| CVE-2026-4012 | 3.3 | low | — | A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. | 177d ago |
| CVE-2026-4010 | 3.3 | low | — | A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. | 177d ago |
| CVE-2026-4009 | 3.3 | low | — | A vulnerability has been found in jarikomppa soloud up to 20200207. | 177d ago |
| CVE-2026-3950 | 3.3 | low | — | A vulnerability was identified in strukturag libheif up to 1.21.2. | 178d ago |
| CVE-2026-3949 | 3.3 | low | — | A vulnerability was determined in strukturag libheif up to 1.21.2. | 178d ago |
| CVE-2026-4590 | 3.1 | low | — | A security flaw has been discovered in kalcaddle kodbox 1.64. | 166d ago |
| CVE-2026-4584 | 3.1 | low | — | A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. | 166d ago |
| CVE-2026-4549 | 3.1 | low | — | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. | 167d ago |
| CVE-2026-4477 | 3.1 | low | — | A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. | 169d ago |
| CVE-2026-32006 | 3.1 | low | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identiti | 170d ago |
| CVE-2026-32943 | 3.1 | low | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 171d ago |
| CVE-2026-22545 | 3.1 | low | mattermost / mattermost server | Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth | 173d ago |
| CVE-2026-29776 | 3.1 | low | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 176d ago |
| CVE-2025-14811 | 3.1 | low | ibm / sterling partner engagement manager | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacke | 176d ago |
| CVE-2026-2366 | 3.1 | low | redhat / build of keycloak | A flaw was found in Keycloak. | 177d ago |
| CVE-2026-3929 | 3.1 | low | google / chrome | Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacke | 178d ago |
| CVE-2026-31974 | 3 | low | openproject / openproject | OpenProject is an open-source, web-based project management software. | 178d ago |
| CVE-2026-32778 | 2.9 | low | libexpat project / libexpat | libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-o | 173d ago |
| CVE-2026-0520 | 2.8 | low | lenovo / filez | A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, coul | 178d ago |
| CVE-2026-3339 | 2.7 | low | — | The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and inclu | 169d ago |
| CVE-2026-32946 | 2.7 | low | stepsecurity / harden-runner | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. | 170d ago |
| CVE-2026-29104 | 2.7 | low | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-33394 | 2.7 | low | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-3230 | 2.7 | low | wolfssl / wolfssl | Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead t | 170d ago |
| CVE-2026-32638 | 2.7 | low | studiocms / studiocms | StudioCMS is a server-side-rendered, Astro native, headless content management system. | 171d ago |
| CVE-2025-31966 | 2.7 | low | hcltech / sametime | HCL Sametime is vulnerable to broken server-side validation. | 172d ago |
| CVE-2026-4285 | 2.7 | low | — | A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. | 173d ago |
| CVE-2026-32717 | 2.7 | low | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 173d ago |
| CVE-2025-69239 | 2.7 | low | raytha / raytha | Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. | 173d ago |
| CVE-2025-13459 | 2.7 | low | ibm / aspera console | IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper | 173d ago |
| CVE-2026-32445 | 2.7 | low | — | Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly | 176d ago |
| CVE-2026-32058 | 2.6 | low | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows wi | 169d ago |
| CVE-2026-22735 | 2.6 | low | vmware / spring framework | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). | 170d ago |
| CVE-2026-4541 | 2.5 | low | — | A flaw has been found in janmojzis tinyssh up to 20250501. | 167d ago |
| CVE-2026-4251 | 2.5 | low | — | A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. | 173d ago |
| CVE-2026-4250 | 2.5 | low | — | A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. | 173d ago |
| CVE-2026-4243 | 2.5 | low | — | A weakness has been identified in La Nacion App 10.2.25 on Android. | 173d ago |
| CVE-2026-4242 | 2.5 | low | — | A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. | 173d ago |
| CVE-2026-4218 | 2.5 | low | — | A vulnerability was detected in myAEDES App up to 1.18.4 on Android. | 173d ago |
| CVE-2026-4217 | 2.5 | low | — | A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. | 173d ago |
| CVE-2026-24508 | 2.5 | low | dell / alienware command center | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vuln | 178d ago |
| CVE-2026-4616 | 2.4 | low | — | A security flaw has been discovered in bolo-blog up to 2.6.4. | 166d ago |
| CVE-2026-4595 | 2.4 | low | — | A vulnerability was determined in code-projects Exam Form Submission 1.0. | 166d ago |
| CVE-2026-4578 | 2.4 | low | — | A vulnerability was determined in code-projects Exam Form Submission 1.0. | 166d ago |
| CVE-2026-4577 | 2.4 | low | — | A vulnerability was found in code-projects Exam Form Submission 1.0. | 166d ago |
| CVE-2026-4576 | 2.4 | low | — | A vulnerability has been found in code-projects Exam Form Submission 1.0. | 166d ago |
| CVE-2026-4575 | 2.4 | low | — | A flaw has been found in code-projects Exam Form Submission 1.0. | 166d ago |
| CVE-2026-4544 | 2.4 | low | wavlink / wl-wn578w2 firmware | A vulnerability was determined in Wavlink WL-WN578W2 221110. | 167d ago |
| CVE-2026-4474 | 2.4 | low | angeljudesuarez / university management system | A flaw has been found in itsourcecode University Management System 1.0. | 169d ago |
| CVE-2026-4356 | 2.4 | low | — | A flaw has been found in itsourcecode University Management System 1.0. | 172d ago |
| CVE-2026-4225 | 2.4 | low | — | A security flaw has been discovered in CMS Made Simple up to 2.2.21. | 173d ago |
| CVE-2026-4169 | 2.4 | low | — | A security flaw has been discovered in Tecnick TCExam up to 16.6.0. | 173d ago |
| CVE-2026-4168 | 2.4 | low | — | A vulnerability was identified in Tecnick TCExam 16.5.0. | 173d ago |
| CVE-2026-4165 | 2.4 | low | — | A vulnerability has been found in Worksuite HR, CRM and Project Management up to 5.5.25. | 173d ago |
| CVE-2026-20989 | 2.4 | low | samsung / android | Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical | 173d ago |
| CVE-2026-30888 | 2.2 | low | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-33408 | 2.2 | low | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2025-52646 | 2.2 | low | hcltech / aion | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially | 173d ago |
| CVE-2025-12697 | 2.2 | low | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, | 178d ago |
| CVE-2026-33550 | 2 | low | alinto / sogo | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digit | 168d ago |