 | high | CVE-2019-25634: Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute a | 152d ago |
| CVE-2019-25633 | high | CVE-2019-25633: AIDA64 Extreme 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local | 152d ago |
| CVE-2019-25632 | medium | CVE-2019-25632: phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read a | 152d ago |
| CVE-2019-25631 | high | CVE-2019-25631: AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local | 152d ago |
| CVE-2019-25630 | high | CVE-2019-25630: PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows au | 152d ago |
| CVE-2019-25629 | high | CVE-2019-25629: AIDA64 Extreme 5.99.4900 contains a structured exception handler buffer overflow vulnerability in the logging func | 152d ago |
| CVE-2019-25628 | critical | CVE-2019-25628: Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that | 152d ago |
| CVE-2019-25627 | high | CVE-2019-25627: FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers t | 152d ago |
| CVE-2019-25626 | high | CVE-2019-25626: River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that all | 152d ago |
| CVE-2026-4649 | | CVE-2026-4649: Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages | 152d ago |
| CVE-2026-3509 | high | CVE-2026-3509: An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log | 152d ago |
| CVE-2026-32642 | medium | CVE-2026-32642: Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an applicat | 152d ago |
| CVE-2025-41660 | high | CVE-2025-41660: A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system | 152d ago |
| CVE-2026-4756 | high | CVE-2026-4756: Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: be | 152d ago |
| CVE-2026-4755 | critical | CVE-2026-4755: CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11 | 152d ago |
| CVE-2026-4754 | medium | CVE-2026-4754: CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11 | 152d ago |
| CVE-2026-33852 | high | CVE-2026-33852: Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue | 152d ago |
| CVE-2026-4753 | critical | CVE-2026-4753: Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72. | 152d ago |
| CVE-2026-4752 | medium | CVE-2026-4752: Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329. | 152d ago |
| CVE-2026-4751 | medium | CVE-2026-4751: NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0. | 152d ago |
| CVE-2026-4750 | critical | CVE-2026-4750: Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0. | 152d ago |
| CVE-2026-4749 | medium | CVE-2026-4749: NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0. | 152d ago |
| CVE-2026-33856 | high | CVE-2026-33856: Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue | 152d ago |
| CVE-2026-33855 | medium | CVE-2026-33855: Integer Overflow or Wraparound vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-Imag | 152d ago |
| CVE-2026-33854 | high | CVE-2026-33854: Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: b | 152d ago |
| CVE-2026-33853 | medium | CVE-2026-33853: NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagic | 152d ago |
| CVE-2026-33851 | high | CVE-2026-33851: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in joncampbell123 doslib.Thi | 152d ago |
| CVE-2026-33850 | high | CVE-2026-33850: Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54. | 152d ago |
| CVE-2026-33849 | high | CVE-2026-33849: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.Th | 152d ago |
| CVE-2026-33848 | high | CVE-2026-33848: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.Th | 152d ago |
| CVE-2026-33847 | high | CVE-2026-33847: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.Th | 152d ago |
| CVE-2026-4746 | | CVE-2026-4746: Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). | 152d ago |
| CVE-2026-4745 | | CVE-2026-4745: Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua | 152d ago |
| CVE-2026-4662 | high | CVE-2026-4662: The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all ve | 152d ago |
| CVE-2026-4640 | high | CVE-2026-4640: Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticat | 152d ago |
| CVE-2026-4639 | high | CVE-2026-4639: Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticate | 152d ago |
| CVE-2026-4632 | high | CVE-2026-4632: A weakness has been identified in itsourcecode Online Enrollment System 1.0. | 152d ago |
| CVE-2026-4627 | high | CVE-2026-4627: A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. | 152d ago |
| CVE-2026-4283 | critical | CVE-2026-4283: The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up | 152d ago |
| CVE-2026-3260 | | CVE-2026-3260: Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. | 152d ago |
| CVE-2026-3138 | medium | CVE-2026-3138: The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a mis | 152d ago |
| CVE-2026-4744 | | CVE-2026-4744: Out-of-bounds Read vulnerability in rizonesoft Notepad3 (scintilla/oniguruma/src modules). | 152d ago |
| CVE-2026-4743 | | CVE-2026-4743: NULL Pointer Dereference vulnerability in taurusxin ncmdump (src/utils modules). | 152d ago |
| CVE-2026-4742 | | CVE-2026-4742: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in visualfc liteide | 152d ago |
| CVE-2026-4741 | | CVE-2026-4741: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid | 152d ago |
