| CVE-2026-21001 | 5.5 | — | — | — | samsung / galaxy store | Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store pr | 173d ago |
| CVE-2026-21000 | 5.5 | — | — | — | samsung / galaxy store | Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy | 173d ago |
| CVE-2026-20993 | 5.5 | — | — | — | samsung / assistant | Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local atta | 173d ago |
| CVE-2025-52458 | 5.5 | — | — | — | openatom / openharmony | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps thr | 173d ago |
| CVE-2025-41432 | 5.5 | — | — | — | openatom / openharmony | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps thr | 173d ago |
| CVE-2016-20031 | 5.5 | — | — | — | — | ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers | 173d ago |
| CVE-2026-22209 | 5.5 | — | — | — | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administra | 176d ago |
| CVE-2025-15515 | 5.5 | — | — | — | vivo / easyshare | The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. | 176d ago |
| CVE-2026-31890 | 5.5 | — | — | — | linuxfoundation / inspektor gadget | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters | 177d ago |
| CVE-2026-2640 | 5.5 | — | — | — | lenovo / pcmanager | During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could al | 178d ago |
| CVE-2026-1717 | 5.5 | — | — | — | lenovo / vantage | An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Leno | 178d ago |
| CVE-2026-1653 | 5.5 | — | — | — | lenovo / smart connect | A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that c | 178d ago |
| CVE-2026-31961 | 5.5 | — | — | — | anchore / quill | Quill provides simple mac binary signing and notarization from any platform. | 178d ago |
| CVE-2019-25464 | 5.5 | — | — | — | — | InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to c | 178d ago |
| CVE-2026-33400 | 5.4 | — | — | — | wallosapp / wallos | Wallos is an open-source, self-hostable personal subscription tracker. | 165d ago |
| CVE-2026-29840 | 5.4 | — | — | — | jizhicms / jizhicms | JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function with | 165d ago |
| CVE-2026-28755 | 5.4 | — | — | — | f5 / nginx plus | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper hand | 165d ago |
| CVE-2026-4056 | 5.4 | — | — | — | — | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a | 166d ago |
| CVE-2024-46879 | 5.4 | — | — | — | tiki / tiki | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system. | 166d ago |
| CVE-2024-46878 | 5.4 | — | — | — | tiki / tiki | A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 | 166d ago |
| CVE-2026-33683 | 5.4 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-33500 | 5.4 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-33295 | 5.4 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 167d ago |
| CVE-2026-4542 | 5.4 | — | — | — | — | A vulnerability has been found in SSCMS 4.7.0. | 167d ago |
| CVE-2026-32898 | 5.4 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-app | 169d ago |
| CVE-2026-32895 | 5.4 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system eve | 169d ago |
| CVE-2026-33411 | 5.4 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-33291 | 5.4 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-33251 | 5.4 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-4438 | 5.4 | — | — | — | gnu / glibc | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend i | 169d ago |
| CVE-2025-63260 | 5.4 | — | — | — | syncfusion / syncfusion | SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and | 169d ago |
| CVE-2026-33312 | 5.4 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 169d ago |
| CVE-2026-33372 | 5.4 | — | — | — | synacor / zimbra collaboration suite | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. | 169d ago |
| CVE-2026-33051 | 5.4 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 170d ago |
| CVE-2026-32757 | 5.4 | — | — | — | admidio / admidio | Admidio is an open-source user management solution. | 170d ago |
| CVE-2026-29105 | 5.4 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-33410 | 5.4 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-32753 | 5.4 | — | — | — | freescout / freescout | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. | 170d ago |
| CVE-2026-32001 | 5.4 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authentica | 170d ago |
| CVE-2026-33305 | 5.4 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 170d ago |
| CVE-2026-33303 | 5.4 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 170d ago |
| CVE-2026-33299 | 5.4 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 170d ago |
| CVE-2026-32867 | 5.4 | — | — | — | opexustech / ecase ecomplaint | OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case n | 170d ago |
| CVE-2026-21788 | 5.4 | — | — | — | hcltech / connections | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execut | 170d ago |
| CVE-2026-1276 | 5.4 | — | — | — | ibm / qradar security information and event manager | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. | 171d ago |
| CVE-2025-15051 | 5.4 | — | — | — | ibm / qradar security information and event manager | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. | 171d ago |
| CVE-2026-30048 | 5.4 | — | — | — | — | A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. | 171d ago |
| CVE-2026-1217 | 5.4 | — | — | — | — | The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c | 171d ago |
| CVE-2026-27977 | 5.4 | — | — | — | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 172d ago |
| CVE-2026-20643 | 5.4 | — | — | — | apple / ipados | A cross-origin issue in the Navigation API was addressed with improved input validation. | 172d ago |
| CVE-2026-32840 | 5.4 | — | — | — | edimax / gs-5008pl firmware | Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the sys | 172d ago |
| CVE-2026-4324 | 5.4 | — | — | — | — | A flaw was found in the Katello plugin for Red Hat Satellite. | 172d ago |
| CVE-2025-69693 | 5.4 | — | — | — | ffmpeg / ffmpeg | Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). | 173d ago |
| CVE-2026-29513 | 5.4 | — | — | — | hereta / eth-imc408m firmware | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allo | 173d ago |
| CVE-2026-29510 | 5.4 | — | — | — | hereta / eth-imc408m firmware | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allo | 173d ago |
| CVE-2025-65734 | 5.4 | — | — | — | openeclass / openeclass | An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v | 173d ago |
| CVE-2026-32587 | 5.4 | — | — | — | — | Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured | 173d ago |
| CVE-2026-3024 | 5.4 | — | — | — | wakyma / wakyma | Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.w | 173d ago |
| CVE-2026-32709 | 5.4 | — | — | — | dronecode / px4 drone autopilot | PX4 autopilot is a flight control solution for drones. | 173d ago |
| CVE-2025-69241 | 5.4 | — | — | — | raytha / raytha | Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. | 173d ago |