| CVE-2026-31798 | 5 | medium | fit2cloud / jumpserver | JumpServer is an open source bastion host and an operation and maintenance security audit system. | 176d ago |
| CVE-2026-30853 | 5 | medium | calibre-ebook / calibre | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. | 176d ago |
| CVE-2026-31878 | 5 | medium | frappe / frappe | Frappe is a full-stack web application framework. | 178d ago |
| CVE-2026-3848 | 5 | medium | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, | 178d ago |
| CVE-2026-33700 | 4.9 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-32879 | 4.9 | medium | newapi / new api | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. | 166d ago |
| CVE-2026-31850 | 4.9 | medium | nexxtsolutions / nebula300plus firmware | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administr | 166d ago |
| CVE-2026-3474 | 4.9 | medium | — | The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via | 169d ago |
| CVE-2026-32947 | 4.9 | medium | stepsecurity / harden-runner | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. | 170d ago |
| CVE-2026-30889 | 4.9 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-32828 | 4.9 | medium | akuity / kargo | Kargo manages and automates the promotion of software artifacts. | 170d ago |
| CVE-2026-29101 | 4.9 | medium | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-29098 | 4.9 | medium | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-30873 | 4.9 | medium | openwrt / openwrt | OpenWrt Project is a Linux operating system targeting embedded devices. | 170d ago |
| CVE-2026-26948 | 4.9 | medium | — | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to | 171d ago |
| CVE-2026-22319 | 4.9 | medium | — | A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send | 171d ago |
| CVE-2026-22318 | 4.9 | medium | — | A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privile | 171d ago |
| CVE-2026-25790 | 4.9 | medium | wazuh / wazuh | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 172d ago |
| CVE-2026-25772 | 4.9 | medium | wazuh / wazuh | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 172d ago |
| CVE-2026-29516 | 4.9 | medium | buffaloamericas / terastation nas ts5400r firmware | Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnera | 173d ago |
| CVE-2026-32349 | 4.9 | medium | — | Server-Side Request Forgery (SSRF) vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer allows Server Si | 176d ago |
| CVE-2026-22203 | 4.9 | medium | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertentl | 176d ago |
| CVE-2026-2376 | 4.9 | medium | redhat / quay | A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended inte | 177d ago |
| CVE-2024-51225 | 4.8 | medium | phpgurukul / vehicle record management system | A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Reco | 166d ago |
| CVE-2024-51224 | 4.8 | medium | phpgurukul / vehicle record management system | Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle | 166d ago |
| CVE-2024-51223 | 4.8 | medium | phpgurukul / vehicle record management system | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record | 166d ago |
| CVE-2024-51222 | 4.8 | medium | phpgurukul / vehicle record management system | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record | 166d ago |
| CVE-2026-32896 | 4.8 | medium | openclaw / openclaw | The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentic | 169d ago |
| CVE-2026-32065 | 4.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where render | 169d ago |
| CVE-2026-22895 | 4.8 | medium | qnap / quftp | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. | 169d ago |
| CVE-2026-32031 | 4.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authen | 170d ago |
| CVE-2026-31993 | 4.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion ap | 171d ago |
| CVE-2025-52648 | 4.8 | medium | hcl / aion | HCL AION is affected by a vulnerability where offering images are not digitally signed. | 173d ago |
| CVE-2026-31867 | 4.8 | medium | craftcms / craft commerce | Craft Commerce is an ecommerce platform for Craft CMS. | 178d ago |
| CVE-2026-31813 | 4.8 | medium | supabase / auth | Supabase Auth is a JWT based API for managing users and issuing JWT tokens. | 178d ago |
| CVE-2026-33311 | 4.7 | medium | dicebear / dicebear | DiceBear is an avatar library for designers and developers. | 165d ago |
| CVE-2026-4591 | 4.7 | medium | — | A weakness has been identified in kalcaddle kodbox 1.64. | 166d ago |
| CVE-2026-4564 | 4.7 | medium | — | A security vulnerability has been detected in yangzongzhuan RuoYi up to 4.8.2. | 167d ago |
| CVE-2026-4550 | 4.7 | medium | — | A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. | 167d ago |
| CVE-2026-4537 | 4.7 | medium | — | A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. | 168d ago |
| CVE-2026-4473 | 4.7 | medium | unguardable / online doctor appointment system | A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. | 169d ago |
| CVE-2026-4471 | 4.7 | medium | adonesevangelista / online frozen foods ordering system | A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. | 170d ago |
| CVE-2026-4470 | 4.7 | medium | adonesevangelista / online frozen foods ordering system | A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. | 170d ago |
| CVE-2026-4469 | 4.7 | medium | adonesevangelista / online frozen foods ordering system | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. | 170d ago |
| CVE-2026-4468 | 4.7 | medium | — | A vulnerability was determined in Comfast CF-AC100 2.6.0.8. | 170d ago |
| CVE-2026-4467 | 4.7 | medium | — | A vulnerability was found in Comfast CF-AC100 2.6.0.8. | 170d ago |
| CVE-2026-4466 | 4.7 | medium | — | A vulnerability has been found in Comfast CF-AC100 2.6.0.8. | 170d ago |
| CVE-2026-3580 | 4.7 | medium | wolfssl / wolfssl | In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bne | 170d ago |
| CVE-2026-32723 | 4.7 | medium | nyariv / sandboxjs | SandboxJS is a JavaScript sandboxing library. | 171d ago |
| CVE-2026-32294 | 4.7 | medium | jetkvm / kvm | JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. | 172d ago |
| CVE-2026-32290 | 4.7 | medium | gl-inet / comet gl-rm1 firmware | The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firm | 172d ago |
| CVE-2025-62320 | 4.7 | medium | hcltech / unica | HTML Injection can be carried out in Product when a web application does not properly check or clean user input be | 172d ago |
| CVE-2026-4284 | 4.7 | medium | — | A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. | 173d ago |
| CVE-2026-4253 | 4.7 | medium | tenda / ac8 firmware | A security flaw has been discovered in Tenda AC8 16.03.50.11. | 173d ago |
| CVE-2025-52643 | 4.7 | medium | hcltech / aion | HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly | 173d ago |
| CVE-2026-4238 | 4.7 | medium | — | A vulnerability has been found in itsourcecode College Management System 1.0. | 173d ago |
| CVE-2026-4189 | 4.7 | medium | — | A weakness has been identified in phpipam up to 1.7.4. | 173d ago |
| CVE-2026-3957 | 4.7 | medium | — | A flaw has been found in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. | 178d ago |
| CVE-2026-3956 | 4.7 | medium | — | A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. | 178d ago |
| CVE-2026-32106 | 4.7 | medium | studiocms / studiocms | StudioCMS is a server-side-rendered, Astro native, headless content management system. | 178d ago |