| CVE-2026-4739 | | CVE-2026-4739: Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (Modules/ThirdParty/Expat/src/expat | 152d ago |
| CVE-2026-4738 | | CVE-2026-4738: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/con | 152d ago |
| CVE-2026-4737 | | CVE-2026-4737: Use After Free vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). | 152d ago |
| CVE-2026-4736 | | CVE-2026-4736: Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/ | 152d ago |
| CVE-2026-4735 | | CVE-2026-4735: Deserialization of Untrusted Data vulnerability in DTStack chunjun (chunjun-core/src/main/java/com/dtstack/chunjun | 152d ago |
| CVE-2026-4734 | | CVE-2026-4734: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libop | 152d ago |
| CVE-2026-4733 | medium | CVE-2026-4733: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue a | 152d ago |
| CVE-2026-4732 | | CVE-2026-4732: Out-of-bounds Read vulnerability in tildearrow furnace (extern/libsndfile-modified/src modules). | 152d ago |
| CVE-2026-4731 | | CVE-2026-4731: Integer Overflow or Wraparound vulnerability in artraweditor ART (rtengine modules). | 152d ago |
| CVE-2026-4626 | low | CVE-2026-4626: A vulnerability has been found in projectworlds Lawyer Management System 1.0. | 152d ago |
| CVE-2026-4625 | high | CVE-2026-4625: A flaw has been found in SourceCodester Online Admission System 1.0. | 152d ago |
| CVE-2026-4624 | high | CVE-2026-4624: A vulnerability was detected in SourceCodester Online Library Management System 1.0. | 152d ago |
| CVE-2026-4623 | high | CVE-2026-4623: A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b | 152d ago |
| CVE-2026-33308 | medium | CVE-2026-33308: Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. | 152d ago |
| CVE-2026-3079 | medium | CVE-2026-3079: The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_ord | 152d ago |
| CVE-2026-33307 | high | CVE-2026-33307: Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. | 152d ago |
| CVE-2026-4680 | high | CVE-2026-4680: Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary cod | 153d ago |
| CVE-2026-4679 | high | CVE-2026-4679: Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of b | 153d ago |
| CVE-2026-4678 | high | CVE-2026-4678: Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary co | 153d ago |
| CVE-2026-4677 | high | CVE-2026-4677: Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perf | 153d ago |
| CVE-2026-4676 | high | CVE-2026-4676: Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a | 153d ago |
| CVE-2026-4675 | high | CVE-2026-4675: Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out | 153d ago |
| CVE-2026-4674 | high | CVE-2026-4674: Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of boun | 153d ago |
| CVE-2026-4673 | high | CVE-2026-4673: Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an o | 153d ago |
| CVE-2026-4617 | high | CVE-2026-4617: A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. | 153d ago |
| CVE-2026-4616 | low | CVE-2026-4616: A security flaw has been discovered in bolo-blog up to 2.6.4. | 153d ago |
| CVE-2026-33320 | medium | CVE-2026-33320: Dasel is a command-line tool and library for querying, modifying, and transforming data structures. | 153d ago |
| CVE-2026-33306 | high | CVE-2026-33306: bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. | 153d ago |
| CVE-2026-33298 | high | CVE-2026-33298: llama.cpp is an inference of several LLM models in C/C++. | 153d ago |
| CVE-2026-33290 | medium | CVE-2026-33290: WPGraphQL provides a GraphQL API for WordPress sites. | 153d ago |
| CVE-2026-22739 | high | CVE-2026-22739: Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Conf | 153d ago |
| CVE-2026-4615 | high | CVE-2026-4615: A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. | 153d ago |
| CVE-2026-4614 | medium | CVE-2026-4614: A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. | 153d ago |
| CVE-2026-4613 | high | CVE-2026-4613: A vulnerability was found in SourceCodester E-Commerce Site 1.0. | 153d ago |
| CVE-2026-4056 | medium | CVE-2026-4056: The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a | 153d ago |
| CVE-2026-4021 | high | CVE-2026-4021: The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeove | 153d ago |
| CVE-2026-4001 | critical | CVE-2026-4001: The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versio | 153d ago |
| CVE-2026-3533 | high | CVE-2026-3533: The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on impor | 153d ago |
| CVE-2026-33286 | critical | CVE-2026-33286: Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. | 153d ago |
| CVE-2026-33283 | medium | CVE-2026-33283: Ella Core is a 5G core designed for private networks. | 153d ago |
| CVE-2026-33282 | high | CVE-2026-33282: Ella Core is a 5G core designed for private networks. | 153d ago |
| CVE-2026-33281 | medium | CVE-2026-33281: Ella Core is a 5G core designed for private networks. | 153d ago |
| CVE-2026-33252 | high | CVE-2026-33252: The Go MCP SDK used Go's standard encoding/json. | 153d ago |
| CVE-2026-33250 | high | CVE-2026-33250: Freeciv21 is a free open source, turn-based, empire-building strategy game. | 153d ago |
