| CVE-2025-69237 | 5.4 | — | — | — | raytha / raytha | Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. | 173d ago |
| CVE-2025-69236 | 5.4 | — | — | — | raytha / raytha | Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. | 173d ago |
| CVE-2026-32612 | 5.4 | — | — | — | statamic / statamic | Statamic is a Laravel and Git powered content management system (CMS). | 176d ago |
| CVE-2026-32423 | 5.4 | — | — | — | — | Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Explo | 176d ago |
| CVE-2026-32420 | 5.4 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forg | 176d ago |
| CVE-2026-32417 | 5.4 | — | — | — | — | Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access C | 176d ago |
| CVE-2026-32416 | 5.4 | — | — | — | — | Missing Authorization vulnerability in bPlugins PDF Poster pdf-poster allows Exploiting Incorrectly Configured Acc | 176d ago |
| CVE-2026-32412 | 5.4 | — | — | — | — | Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift | 176d ago |
| CVE-2026-32391 | 5.4 | — | — | — | — | Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Acces | 176d ago |
| CVE-2026-32390 | 5.4 | — | — | — | — | Missing Authorization vulnerability in linethemes Nanosoft nanosoft allows Exploiting Incorrectly Configured Acces | 176d ago |
| CVE-2026-32388 | 5.4 | — | — | — | — | Missing Authorization vulnerability in linethemes GLB glb allows Exploiting Incorrectly Configured Access Control | 176d ago |
| CVE-2026-32385 | 5.4 | — | — | — | — | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submissio | 176d ago |
| CVE-2026-32373 | 5.4 | — | — | — | — | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incor | 176d ago |
| CVE-2026-32331 | 5.4 | — | — | — | — | Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Ac | 176d ago |
| CVE-2026-32328 | 5.4 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in shufflehound Lemmony lemmony allows Cross Site Request Forgery. | 176d ago |
| CVE-2026-2879 | 5.4 | — | — | — | — | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl | 176d ago |
| CVE-2026-23942 | 5.4 | — | — | — | erlang / erlang\/otp | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sf | 176d ago |
| CVE-2026-0835 | 5.4 | — | — | — | ibm / sterling b2b integrator | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2 | 176d ago |
| CVE-2025-14504 | 5.4 | — | — | — | ibm / sterling b2b integrator | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6. | 176d ago |
| CVE-2023-40693 | 5.4 | — | — | — | ibm / sterling b2b integrator | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1 | 176d ago |
| CVE-2026-32139 | 5.4 | — | — | — | dataease / dataease | Dataease is an open source data visualization analysis tool. | 177d ago |
| CVE-2026-32125 | 5.4 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 178d ago |
| CVE-2026-32124 | 5.4 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 178d ago |
| CVE-2026-32118 | 5.4 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 178d ago |
| CVE-2026-32104 | 5.4 | — | — | — | studiocms / studiocms | StudioCMS is a server-side-rendered, Astro native, headless content management system. | 178d ago |
| CVE-2026-32095 | 5.4 | — | — | — | useplunk / plunk | Plunk is an open-source email platform built on top of AWS SES. | 178d ago |
| CVE-2026-31879 | 5.4 | — | — | — | frappe / frappe | Frappe is a full-stack web application framework. | 178d ago |
| CVE-2026-31876 | 5.4 | — | — | — | streetwriters / notesnook desktop | Notesnook is a note-taking app focused on user privacy & ease of use. | 178d ago |
| CVE-2026-20166 | 5.4 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1. | 178d ago |
| CVE-2026-66384exploited | 5.3 | — | — | — | jfrog / artifactory | An authenticated user may write data outside the intended Docker cache path under specific remote-repository condi | 24d ago |
| CVE-2026-20316exploited | 5.3 | — | — | — | cisco / secure firewall management center | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unau | 38d ago |
| CVE-2026-56164exploited | 5.3 | — | — | — | microsoft / sharepoint server | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to ele | 53d ago |
| CVE-2026-33429 | 5.3 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 165d ago |
| CVE-2026-33323 | 5.3 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 165d ago |
| CVE-2026-33160 | 5.3 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 165d ago |
| CVE-2026-4751 | 5.3 | — | — | — | — | NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0. | 166d ago |
| CVE-2026-4733 | 5.3 | — | — | — | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue a | 166d ago |
| CVE-2026-33173 | 5.3 | — | — | — | rubyonrails / rails | Active Storage allows users to attach cloud and local files in Rails applications. | 166d ago |
| CVE-2026-33169 | 5.3 | — | — | — | rubyonrails / rails | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. | 166d ago |
| CVE-2026-27183 | 5.3 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wr | 166d ago |
| CVE-2026-23488 | 5.3 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 166d ago |
| CVE-2026-23486 | 5.3 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 166d ago |
| CVE-2026-23485 | 5.3 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 166d ago |
| CVE-2026-23483 | 5.3 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 166d ago |
| CVE-2026-33690 | 5.3 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-33688 | 5.3 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-33685 | 5.3 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-33501 | 5.3 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-28809 | 5.3 | — | — | — | arekinath / esaml | XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read lo | 166d ago |
| CVE-2025-13997 | 5.3 | — | — | — | — | The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor pl | 167d ago |
| CVE-2026-1969 | 5.3 | — | — | — | — | The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, all | 167d ago |
| CVE-2025-10734 | 5.3 | — | — | — | — | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plug | 167d ago |
| CVE-2025-10731 | 5.3 | — | — | — | — | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plug | 167d ago |
| CVE-2026-4538 | 5.3 | — | — | — | linuxfoundation / pytorch | A vulnerability was identified in PyTorch 2.10.0. | 168d ago |
| CVE-2026-4532 | 5.3 | — | — | — | carmelo / simple food order system | A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. | 168d ago |
| CVE-2026-4531 | 5.3 | — | — | — | — | A weakness has been identified in Free5GC 4.1.0. | 168d ago |
| CVE-2026-4530 | 5.3 | — | — | — | — | A security flaw has been discovered in apconw Aix-DB up to 1.2.3. | 168d ago |
| CVE-2026-3651 | 5.3 | — | — | — | — | The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including | 169d ago |
| CVE-2026-3645 | 5.3 | — | — | — | — | The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to | 169d ago |
| CVE-2026-3641 | 5.3 | — | — | — | — | The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1. | 169d ago |