| CVE-2026-31849 | 6.5 | medium | nexxtsolutions / nebula300plus firmware | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-chan | 166d ago |
| CVE-2026-31846 | 6.5 | medium | — | Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.0 | 166d ago |
| CVE-2025-10736 | 6.5 | medium | — | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plug | 166d ago |
| CVE-2019-25610 | 6.5 | medium | — | NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated | 167d ago |
| CVE-2019-25600 | 6.5 | medium | — | UltraVNC Viewer 1.2.2.4 contains a denial of service vulnerability that allows attackers to crash the application | 167d ago |
| CVE-2019-25582 | 6.5 | medium | i-doit / i-doit | i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download | 168d ago |
| CVE-2019-25574 | 6.5 | medium | njtech / greencms | Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary fi | 168d ago |
| CVE-2026-4087 | 6.5 | medium | — | The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of t | 169d ago |
| CVE-2026-4004 | 6.5 | medium | — | The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action i | 169d ago |
| CVE-2026-2720 | 6.5 | medium | — | The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a mis | 169d ago |
| CVE-2026-2503 | 6.5 | medium | — | The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parame | 169d ago |
| CVE-2026-2375 | 6.5 | medium | — | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Es | 169d ago |
| CVE-2026-2351 | 6.5 | medium | — | The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3. | 169d ago |
| CVE-2026-32054 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download outpu | 169d ago |
| CVE-2026-32053 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalize | 169d ago |
| CVE-2026-32043 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.ru | 169d ago |
| CVE-2026-33428 | 6.5 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-3864 | 6.5 | medium | — | A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifier | 169d ago |
| CVE-2026-32733 | 6.5 | medium | halloy / halloy | Halloy is an IRC application written in Rust. | 169d ago |
| CVE-2026-31926 | 6.5 | medium | — | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | 169d ago |
| CVE-2026-28204 | 6.5 | medium | — | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | 169d ago |
| CVE-2026-30579 | 6.5 | medium | leefish / file thingie | File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). | 169d ago |
| CVE-2026-30578 | 6.5 | medium | leefish / file thingie | File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). | 169d ago |
| CVE-2026-25792 | 6.5 | medium | getgreenshot / greenshot | Greenshot is an open source Windows screenshot utility. | 169d ago |
| CVE-2026-33130 | 6.5 | medium | uptime.kuma / uptime kuma | Uptime Kuma is an open source, self-hosted monitoring tool. | 169d ago |
| CVE-2026-33123 | 6.5 | medium | pypdf project / pypdf | pypdf is a free and open-source pure-python PDF library. | 169d ago |
| CVE-2026-2421 | 6.5 | medium | — | The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up t | 169d ago |
| CVE-2026-33056 | 6.5 | medium | tar project / tar | tar-rs is a tar archive reading/writing library for Rust. | 169d ago |
| CVE-2026-33022 | 6.5 | medium | linuxfoundation / tekton pipelines | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. | 169d ago |
| CVE-2026-32941 | 6.5 | medium | bishopfox / sliver | Sliver is a command and control framework that uses a custom Wireguard netstack. | 170d ago |
| CVE-2026-32937 | 6.5 | medium | free5gc / free5gc | free5GC is an open source 5G core network. | 170d ago |
| CVE-2026-32889 | 6.5 | medium | tinytag / tinytag | tinytag is a Python library for reading audio file metadata. | 170d ago |
| CVE-2026-30891 | 6.5 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-32761 | 6.5 | medium | filebrowser / filebrowser | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within | 170d ago |
| CVE-2026-32758 | 6.5 | medium | filebrowser / filebrowser | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within | 170d ago |
| CVE-2026-32697 | 6.5 | medium | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-29108 | 6.5 | medium | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-32818 | 6.5 | medium | admidio / admidio | Admidio is an open-source user management solution. | 170d ago |
| CVE-2026-33355 | 6.5 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-32036 | 6.5 | medium | openclaw / openclaw | OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote atta | 170d ago |
| CVE-2026-32033 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass | 170d ago |
| CVE-2026-32027 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identiti | 170d ago |
| CVE-2026-32026 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling t | 170d ago |
| CVE-2026-32022 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tool | 170d ago |
| CVE-2026-32021 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowli | 170d ago |
| CVE-2026-32008 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserN | 170d ago |
| CVE-2026-32004 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route clas | 170d ago |
| CVE-2026-28282 | 6.5 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-27935 | 6.5 | medium | discourse / discourse | Discourse is an open-source discussion platform. | 170d ago |
| CVE-2026-33304 | 6.5 | medium | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 170d ago |
| CVE-2026-26136 | 6.5 | medium | microsoft / copilot | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an | 170d ago |
| CVE-2026-26120 | 6.5 | medium | microsoft / bing | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a n | 170d ago |
| CVE-2026-25928 | 6.5 | medium | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 170d ago |
| CVE-2026-25744 | 6.5 | medium | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 170d ago |
| CVE-2026-26940 | 6.5 | medium | elastic / kibana | Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can l | 170d ago |
| CVE-2026-26939 | 6.5 | medium | elastic / kibana | Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoin | 170d ago |
| CVE-2025-67115 | 6.5 | medium | — | A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware | 170d ago |
| CVE-2026-4426 | 6.5 | medium | libarchive / libarchive | A flaw was found in libarchive. | 170d ago |
| CVE-2026-2369 | 6.5 | medium | gnome / libsoup | A flaw was found in libsoup. | 170d ago |
| CVE-2025-14716 | 6.5 | medium | — | Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This | 170d ago |