| CVE-2026-33242 | high | CVE-2026-33242: Salvo is a Rust web framework. | 153d ago |
| CVE-2026-33241 | high | CVE-2026-33241: Salvo is a Rust web framework. | 153d ago |
| CVE-2026-33211 | critical | CVE-2026-33211: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. | 153d ago |
| CVE-2026-33202 | critical | CVE-2026-33202: Active Storage allows users to attach cloud and local files in Rails applications. | 153d ago |
| CVE-2026-33195 | critical | CVE-2026-33195: Active Storage allows users to attach cloud and local files in Rails applications. | 153d ago |
| CVE-2026-33176 | high | CVE-2026-33176: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. | 153d ago |
| CVE-2026-33174 | high | CVE-2026-33174: Active Storage allows users to attach cloud and local files in Rails applications. | 153d ago |
| CVE-2026-33173 | medium | CVE-2026-33173: Active Storage allows users to attach cloud and local files in Rails applications. | 153d ago |
| CVE-2026-33170 | medium | CVE-2026-33170: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. | 153d ago |
| CVE-2026-33169 | medium | CVE-2026-33169: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. | 153d ago |
| CVE-2026-4306 | high | CVE-2026-4306: The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up | 153d ago |
| CVE-2026-4066 | medium | CVE-2026-4066: The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili | 153d ago |
| CVE-2026-3225 | medium | CVE-2026-3225: The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question | 153d ago |
| CVE-2026-33168 | | CVE-2026-33168: Action View provides conventions and helpers for building web pages with the Rails framework. | 153d ago |
| CVE-2026-33167 | | CVE-2026-33167: Action Pack is a Rubygem for building web applications on the Rails framework. | 153d ago |
| CVE-2026-33046 | high | CVE-2026-33046: Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. | 153d ago |
| CVE-2026-2412 | medium | CVE-2026-2412: The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' para | 153d ago |
| CVE-2026-4681 | | CVE-2026-4681: A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. | 153d ago |
| CVE-2026-4612 | high | CVE-2026-4612: A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. | 153d ago |
| CVE-2026-4611 | high | CVE-2026-4611: A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. | 153d ago |
| CVE-2026-33634 | high | CVE-2026-33634: Trivy is a security scanner. | 153d ago |
| CVE-2026-32913 | critical | CVE-2026-32913: OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards | 153d ago |
| CVE-2026-32912 | | CVE-2026-32912: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32911 | | CVE-2026-32911: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32910 | | CVE-2026-32910: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32909 | | CVE-2026-32909: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32908 | | CVE-2026-32908: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32907 | | CVE-2026-32907: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32904 | | CVE-2026-32904: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32903 | | CVE-2026-32903: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32902 | | CVE-2026-32902: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32901 | | CVE-2026-32901: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32900 | | CVE-2026-32900: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32300 | high | CVE-2026-32300: Connect-CMS is a content management system. | 153d ago |
| CVE-2026-32299 | high | CVE-2026-32299: Connect-CMS is a content management system. | 153d ago |
| CVE-2026-32279 | medium | CVE-2026-32279: Connect-CMS is a content management system. | 153d ago |
| CVE-2026-32278 | high | CVE-2026-32278: Connect-CMS is a content management system. | 153d ago |
| CVE-2026-32277 | high | CVE-2026-32277: Connect-CMS is a content management system. | 153d ago |
| CVE-2026-32276 | high | CVE-2026-32276: Connect-CMS is a content management system. | 153d ago |
| CVE-2026-32066 | | CVE-2026-32066: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32047 | | CVE-2026-32047: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-32012 | | CVE-2026-32012: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-29111 | medium | CVE-2026-29111: systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC AP | 153d ago |
| CVE-2026-28483 | | CVE-2026-28483: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-28455 | | CVE-2026-28455: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-27646 | medium | CVE-2026-27646: OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows a | 153d ago |
| CVE-2026-27183 | medium | CVE-2026-27183: OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wr | 153d ago |
| CVE-2026-22173 | | CVE-2026-22173: Rejected reason: This CVE ID has been rejected. | 153d ago |
| CVE-2026-1940 | medium | CVE-2026-1940: An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. | 153d ago |
| CVE-2025-60949 | critical | CVE-2025-60949: Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. | 153d ago |
| CVE-2025-60948 | medium | CVE-2025-60948: Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. | 153d ago |
| CVE-2025-60947 | high | CVE-2025-60947: Census CSWeb 8.0.1 allows arbitrary file upload. | 153d ago |
