| CVE-2026-32347 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Restaurant and Cafe restaurant-and-cafe allows Exploiting Incorre | 176d ago |
| CVE-2026-32346 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Travel Agency travel-agency allows Exploiting Incorrectly Configu | 176d ago |
| CVE-2026-32345 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Perfect Portfolio perfect-portfolio allows Exploiting Incorrectly | 176d ago |
| CVE-2026-32341 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Benevolent benevolent allows Exploiting Incorrectly Configured Ac | 176d ago |
| CVE-2026-32340 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Business One Page business-one-page allows Exploiting Incorrectly | 176d ago |
| CVE-2026-32339 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Bakes And Cakes bakes-and-cakes allows Exploiting Incorrectly Con | 176d ago |
| CVE-2026-32338 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Construction Landing Page construction-landing-page allows Exploi | 176d ago |
| CVE-2026-32337 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Preschool and Kindergarten preschool-and-kindergarten allows Expl | 176d ago |
| CVE-2026-32336 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme Rara Business rara-business allows Exploiting Incorrectly Configu | 176d ago |
| CVE-2026-32335 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme The Conference the-conference allows Exploiting Incorrectly Confi | 176d ago |
| CVE-2026-32334 | 5.3 | medium | — | Missing Authorization vulnerability in raratheme JobScout jobscout allows Exploiting Incorrectly Configured Access | 176d ago |
| CVE-2026-32332 | 5.3 | medium | — | Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access | 176d ago |
| CVE-2026-32329 | 5.3 | medium | — | Missing Authorization vulnerability in Ays Pro Advanced Related Posts advanced-related-posts allows Exploiting Inc | 176d ago |
| CVE-2026-32322 | 5.3 | medium | stellar / rs-soroban-sdk | soroban-sdk is a Rust SDK for Soroban contracts. | 176d ago |
| CVE-2026-31916 | 5.3 | medium | — | Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting I | 176d ago |
| CVE-2026-31915 | 5.3 | medium | — | Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access | 176d ago |
| CVE-2026-2888 | 5.3 | medium | — | The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in a | 176d ago |
| CVE-2026-29775 | 5.3 | medium | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 176d ago |
| CVE-2026-29774 | 5.3 | medium | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 176d ago |
| CVE-2026-23943 | 5.3 | medium | erlang / erlang\/otp | Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modu | 176d ago |
| CVE-2026-22201 | 5.3 | medium | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypa | 176d ago |
| CVE-2025-13726 | 5.3 | medium | ibm / sterling partner engagement manager | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote a | 176d ago |
| CVE-2025-13723 | 5.3 | medium | ibm / sterling partner engagement manager | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacke | 176d ago |
| CVE-2026-32249 | 5.3 | medium | vim / vim | Vim is an open source, command line text editor. | 177d ago |
| CVE-2026-32230 | 5.3 | medium | uptime.kuma / uptime kuma | Uptime Kuma is an open source, self-hosted monitoring tool. | 177d ago |
| CVE-2026-32142 | 5.3 | medium | — | Shopware is an open commerce platform. | 177d ago |
| CVE-2026-32100 | 5.3 | medium | — | Shopware is an open commerce platform. | 177d ago |
| CVE-2026-4016 | 5.3 | medium | — | A security vulnerability has been detected in GPAC 26.03-DEV. | 177d ago |
| CVE-2026-4015 | 5.3 | medium | — | A weakness has been identified in GPAC 26.03-DEV. | 177d ago |
| CVE-2026-3994 | 5.3 | medium | — | A vulnerability was detected in rui314 mold up to 2.40.4. | 177d ago |
| CVE-2026-3979 | 5.3 | medium | — | A flaw has been found in quickjs-ng quickjs up to 0.12.1. | 178d ago |
| CVE-2026-3964 | 5.3 | medium | — | A weakness has been identified in OpenAkita up to 1.24.3. | 178d ago |
| CVE-2026-31988 | 5.3 | medium | — | yauzl (aka Yet Another Unzip Library) version 3.2.0 for Node.js contains an off-by-one error in the NTFS extended | 178d ago |
| CVE-2026-3959 | 5.3 | medium | — | A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. | 178d ago |
| CVE-2026-3940 | 5.3 | medium | google / chrome | Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to by | 178d ago |
| CVE-2026-3939 | 5.3 | medium | google / chrome | Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass | 178d ago |
| CVE-2026-3930 | 5.3 | medium | google / chrome | Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass | 178d ago |
| CVE-2026-32111 | 5.3 | medium | homeassistant-ai / home assistant mcp server | ha-mcp is a Home Assistant MCP Server. | 178d ago |
| CVE-2026-1068 | 5.3 | medium | lenovo / filez | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a us | 178d ago |
| CVE-2026-31960 | 5.3 | medium | anchore / quill | Quill provides simple mac binary signing and notarization from any platform. | 178d ago |
| CVE-2026-31959 | 5.3 | medium | anchore / quill | Quill provides simple mac binary signing and notarization from any platform. | 178d ago |
| CVE-2026-31901 | 5.3 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 178d ago |
| CVE-2026-31888 | 5.3 | medium | shopware / shopware | Shopware is an open commerce platform. | 178d ago |
| CVE-2026-3503 | 5.2 | medium | wolfssl / wolfssl | Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex | 170d ago |
| CVE-2026-32707 | 5.2 | medium | dronecode / px4 drone autopilot | PX4 autopilot is a flight control solution for drones. | 173d ago |
| CVE-2026-22191 | 5.2 | medium | gvectors / wpdiscuz | Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary | 176d ago |
| CVE-2026-1940 | 5.1 | medium | freedesktop / gst-plugins-good | An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. | 166d ago |
| CVE-2026-0977 | 5.1 | medium | ibm / cics transaction gateway | IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to im | 173d ago |
| CVE-2026-4583 | 5 | medium | — | A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. | 166d ago |
| CVE-2026-4582 | 5 | medium | — | A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. | 166d ago |
| CVE-2026-33294 | 5 | medium | wwbn / avideo | WWBN AVideo is an open source video platform. | 167d ago |
| CVE-2026-2756 | 5 | medium | — | A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. | 168d ago |
| CVE-2026-33126 | 5 | medium | frigate / frigate | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. | 169d ago |
| CVE-2026-29107 | 5 | medium | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2025-13995 | 5 | medium | ibm / qradar security information and event manager | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access | 171d ago |
| CVE-2026-20988 | 5 | medium | samsung / android | Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local att | 173d ago |
| CVE-2026-0385 | 5 | medium | microsoft / edge chromium | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | 173d ago |
| CVE-2025-6969 | 5 | medium | openatom / openharmony | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. | 173d ago |
| CVE-2026-32442 | 5 | medium | — | Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control S | 176d ago |
| CVE-2026-32415 | 5 | medium | — | Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue af | 176d ago |