| CVE-2026-3570 | 5.3 | medium | — | The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and includin | 169d ago |
| CVE-2026-3546 | 5.3 | medium | — | The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, | 169d ago |
| CVE-2026-3506 | 5.3 | medium | — | The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and | 169d ago |
| CVE-2026-3460 | 5.3 | medium | — | The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions | 169d ago |
| CVE-2026-3335 | 5.3 | medium | — | The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 v | 169d ago |
| CVE-2026-32046 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers | 169d ago |
| CVE-2026-3567 | 5.3 | medium | — | The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versio | 169d ago |
| CVE-2026-33425 | 5.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-33221 | 5.3 | medium | nhost / storage | Nhost is an open source Firebase alternative with GraphQL. | 169d ago |
| CVE-2026-4496 | 5.3 | medium | — | A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. | 169d ago |
| CVE-2026-29794 | 5.3 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 169d ago |
| CVE-2025-46598 | 5.3 | medium | bitcoin / bitcoin core | Bitcoin Core through 29.0 allows a denial of service via a crafted transaction. | 169d ago |
| CVE-2026-31381 | 5.3 | medium | gainsight / assist | An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth | 169d ago |
| CVE-2026-33132 | 5.3 | medium | zitadel / zitadel | ZITADEL is an open source identity management platform. | 169d ago |
| CVE-2026-32305 | 5.3 | medium | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 169d ago |
| CVE-2026-3550 | 5.3 | medium | — | The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0 | 169d ago |
| CVE-2026-33192 | 5.3 | medium | free5gc / udm | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. | 169d ago |
| CVE-2026-33065 | 5.3 | medium | free5gc / udm | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. | 169d ago |
| CVE-2026-33060 | 5.3 | medium | ondata / ckan mcp server | CKAN MCP Server is a tool for querying CKAN open data portals. | 169d ago |
| CVE-2026-33041 | 5.3 | medium | wwbn / avideo | WWBN AVideo is an open source video platform. | 170d ago |
| CVE-2026-31805 | 5.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-32881 | 5.3 | medium | vshakitskiy / ewe | ewe is a Gleam web server. | 170d ago |
| CVE-2026-32766 | 5.3 | medium | astral / astral-tokio-tar | astral-tokio-tar is a tar archive reading/writing library for async Rust. | 170d ago |
| CVE-2026-32029 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests ori | 170d ago |
| CVE-2026-32028 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct | 170d ago |
| CVE-2026-32002 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails | 170d ago |
| CVE-2026-27936 | 5.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-27454 | 5.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-24299 | 5.3 | medium | microsoft / 365 copilot | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unau | 170d ago |
| CVE-2026-1005 | 5.3 | medium | wolfssl / wolfssl | Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decr | 170d ago |
| CVE-2026-3475 | 5.3 | medium | — | The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in al | 170d ago |
| CVE-2026-28070 | 5.3 | medium | — | Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Acce | 171d ago |
| CVE-2026-31995 | 5.3 | medium | openclaw / openclaw | OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension' | 171d ago |
| CVE-2026-27670 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local att | 171d ago |
| CVE-2026-33042 | 5.3 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 171d ago |
| CVE-2026-32700 | 5.3 | medium | heartcombo / devise | Devise is an authentication solution for Rails based on Warden. | 171d ago |
| CVE-2026-32636 | 5.3 | medium | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 171d ago |
| CVE-2026-26945 | 5.3 | medium | — | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to | 171d ago |
| CVE-2026-2559 | 5.3 | medium | — | The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c | 171d ago |
| CVE-2026-32691 | 5.3 | medium | canonical / juju | A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated | 171d ago |
| CVE-2026-32565 | 5.3 | medium | — | Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting In | 171d ago |
| CVE-2026-22321 | 5.3 | medium | — | A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker | 171d ago |
| CVE-2026-2575 | 5.3 | medium | redhat / build of keycloak | A flaw was found in Keycloak. | 172d ago |
| CVE-2026-1926 | 5.3 | medium | — | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a | 172d ago |
| CVE-2026-22180 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling tha | 172d ago |
| CVE-2026-27448 | 5.3 | medium | pyopenssl / pyopenssl | pyOpenSSL is a Python wrapper around the OpenSSL library. | 172d ago |
| CVE-2026-3856 | 5.3 | medium | ibm / db2 recovery expert | IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due | 172d ago |
| CVE-2026-25771 | 5.3 | medium | wazuh / wazuh | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 172d ago |
| CVE-2026-4271 | 5.3 | medium | gnome / libsoup | A flaw was found in libsoup, a library for handling HTTP requests. | 172d ago |
| CVE-2026-32586 | 5.3 | medium | — | Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Inco | 172d ago |
| CVE-2026-2373 | 5.3 | medium | — | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Infor | 173d ago |
| CVE-2026-30876 | 5.3 | medium | chamilo / chamilo lms | Chamilo LMS is a learning management system. | 173d ago |
| CVE-2025-69727 | 5.3 | medium | — | An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. | 173d ago |
| CVE-2026-32583 | 5.3 | medium | — | Missing Authorization vulnerability in Webnus Inc. | 173d ago |
| CVE-2026-4240 | 5.3 | medium | open5gs / open5gs | A vulnerability was determined in Open5GS up to 2.7.6. | 173d ago |
| CVE-2026-4216 | 5.3 | medium | — | A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. | 173d ago |
| CVE-2026-4199 | 5.3 | medium | — | A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. | 173d ago |
| CVE-2026-4198 | 5.3 | medium | — | A vulnerability was determined in hypermodel-labs mcp-server-auto-commit 1.0.0. | 173d ago |
| CVE-2026-4187 | 5.3 | medium | — | A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. | 173d ago |
| CVE-2026-32724 | 5.3 | medium | dronecode / px4 drone autopilot | PX4 autopilot is a flight control solution for drones. | 173d ago |