| CVE-2025-60946 | high | CVE-2025-60946: Census CSWeb 8.0.1 allows arbitrary file path input. | 153d ago |
| CVE-2026-4597 | medium | CVE-2026-4597: A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. | 153d ago |
| CVE-2026-4368 | | CVE-2026-4368: Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, | 153d ago |
| CVE-2026-3055 | critical | CVE-2026-3055: Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memor | 153d ago |
| CVE-2026-23882 | high | CVE-2026-23882: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23488 | medium | CVE-2026-23488: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23487 | medium | CVE-2026-23487: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23486 | medium | CVE-2026-23486: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23485 | medium | CVE-2026-23485: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23484 | medium | CVE-2026-23484: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23483 | medium | CVE-2026-23483: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23482 | high | CVE-2026-23482: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23481 | medium | CVE-2026-23481: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-23480 | high | CVE-2026-23480: Blinko is an AI-powered card note-taking project. | 153d ago |
| CVE-2026-4596 | low | CVE-2026-4596: A vulnerability was identified in projectworlds Lawyer Management System 1.0. | 153d ago |
| CVE-2026-33548 | medium | CVE-2026-33548: Mantis Bug Tracker (MantisBT) is an open source issue tracker. | 153d ago |
| CVE-2026-33517 | medium | CVE-2026-33517: Mantis Bug Tracker (MantisBT) is an open source issue tracker. | 153d ago |
| CVE-2026-32879 | medium | CVE-2026-32879: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. | 153d ago |
| CVE-2026-32852 | medium | CVE-2026-32852: MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface | 153d ago |
| CVE-2026-32851 | medium | CVE-2026-32851: MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface | 153d ago |
| CVE-2026-32850 | medium | CVE-2026-32850: MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface | 153d ago |
| CVE-2026-30886 | medium | CVE-2026-30886: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. | 153d ago |
| CVE-2026-30849 | critical | CVE-2026-30849: Mantis Bug Tracker (MantisBT) is an open source issue tracker. | 153d ago |
| CVE-2026-2298 | critical | CVE-2026-2298: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Mark | 153d ago |
| CVE-2026-27131 | medium | CVE-2026-27131: The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. | 153d ago |
| CVE-2025-52204 | medium | CVE-2025-52204: A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCus | 153d ago |
| CVE-2024-46879 | medium | CVE-2024-46879: A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system. | 153d ago |
| CVE-2024-46878 | medium | CVE-2024-46878: A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 | 153d ago |
| CVE-2026-4595 | low | CVE-2026-4595: A vulnerability was determined in code-projects Exam Form Submission 1.0. | 153d ago |
| CVE-2026-33723 | high | CVE-2026-33723: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33719 | high | CVE-2026-33719: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33717 | high | CVE-2026-33717: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33716 | critical | CVE-2026-33716: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33690 | medium | CVE-2026-33690: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33688 | medium | CVE-2026-33688: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33685 | medium | CVE-2026-33685: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33683 | medium | CVE-2026-33683: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33681 | high | CVE-2026-33681: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33651 | high | CVE-2026-33651: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33650 | high | CVE-2026-33650: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33649 | high | CVE-2026-33649: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33648 | high | CVE-2026-33648: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33647 | high | CVE-2026-33647: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33513 | high | CVE-2026-33513: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33512 | high | CVE-2026-33512: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-26209 | high | CVE-2026-26209: cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. | 153d ago |
| CVE-2026-25075 | high | CVE-2026-25075: strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser tha | 153d ago |
| CVE-2026-0898 | | CVE-2026-0898: An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are | 153d ago |
| CVE-2025-15606 | high | CVE-2025-15606: A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input s | 153d ago |
| CVE-2026-4594 | high | CVE-2026-4594: A vulnerability has been found in erupts erupt up to 1.13.3. | 153d ago |
| CVE-2025-15605 | high | CVE-2025-15605: A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 e | 153d ago |
| CVE-2025-15519 | high | CVE-2025-15519: Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and | 153d ago |
