| CVE-2026-68567 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | 18d ago |
| CVE-2026-66667 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | 18d ago |
| CVE-2026-66633 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | 18d ago |
| CVE-2026-66629zero day | 7.1 | 0.24% | 1/3 | same day | — | Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. | 18d ago |
| CVE-2026-66621 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG | 18d ago |
| CVE-2026-48798 | 7.1 | — | — | — | — | SSH.NET is a Secure Shell (SSH) library for .NET. | 18d ago |
| CVE-2026-32547 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | 18d ago |
| CVE-2026-32333 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. | 18d ago |
| CVE-2026-28569 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. | 18d ago |
| CVE-2026-28568 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | 18d ago |
| CVE-2026-75846 | 7.1 | — | — | — | — | ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE | 19d ago |
| CVE-2026-75844 | 7.1 | — | — | — | — | ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command | 19d ago |
| CVE-2026-75830 | 7.1 | — | — | — | — | grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnera | 19d ago |
| CVE-2026-74905 | 7.1 | — | — | — | — | SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in ke | 19d ago |
| CVE-2026-69148 | 7.1 | — | — | — | — | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. | 19d ago |
| CVE-2026-75109 | 7.1 | — | — | — | — | Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. | 19d ago |
| CVE-2026-54356 | 7.1 | — | — | — | — | Budibase is an open-source low-code platform. | 19d ago |
| CVE-2026-19589 | 7.1 | — | — | — | — | Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file s | 19d ago |
| CVE-2026-19650 | 7.1 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0. | 19d ago |
| CVE-2026-75050 | 7.1 | — | — | — | — | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | 19d ago |
| CVE-2026-59909 | 7.1 | — | — | — | dell / objectscale | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. | 19d ago |
| CVE-2026-75002 | 7.1 | — | — | — | — | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization c | 19d ago |
| CVE-2026-74579 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for par | 20d ago |
| CVE-2026-74578 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous pro | 21d ago |
| CVE-2026-74567 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in keyring_get_ke | 21d ago |
| CVE-2026-74564 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_hashlimit: validate hashtable su | 21d ago |
| CVE-2026-74507 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payl | 21d ago |
| CVE-2026-74485 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: reject a flag character as the fi | 21d ago |
| CVE-2026-74364 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject exclusive maps as inner maps in ma | 22d ago |
| CVE-2026-74349 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shorter than a clu | 22d ago |
| CVE-2026-74295 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: hdac_hdmi: Validate written enum | 22d ago |
| CVE-2026-74292 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: tegra: tegra210_ahub: Validate written e | 22d ago |
| CVE-2026-72471 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent potential lcn remains uninit | 22d ago |
| CVE-2026-72460 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: apparmor: check label build before no_new_priv | 22d ago |
| CVE-2026-72455 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix uninitialised pointer passed to | 22d ago |
| CVE-2026-72440 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: md/raid1: fix writes_pending and barrier refer | 22d ago |
| CVE-2026-72425 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ice: fix FDIR CTRL VSI resource leak in ice_re | 22d ago |
| CVE-2026-72415 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Validate written enum value in ge_ | 22d ago |
| CVE-2026-72397 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) honor vrm_version in pmbus | 22d ago |
| CVE-2026-72395 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing events to regulator | 22d ago |
| CVE-2026-72364 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix writeback error handling Fix the er | 22d ago |
| CVE-2026-72297 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: atm: reject out-of-range traffic classes | 22d ago |
| CVE-2026-72284 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ignore pending PV EOI if the vCPU ha | 22d ago |
| CVE-2026-72280 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Drop bogus WARN for write to Z | 22d ago |
| CVE-2026-72213 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb cgroup rsvd charge/unc | 22d ago |
| CVE-2026-72175 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix make_uffd_wp_huge_pte() | 22d ago |
| CVE-2026-72143 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Restore SST-PP control to | 22d ago |
| CVE-2026-72116 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops after device rem | 22d ago |
| CVE-2026-72099 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twic | 22d ago |
| CVE-2026-72089 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Reject firmware log with size smal | 22d ago |
| CVE-2026-72049 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ieee802154: admin-gate legacy LLSEC dump opera | 22d ago |
| CVE-2026-72043 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing dirty page tracking in | 22d ago |
| CVE-2026-19908 | 7.1 | — | — | — | — | PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. | 22d ago |
| CVE-2025-7639 | 7.1 | — | — | — | — | The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege t | 22d ago |
| CVE-2026-19680 | 7.1 | — | — | — | tenable / security center | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data f | 22d ago |
| CVE-2026-19483 | 7.1 | — | — | — | ibm / storage scale | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IB | 23d ago |
| CVE-2026-72675 | 7.1 | — | — | — | elastic / kibana | Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data mod | 23d ago |
| CVE-2026-72643 | 7.1 | — | — | — | elastic / kibana | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when o | 23d ago |
| CVE-2026-72632 | 7.1 | — | — | — | elastic / kibana | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). | 23d ago |
| CVE-2026-72630 | 7.1 | — | — | — | elastic / kibana | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122) | 23d ago |