| CVE-2026-33393 | 4.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-32099 | 4.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-27491 | 4.3 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2025-71259 | 4.3 | medium | bmc / footprints | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerabili | 170d ago |
| CVE-2025-71258 | 4.3 | medium | bmc / footprints | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerabili | 170d ago |
| CVE-2026-4068 | 4.3 | medium | — | The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up | 170d ago |
| CVE-2026-2571 | 4.3 | medium | — | The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability | 170d ago |
| CVE-2026-32736 | 4.3 | medium | hytalemodding / wiki | The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. | 171d ago |
| CVE-2026-32742 | 4.3 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 171d ago |
| CVE-2026-33004 | 4.3 | medium | jenkins / loadninja | Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, | 171d ago |
| CVE-2026-33003 | 4.3 | medium | jenkins / loadninja | Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenk | 171d ago |
| CVE-2026-27524 | 4.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, | 172d ago |
| CVE-2026-27978 | 4.3 | medium | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 172d ago |
| CVE-2026-27895 | 4.3 | medium | ldap-account-manager / ldap account manager | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. | 172d ago |
| CVE-2026-32839 | 4.3 | medium | edimax / gs-5008pl firmware | Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows | 172d ago |
| CVE-2026-28506 | 4.3 | medium | getoutline / outline | Outline is a service that allows for collaborative documentation. | 172d ago |
| CVE-2026-28563 | 4.3 | medium | apache / airflow | Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph withou | 172d ago |
| CVE-2026-4202 | 4.3 | medium | ayacoo / redirect tab | The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposur | 172d ago |
| CVE-2026-3237 | 4.3 | medium | octopus / octopus server | In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to ch | 172d ago |
| CVE-2026-4307 | 4.3 | medium | — | A security flaw has been discovered in frdel/agent0ai agent-zero 0.9.7-10. | 173d ago |
| CVE-2026-1629 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel | 173d ago |
| CVE-2026-32262 | 4.3 | medium | craftcms / craft cms | Craft CMS is a content management system (CMS). | 173d ago |
| CVE-2026-26304 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, | 173d ago |
| CVE-2026-29521 | 4.3 | medium | hereta / eth-imc408m firmware | Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allow | 173d ago |
| CVE-2026-2455 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 a | 173d ago |
| CVE-2026-24692 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissi | 173d ago |
| CVE-2026-21386 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses | 173d ago |
| CVE-2026-4265 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_f | 173d ago |
| CVE-2026-4233 | 4.3 | medium | — | A vulnerability was identified in ThingsGateway 12. | 173d ago |
| CVE-2026-32713 | 4.3 | medium | dronecode / px4 drone autopilot | PX4 autopilot is a flight control solution for drones. | 173d ago |
| CVE-2026-2578 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion whic | 173d ago |
| CVE-2026-2463 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user | 173d ago |
| CVE-2026-2461 | 4.3 | medium | mattermost / mattermost server | Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block | 173d ago |
| CVE-2026-2458 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membersh | 173d ago |
| CVE-2026-2457 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post m | 173d ago |
| CVE-2026-26246 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when p | 173d ago |
| CVE-2026-25783 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent h | 173d ago |
| CVE-2026-25780 | 4.3 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when p | 173d ago |
| CVE-2026-1948 | 4.3 | medium | — | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification | 173d ago |
| CVE-2026-1883 | 4.3 | medium | — | The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to | 173d ago |
| CVE-2025-69238 | 4.3 | medium | raytha / raytha | Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. | 173d ago |
| CVE-2017-20221 | 4.3 | medium | telesquare / sdt-cs3b1 firmware | Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows | 173d ago |
| CVE-2016-20028 | 4.3 | medium | — | ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform admi | 173d ago |
| CVE-2026-4063 | 4.3 | medium | — | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due | 176d ago |
| CVE-2026-32461 | 4.3 | medium | — | Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting | 176d ago |
| CVE-2026-32456 | 4.3 | medium | — | Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor admin-menu-editor allows Cross Si | 176d ago |
| CVE-2026-32447 | 4.3 | medium | — | Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly | 176d ago |
| CVE-2026-32446 | 4.3 | medium | — | Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrec | 176d ago |
| CVE-2026-32408 | 4.3 | medium | — | Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Co | 176d ago |
| CVE-2026-32407 | 4.3 | medium | — | Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Explo | 176d ago |
| CVE-2026-32406 | 4.3 | medium | — | Missing Authorization vulnerability in WPClever WPC Product Bundles for WooCommerce woo-product-bundle allows Expl | 176d ago |
| CVE-2026-32394 | 4.3 | medium | — | Missing Authorization vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows E | 176d ago |
| CVE-2026-32386 | 4.3 | medium | — | Missing Authorization vulnerability in EnvoThemes Envo Extra envo-extra allows Exploiting Incorrectly Configured A | 176d ago |
| CVE-2026-32344 | 4.3 | medium | — | Cross-Site Request Forgery (CSRF) vulnerability in desertthemes Corpiva corpiva allows Cross Site Request Forgery. | 176d ago |
| CVE-2026-32343 | 4.3 | medium | — | Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Easy Table of Contents easy-table-of-contents allows | 176d ago |
| CVE-2026-32342 | 4.3 | medium | — | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery | 176d ago |
| CVE-2026-32330 | 4.3 | medium | — | Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Cross Site Re | 176d ago |
| CVE-2026-31919 | 4.3 | medium | — | Missing Authorization vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for | 176d ago |
| CVE-2026-30961 | 4.3 | medium | forceu / gokapi | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. | 176d ago |
| CVE-2026-30915 | 4.3 | medium | sftpgo project / sftpgo | SFTPGo is an open source, event-driven file transfer solution. | 176d ago |