| CVE-2026-31853 | 5.7 | — | — | — | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 178d ago |
| CVE-2026-4592 | 5.6 | — | — | — | — | A security vulnerability has been detected in kalcaddle kodbox 1.64. | 166d ago |
| CVE-2024-13785 | 5.6 | — | — | — | — | The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary | 169d ago |
| CVE-2026-4349 | 5.6 | — | — | — | — | A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. | 172d ago |
| CVE-2025-52638 | 5.6 | — | — | — | hcl / aion | HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges | 173d ago |
| CVE-2026-33855 | 5.5 | — | — | — | molotovcherry / android-imagemagick7 | Integer Overflow or Wraparound vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-Imag | 166d ago |
| CVE-2026-33853 | 5.5 | — | — | — | molotovcherry / android-imagemagick7 | NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagic | 166d ago |
| CVE-2026-29111 | 5.5 | — | — | — | systemd project / systemd | systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC AP | 166d ago |
| CVE-2026-27131 | 5.5 | — | — | — | — | The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. | 166d ago |
| CVE-2019-25606 | 5.5 | — | — | — | — | Fast AVI MPEG Joiner 1.2.0812 contains a buffer overflow vulnerability that allows local attackers to crash the ap | 167d ago |
| CVE-2019-25602 | 5.5 | — | — | — | — | GSearch 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by | 167d ago |
| CVE-2019-25593 | 5.5 | — | — | — | — | jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application | 167d ago |
| CVE-2019-25577 | 5.5 | — | — | — | seotoaster / seotoaster | SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to re | 168d ago |
| CVE-2019-25570 | 5.5 | — | — | — | crun / realterm | RealTerm Serial Terminal 2.0.0.70 contains a denial of service vulnerability that allows local attackers to crash | 168d ago |
| CVE-2019-25564 | 5.5 | — | — | — | uvnc / pchelpwarev2 | PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the applicati | 168d ago |
| CVE-2019-25562 | 5.5 | — | — | — | jetaudio / jetaudio | jetAudio 8.1.7 contains a buffer overflow vulnerability in the video converter component that allows local attacke | 168d ago |
| CVE-2019-25559 | 5.5 | — | — | — | nsasoft / spotpaltalk | SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows loca | 168d ago |
| CVE-2019-25554 | 5.5 | — | — | — | tomabo / mp4 converter | Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the a | 168d ago |
| CVE-2026-3347 | 5.5 | — | — | — | — | The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_ | 169d ago |
| CVE-2026-32044 | 5.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that | 169d ago |
| CVE-2026-33237 | 5.5 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 169d ago |
| CVE-2026-32810 | 5.5 | — | — | — | halloy / halloy | Halloy is an IRC application written in Rust. | 169d ago |
| CVE-2026-33179 | 5.5 | — | — | — | libfuse project / libfuse | libfuse is the reference implementation of the Linux FUSE. | 169d ago |
| CVE-2026-33165 | 5.5 | — | — | — | struktur / libde265 | libde265 is an open source implementation of the h.265 video codec. | 169d ago |
| CVE-2025-62844 | 5.5 | — | — | — | qnap / qurouter | A weak authentication vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2026-23277 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference | 169d ago |
| CVE-2026-23276 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: add xmit recursion limit to tunnel xmit f | 169d ago |
| CVE-2026-32024 | 5.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows atta | 170d ago |
| CVE-2026-3229 | 5.5 | — | — | — | wolfssl / wolfssl | An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption | 170d ago |
| CVE-2026-32869 | 5.5 | — | — | — | opexustech / ecase ecomplaint | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" f | 170d ago |
| CVE-2026-32868 | 5.5 | — | — | — | opexustech / ecase ecomplaint | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields i | 170d ago |
| CVE-2026-32866 | 5.5 | — | — | — | opexustech / ecase ecomplaint | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields i | 170d ago |
| CVE-2026-23267 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix IS_CHECKPOINTED flag inconsistency i | 171d ago |
| CVE-2026-23266 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fbdev: rivafb: fix divide error in nv3_arb() A | 171d ago |
| CVE-2026-23265 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node footer in | 171d ago |
| CVE-2026-23264 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd: Check if ASPM is enabled from | 171d ago |
| CVE-2026-23263 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix page array leak d9f595b9a65 | 171d ago |
| CVE-2026-23261 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: release admin tagset if init fails nv | 171d ago |
| CVE-2026-23260 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: regmap: maple: free entry on mas_store_gfp() f | 171d ago |
| CVE-2026-23259 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec | 171d ago |
| CVE-2026-23258 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Initialize netdev pointer befor | 171d ago |
| CVE-2026-23257 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setu | 171d ago |
| CVE-2026-23256 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setu | 171d ago |
| CVE-2026-23255 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/pt | 171d ago |
| CVE-2026-23254 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: gro: fix outer network offset The udp GRO | 171d ago |
| CVE-2026-23252 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: xfs: get rid of the xchk_xfile_*_descr calls T | 171d ago |
| CVE-2026-23251 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we ha | 171d ago |
| CVE-2026-23250 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: xfs: check return value of xchk_scrub_create_s | 171d ago |
| CVE-2026-23249 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidati | 171d ago |
| CVE-2025-71270 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific | 171d ago |
| CVE-2026-23247 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset T | 171d ago |
| CVE-2025-71267 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero | 171d ago |
| CVE-2025-71266 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to | 171d ago |
| CVE-2025-71265 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs | 171d ago |
| CVE-2026-3563 | 5.5 | — | — | — | ironmansoftware / powershell universal | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an | 172d ago |
| CVE-2026-23241 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The | 172d ago |
| CVE-2025-71239 | 5.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes cl | 172d ago |
| CVE-2026-21991 | 5.5 | — | — | — | oracle / linux | A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names. | 173d ago |
| CVE-2026-4270 | 5.5 | — | — | — | amazon / aws api mcp server | Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server version | 173d ago |
| CVE-2026-21002 | 5.5 | — | — | — | samsung / galaxy store | Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker t | 173d ago |