| CVE-2026-78203 | 7.1 | — | — | — | — | Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attac | 13d ago |
| CVE-2026-77115 | 7.1 | — | — | — | — | Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML w | 14d ago |
| CVE-2026-74713 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vhost_iotlb: bound map allocation in add_range | 14d ago |
| CVE-2026-74703 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Validate T10 PI scatterlist counts | 14d ago |
| CVE-2026-74689 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/atm: fix slab-out-of-bounds read in vcc_se | 14d ago |
| CVE-2026-74684 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: tap: set skb->dev before parsing virtio n | 14d ago |
| CVE-2026-74603 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix board ID over-read The EEPROM bo | 14d ago |
| CVE-2026-74584 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing | 14d ago |
| CVE-2026-63310 | 7.1 | — | — | — | nltk / nltk | NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloade | 14d ago |
| CVE-2026-58003 | 7.1 | — | — | — | — | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.jso | 15d ago |
| CVE-2026-77219 | 7.1 | — | — | — | — | GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to l | 15d ago |
| CVE-2026-30865 | 7.1 | — | — | — | — | Combodo iTop is a web based IT service management tool. | 15d ago |
| CVE-2026-62676 | 7.1 | — | — | — | — | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. | 15d ago |
| CVE-2026-49114 | 7.1 | — | — | — | — | In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's exter | 15d ago |
| CVE-2026-55013 | 7.1 | — | — | — | microsoft / remote help | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing | 16d ago |
| CVE-2026-46355 | 7.1 | — | — | — | — | BigBlueButton is an open-source virtual classroom. | 16d ago |
| CVE-2026-16989 | 7.1 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to impr | 16d ago |
| CVE-2026-54623 | 7.1 | — | — | — | — | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. | 16d ago |
| CVE-2026-54616 | 7.1 | — | — | — | — | NanaZip is the 7-Zip derivative intended for the modern Windows experience. | 16d ago |
| CVE-2026-16925 | 7.1 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to | 16d ago |
| CVE-2026-77081 | 7.1 | — | — | — | n8n / n8n | n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL nod | 17d ago |
| CVE-2026-74019 | 7.1 | — | — | — | — | Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. | 17d ago |
| CVE-2026-68564 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | 17d ago |
| CVE-2026-66673 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. | 17d ago |
| CVE-2026-66616 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. | 17d ago |
| CVE-2026-66615 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. | 17d ago |
| CVE-2026-66614 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. | 17d ago |
| CVE-2026-66612 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions. | 17d ago |
| CVE-2026-66611 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | 17d ago |
| CVE-2026-66607 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | 17d ago |
| CVE-2026-66606 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | 17d ago |
| CVE-2026-66605 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 ver | 17d ago |
| CVE-2026-66604 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. | 17d ago |
| CVE-2026-66598 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. | 17d ago |
| CVE-2026-66597 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | 17d ago |
| CVE-2026-66590 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | 17d ago |
| CVE-2026-66582 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | 17d ago |
| CVE-2026-66581 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | 17d ago |
| CVE-2026-76336 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk role | 17d ago |
| CVE-2026-76333 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role c | 17d ago |
| CVE-2026-76332 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an aut | 17d ago |
| CVE-2026-76330 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an aut | 17d ago |
| CVE-2026-76251 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Sp | 17d ago |
| CVE-2026-68553 | 7.1 | — | — | — | — | Coturn is a free open source implementation of TURN and STUN Server. | 17d ago |
| CVE-2026-54491 | 7.1 | — | — | — | — | Koel is a free, open-source music streaming solution. | 17d ago |
| CVE-2026-62680 | 7.1 | — | — | — | — | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. | 17d ago |
| CVE-2026-17183 | 7.1 | — | — | — | — | An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by m | 17d ago |
| CVE-2026-75147 | 7.1 | — | — | — | — | FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). | 17d ago |
| CVE-2026-49253 | 7.1 | — | — | — | — | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. | 17d ago |
| CVE-2026-76223 | 7.1 | — | — | — | — | ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFI | 17d ago |
| CVE-2026-56088 | 7.1 | — | — | — | dell / openmanage enterprise | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used | 17d ago |
| CVE-2026-73354 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. | 17d ago |
| CVE-2026-73184 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. | 17d ago |
| CVE-2026-73182 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. | 17d ago |
| CVE-2026-66596 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. | 17d ago |
| CVE-2026-61986 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. | 17d ago |
| CVE-2026-49421 | 7.1 | — | — | — | freebsd / freebsd | The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed | 18d ago |
| CVE-2026-19056 | 7.1 | — | — | — | — | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflectin | 18d ago |
| CVE-2026-19055 | 7.1 | — | — | — | — | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before re | 18d ago |
| CVE-2026-16570 | 7.1 | — | — | — | — | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-strin | 18d ago |