| CVE-2026-32234 | 4.7 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 178d ago |
| CVE-2025-60948 | 4.6 | medium | csprousers / csweb | Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. | 166d ago |
| CVE-2026-32953 | 4.6 | medium | tillitis / tkey client | Tillitis TKey Client package is a Go package for a TKey client. | 170d ago |
| CVE-2026-32040 | 4.6 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that all | 170d ago |
| CVE-2026-1527 | 4.6 | medium | nodejs / undici | ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can i | 177d ago |
| CVE-2025-52637 | 4.5 | medium | hcl / aion | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially | 173d ago |
| CVE-2026-4161 | 4.4 | medium | — | The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin set | 169d ago |
| CVE-2026-3354 | 4.4 | medium | — | The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in a | 169d ago |
| CVE-2026-3353 | 4.4 | medium | — | The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting | 169d ago |
| CVE-2026-2837 | 4.4 | medium | — | The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settin | 169d ago |
| CVE-2026-2424 | 4.4 | medium | — | The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti | 169d ago |
| CVE-2026-2121 | 4.4 | medium | — | The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' paramet | 169d ago |
| CVE-2026-1278 | 4.4 | medium | — | The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver | 169d ago |
| CVE-2026-1247 | 4.4 | medium | — | The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up | 169d ago |
| CVE-2026-3577 | 4.4 | medium | — | The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias | 169d ago |
| CVE-2026-2432 | 4.4 | medium | — | The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored | 169d ago |
| CVE-2026-33395 | 4.4 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-32119 | 4.4 | medium | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 170d ago |
| CVE-2026-31996 | 4.4 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that al | 171d ago |
| CVE-2026-20991 | 4.4 | medium | samsung / android | Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to | 173d ago |
| CVE-2026-22210 | 4.4 | medium | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious cod | 176d ago |
| CVE-2026-32237 | 4.4 | medium | linuxfoundation / backstage\/plugin-scaffolder-backend | Backstage is an open framework for building developer portals. | 177d ago |
| CVE-2026-33527 | 4.3 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 165d ago |
| CVE-2026-33161 | 4.3 | medium | craftcms / craft cms | Craft CMS is a content management system (CMS). | 165d ago |
| CVE-2026-33315 | 4.3 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-33313 | 4.3 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-32642 | 4.3 | medium | apache / artemis | Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an applicat | 165d ago |
| CVE-2026-33290 | 4.3 | medium | — | WPGraphQL provides a GraphQL API for WordPress sites. | 166d ago |
| CVE-2026-4066 | 4.3 | medium | — | The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili | 166d ago |
| CVE-2026-3225 | 4.3 | medium | — | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question | 166d ago |
| CVE-2026-4628 | 4.3 | medium | redhat / build of keycloak | A flaw was found in Keycloak. | 166d ago |
| CVE-2026-4563 | 4.3 | medium | — | A weakness has been identified in MacCMS up to 2025.1000.4052. | 167d ago |
| CVE-2026-4557 | 4.3 | medium | — | A vulnerability was detected in code-projects Exam Form Submission 1.0. | 167d ago |
| CVE-2026-4547 | 4.3 | medium | — | A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. | 167d ago |
| CVE-2026-4510 | 4.3 | medium | — | A weakness has been identified in PbootCMS up to 3.2.12. | 168d ago |
| CVE-2026-4143 | 4.3 | medium | — | The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u | 169d ago |
| CVE-2026-4127 | 4.3 | medium | — | The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and incl | 169d ago |
| CVE-2026-3332 | 4.3 | medium | — | The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions | 169d ago |
| CVE-2026-3331 | 4.3 | medium | — | The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, | 169d ago |
| CVE-2026-2294 | 4.3 | medium | — | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unaut | 169d ago |
| CVE-2026-1935 | 4.3 | medium | — | The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, a | 169d ago |
| CVE-2026-1503 | 4.3 | medium | — | The login_register plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting | 169d ago |
| CVE-2026-1393 | 4.3 | medium | — | The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forg | 169d ago |
| CVE-2026-1392 | 4.3 | medium | — | The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i | 169d ago |
| CVE-2026-1390 | 4.3 | medium | — | The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and | 169d ago |
| CVE-2026-1378 | 4.3 | medium | — | The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i | 169d ago |
| CVE-2026-1253 | 4.3 | medium | — | The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due | 169d ago |
| CVE-2026-32899 | 4.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-m | 169d ago |
| CVE-2026-33238 | 4.3 | medium | wwbn / avideo | WWBN AVideo is an open source video platform. | 169d ago |
| CVE-2026-33423 | 4.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-33177 | 4.3 | medium | statamic / statamic | Statamic is a Laravel and Git powered content management system (CMS). | 169d ago |
| CVE-2026-33171 | 4.3 | medium | statamic / statamic | Statamic is a Laravel and Git powered content management system (CMS). | 169d ago |
| CVE-2026-30580 | 4.3 | medium | leefish / file thingie | File Thingie 2.5.7 is vulnerable to Directory Traversal. | 169d ago |
| CVE-2026-33371 | 4.3 | medium | synacor / zimbra collaboration suite | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. | 169d ago |
| CVE-2026-33369 | 4.3 | medium | synacor / zimbra collaboration suite | Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service with | 169d ago |
| CVE-2026-33071 | 4.3 | medium | filerise / filerise | FileRise is a self-hosted web file manager / WebDAV server. | 169d ago |
| CVE-2026-4136 | 4.3 | medium | — | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions | 170d ago |
| CVE-2026-32114 | 4.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-31869 | 4.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-4453 | 4.3 | medium | google / chrome | Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-or | 170d ago |