| CVE-2025-15518 | high | CVE-2025-15518: Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and | 153d ago |
| CVE-2025-15517 | high | CVE-2025-15517: A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi e | 153d ago |
| CVE-2026-4593 | medium | CVE-2026-4593: A flaw has been found in erupts erupt bis 1.13.3. | 153d ago |
| CVE-2026-33507 | high | CVE-2026-33507: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33502 | critical | CVE-2026-33502: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33501 | medium | CVE-2026-33501: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33500 | medium | CVE-2026-33500: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33499 | medium | CVE-2026-33499: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-30007 | medium | CVE-2026-30007: XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file | 153d ago |
| CVE-2026-30006 | medium | CVE-2026-30006: XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file. | 153d ago |
| CVE-2026-26829 | high | CVE-2026-26829: A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allow | 153d ago |
| CVE-2026-26828 | high | CVE-2026-26828: A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652 | 153d ago |
| CVE-2026-24516 | high | CVE-2026-24516: A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. | 153d ago |
| CVE-2026-4592 | medium | CVE-2026-4592: A security vulnerability has been detected in kalcaddle kodbox 1.64. | 153d ago |
| CVE-2026-4591 | medium | CVE-2026-4591: A weakness has been identified in kalcaddle kodbox 1.64. | 153d ago |
| CVE-2026-33493 | high | CVE-2026-33493: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33492 | high | CVE-2026-33492: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33488 | high | CVE-2026-33488: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-32845 | high | CVE-2026-32845: cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when valid | 153d ago |
| CVE-2024-51226 | medium | CVE-2024-51226: A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle | 153d ago |
| CVE-2024-51225 | medium | CVE-2024-51225: A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Reco | 153d ago |
| CVE-2024-51224 | medium | CVE-2024-51224: Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle | 153d ago |
| CVE-2024-51223 | medium | CVE-2024-51223: A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record | 153d ago |
| CVE-2024-51222 | medium | CVE-2024-51222: A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record | 153d ago |
| CVE-2026-4590 | low | CVE-2026-4590: A security flaw has been discovered in kalcaddle kodbox 1.64. | 153d ago |
| CVE-2026-4404 | critical | CVE-2026-4404: Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default pass | 153d ago |
| CVE-2026-33485 | high | CVE-2026-33485: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33483 | high | CVE-2026-33483: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33482 | high | CVE-2026-33482: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33480 | high | CVE-2026-33480: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33479 | high | CVE-2026-33479: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33478 | critical | CVE-2026-33478: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33354 | high | CVE-2026-33354: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-4647 | medium | CVE-2026-4647: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object | 153d ago |
| CVE-2026-4645 | | CVE-2026-4645: Rejected reason: Duplicate of CVE-2026-32287 | 153d ago |
| CVE-2026-4589 | medium | CVE-2026-4589: A vulnerability was identified in kalcaddle kodbox 1.64. | 153d ago |
| CVE-2026-3635 | medium | CVE-2026-3635: Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0 | 153d ago |
| CVE-2026-33352 | critical | CVE-2026-33352: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33351 | critical | CVE-2026-33351: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2026-33297 | critical | CVE-2026-33297: WWBN AVideo is an open source video platform. | 153d ago |
| CVE-2025-41008 | | CVE-2025-41008: SQL injection vulnerability in Sinturno. | 153d ago |
| CVE-2019-25625 | medium | CVE-2019-25625: Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application b | 153d ago |
| CVE-2019-25624 | medium | CVE-2019-25624: Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application | 153d ago |
| CVE-2019-25623 | medium | CVE-2019-25623: Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the applicat | 153d ago |
| CVE-2019-25622 | medium | CVE-2019-25622: Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application | 153d ago |
| CVE-2019-25621 | medium | CVE-2019-25621: Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application | 153d ago |
| CVE-2019-25620 | medium | CVE-2019-25620: Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application b | 153d ago |
| CVE-2026-4588 | low | CVE-2026-4588: A vulnerability was determined in kalcaddle kodbox 1.64. | 153d ago |
| CVE-2026-4587 | low | CVE-2026-4587: A vulnerability was found in HybridAuth up to 3.12.2. | 153d ago |
| CVE-2026-4586 | medium | CVE-2026-4586: A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. | 153d ago |