| CVE-2026-55066 | 7.1 | — | — | — | — | Vikunja is an open-source self-hosted task management platform. | 8d ago |
| CVE-2026-81760 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock J | 8d ago |
| CVE-2026-82246 | 7.1 | — | — | — | — | Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint th | 9d ago |
| CVE-2026-82241 | 7.1 | — | — | — | — | Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 1 | 9d ago |
| CVE-2026-80685 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mm/util: don't read __page_2 for order-1 folio | 9d ago |
| CVE-2026-80675 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libbpf: Reject non-exclusive metadata maps in | 9d ago |
| CVE-2026-80665 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if kvm_translate_vn | 9d ago |
| CVE-2026-80663 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tools/power/x86/intel-speed-select: Harden dae | 9d ago |
| CVE-2026-80662 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capab | 9d ago |
| CVE-2026-38821 | 7.1 | — | — | — | — | A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker | 9d ago |
| CVE-2026-54085 | 7.1 | — | — | — | — | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud worklo | 9d ago |
| CVE-2026-81934 | 7.1 | — | — | — | — | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pen | 9d ago |
| CVE-2026-81838 | 7.1 | — | — | — | amazon / diagram-as-code | A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0. | 9d ago |
| CVE-2026-81529 | 7.1 | — | — | — | — | Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the Mon | 9d ago |
| CVE-2026-81727 | 7.1 | — | — | — | nltk / nltk | NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and D | 9d ago |
| CVE-2026-78293 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | 10d ago |
| CVE-2026-78289 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. | 10d ago |
| CVE-2026-78283 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | 10d ago |
| CVE-2026-78281 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | 10d ago |
| CVE-2026-78261 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | 10d ago |
| CVE-2026-47849 | 7.1 | — | — | — | vmware / spring data rest | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 J | 10d ago |
| CVE-2026-77611 | 7.1 | — | — | — | — | SeaweedFS is a distributed storage system for files and blobs. | 10d ago |
| CVE-2025-29419 | 7.1 | — | — | — | — | CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. | 10d ago |
| CVE-2026-80426 | 7.1 | — | — | — | — | FiftyOne renders a dataset field's description as markup. | 10d ago |
| CVE-2026-80555 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Free all memory if cp_init() fa | 10d ago |
| CVE-2026-80538 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfs: propagate errors from xfs_rtginode_load x | 10d ago |
| CVE-2026-80530 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing | 10d ago |
| CVE-2026-80523 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: clk: spacemit: k3: set hdma clock as critical | 10d ago |
| CVE-2026-80350 | 7.1 | — | — | — | — | OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 | 11d ago |
| CVE-2026-80346 | 7.1 | — | — | — | — | StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. | 11d ago |
| CVE-2026-78892 | 7.1 | — | — | — | google / chrome | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attack | 11d ago |
| CVE-2026-68515 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 11d ago |
| CVE-2026-68513 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 11d ago |
| CVE-2026-59981 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion | 11d ago |
| CVE-2026-79788 | 7.1 | — | — | — | — | In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action | 11d ago |
| CVE-2026-79786 | 7.1 | — | — | — | — | Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect U | 11d ago |
| CVE-2026-55609 | 7.1 | — | — | — | — | sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in subl | 11d ago |
| CVE-2026-59982 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 11d ago |
| CVE-2026-59189 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 11d ago |
| CVE-2026-59187 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 11d ago |
| CVE-2026-59186 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 11d ago |
| CVE-2026-59184 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 11d ago |
| CVE-2026-55540 | 7.1 | — | — | — | — | PraisonAI is a multi-agent teams system. | 11d ago |
| CVE-2026-55537 | 7.1 | — | — | — | — | PraisonAI is a multi-agent teams system. | 11d ago |
| CVE-2026-55527 | 7.1 | — | — | — | — | PraisonAI is a multi-agent teams system. | 11d ago |
| CVE-2026-78282 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | 12d ago |
| CVE-2026-78264 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | 12d ago |
| CVE-2026-78263 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | 12d ago |
| CVE-2026-32556 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | 12d ago |
| CVE-2026-75369 | 7.1 | — | — | — | — | An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot Acu | 12d ago |
| CVE-2026-71505 | 7.1 | — | — | — | — | Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site | 12d ago |
| CVE-2026-19685 | 7.1 | — | — | — | — | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-value | 12d ago |
| CVE-2026-66623 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | 13d ago |
| CVE-2026-66610 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. | 13d ago |
| CVE-2026-66599 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | 13d ago |
| CVE-2026-66584 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | 13d ago |
| CVE-2026-32476 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | 13d ago |
| CVE-2026-28190 | 7.1 | — | — | — | — | Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. | 13d ago |
| CVE-2026-28166 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions. | 13d ago |
| CVE-2026-28162 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | 13d ago |