| CVE-2026-85451 | 7.1 | — | — | — | — | MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component | 2d ago |
| CVE-2026-53728 | 7.1 | — | — | — | — | Medplum is a developer platform that enables development of healthcare apps. | 2d ago |
| CVE-2026-85395 | 7.1 | — | — | — | — | UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing | 2d ago |
| CVE-2026-85390 | 7.1 | — | — | — | — | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check- | 2d ago |
| CVE-2026-84848 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | 2d ago |
| CVE-2026-84836 | 7.1 | — | — | — | — | Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions. | 2d ago |
| CVE-2026-84812 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | 2d ago |
| CVE-2026-84765 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. | 2d ago |
| CVE-2026-84763 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions. | 2d ago |
| CVE-2026-84756 | 7.1 | — | — | — | — | Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions. | 2d ago |
| CVE-2026-81776 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | 2d ago |
| CVE-2026-81773 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | 2d ago |
| CVE-2026-81300 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | 2d ago |
| CVE-2026-81295 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. | 2d ago |
| CVE-2026-81292 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. | 2d ago |
| CVE-2026-83961 | 7.1 | — | — | — | — | ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. | 2d ago |
| CVE-2026-84989 | 7.1 | — | — | — | — | ntopng is a web-based network traffic monitoring application. | 2d ago |
| CVE-2026-85164 | 7.1 | — | — | — | — | WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImage | 3d ago |
| CVE-2026-80749 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/connector/hdmi: Fix out of bounds memory r | 3d ago |
| CVE-2026-80741 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read on empty messa | 3d ago |
| CVE-2026-84667 | 7.1 | — | — | — | — | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler d | 3d ago |
| CVE-2026-14199 | 7.1 | — | — | — | — | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater | 3d ago |
| CVE-2026-84800 | 7.1 | — | — | — | — | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::a | 4d ago |
| CVE-2026-84798 | 7.1 | — | — | — | — | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsContro | 4d ago |
| CVE-2026-84794 | 7.1 | — | — | — | — | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supp | 4d ago |
| CVE-2026-84759 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions. | 4d ago |
| CVE-2026-81775 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. | 4d ago |
| CVE-2026-81771 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | 4d ago |
| CVE-2026-81770 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | 4d ago |
| CVE-2026-81289 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 vers | 4d ago |
| CVE-2026-81288 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | 4d ago |
| CVE-2026-82883 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login | 4d ago |
| CVE-2026-19723 | 7.1 | — | — | — | — | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a val | 4d ago |
| CVE-2026-19453 | 7.1 | — | — | — | — | The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserve | 4d ago |
| CVE-2026-12865 | 7.1 | — | — | — | — | The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting | 4d ago |
| CVE-2026-73764 | 7.1 | — | — | — | hpe / arubaos-cx | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an un | 4d ago |
| CVE-2026-73763 | 7.1 | — | — | — | — | A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute | 4d ago |
| CVE-2026-73724 | 7.1 | — | — | — | arubanetworks / fabric composer | Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. | 4d ago |
| CVE-2026-73723 | 7.1 | — | — | — | arubanetworks / fabric composer | A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Compose | 4d ago |
| CVE-2026-84201 | 7.1 | — | — | — | — | appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch | 4d ago |
| CVE-2026-18780 | 7.1 | — | — | — | — | Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. | 4d ago |
| CVE-2026-84192 | 7.1 | — | — | — | — | LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SN | 5d ago |
| CVE-2026-82392 | 7.1 | — | — | — | — | pnpm is a package manager. | 5d ago |
| CVE-2026-82229 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | 5d ago |
| CVE-2026-82224 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. | 5d ago |
| CVE-2026-82221 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. | 5d ago |
| CVE-2026-81768 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | 5d ago |
| CVE-2026-81765 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | 5d ago |
| CVE-2026-81764 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | 5d ago |
| CVE-2026-81298 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | 5d ago |
| CVE-2026-81291 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. | 5d ago |
| CVE-2026-81290 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | 5d ago |
| CVE-2026-79747 | 7.1 | — | — | — | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separa | 5d ago |
| CVE-2026-79745 | 7.1 | — | — | — | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separa | 5d ago |
| CVE-2026-82659 | 7.1 | — | — | — | — | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, a | 6d ago |
| CVE-2026-82648 | 7.1 | — | — | — | — | WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that | 6d ago |
| CVE-2026-14307 | 7.1 | — | — | — | — | The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflectin | 7d ago |
| CVE-2026-82455 | 7.1 | — | — | — | — | RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. | 7d ago |
| CVE-2026-81533 | 7.1 | — | — | — | — | An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL | 8d ago |
| CVE-2026-82280 | 7.1 | — | — | — | — | Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any | 8d ago |