| CVE-2026-72629 | 7.1 | — | — | — | elastic / kibana | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access v | 23d ago |
| CVE-2026-59714 | 7.1 | — | — | — | — | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. | 23d ago |
| CVE-2026-48099 | 7.1 | — | — | — | — | WsgiDAV is a generic and extendable WebDAV server based on WSGI. | 23d ago |
| CVE-2026-16896 | 7.1 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due | 23d ago |
| CVE-2026-13365 | 7.1 | — | — | — | ibm / planning analytics local | IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacke | 23d ago |
| CVE-2026-73266 | 7.1 | — | — | — | — | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). | 23d ago |
| CVE-2026-58437 | 7.1 | — | — | — | — | Repository Visibility Manipulation via Git Push Options | 23d ago |
| CVE-2026-58416 | 7.1 | — | — | — | — | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard | 23d ago |
| CVE-2026-68453 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_ciphe | 23d ago |
| CVE-2026-63426 | 7.1 | — | — | — | — | During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could | 23d ago |
| CVE-2026-53802 | 7.1 | — | — | — | samba / rsync | rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to | 23d ago |
| CVE-2026-53785 | 7.1 | — | — | — | — | rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside t | 23d ago |
| CVE-2026-53784 | 7.1 | — | — | — | samba / rsync | rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the | 23d ago |
| CVE-2026-28154 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Sam | 23d ago |
| CVE-2026-12036 | 7.1 | — | — | — | — | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commer | 23d ago |
| CVE-2026-66700 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | 23d ago |
| CVE-2026-66698 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. | 23d ago |
| CVE-2026-66697 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10. | 23d ago |
| CVE-2026-66655 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. | 23d ago |
| CVE-2026-66468 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | 23d ago |
| CVE-2026-66449 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions. | 23d ago |
| CVE-2026-66429 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | 23d ago |
| CVE-2026-66426 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. | 23d ago |
| CVE-2026-65580 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. | 23d ago |
| CVE-2026-61974 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. | 23d ago |
| CVE-2026-61965 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. | 23d ago |
| CVE-2026-61960 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions. | 23d ago |
| CVE-2026-28187 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211. | 23d ago |
| CVE-2026-28175 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | 23d ago |
| CVE-2026-28173 | 7.1 | — | — | — | — | Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. | 23d ago |
| CVE-2026-28170 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. | 23d ago |
| CVE-2026-28158 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. | 23d ago |
| CVE-2026-28004 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | 23d ago |
| CVE-2026-28003 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | 23d ago |
| CVE-2026-27539 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions. | 23d ago |
| CVE-2026-27536 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. | 23d ago |
| CVE-2026-27535 | 7.1 | — | — | — | — | Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. | 23d ago |
| CVE-2026-73617 | 7.1 | — | — | — | — | Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-s | 23d ago |
| CVE-2026-73331 | 7.1 | — | — | — | — | CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with p | 24d ago |
| CVE-2026-16494 | 7.1 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 | 24d ago |
| CVE-2026-17248 | 7.1 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to impro | 24d ago |
| CVE-2026-73291 | 7.1 | — | — | — | — | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. | 24d ago |
| CVE-2026-16294 | 7.1 | — | — | — | — | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast E | 25d ago |
| CVE-2026-68447 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkp | 25d ago |
| CVE-2026-63177 | 7.1 | — | — | — | — | Malcolm is a network traffic analysis tool suite. | 25d ago |
| CVE-2026-71474 | 7.1 | — | — | — | redhat / advanced cluster management for kubernetes | A flaw was found in insights-client. | 25d ago |
| CVE-2026-18711 | 7.1 | — | — | — | — | An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileg | 25d ago |
| CVE-2026-18694 | 7.1 | — | — | — | — | An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges t | 25d ago |
| CVE-2026-18688 | 7.1 | — | — | — | — | An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds m | 25d ago |
| CVE-2026-18687 | 7.1 | — | — | — | — | MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain reques | 25d ago |
| CVE-2026-65675 | 7.1 | — | — | — | microsoft / github copilot chat | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a sec | 25d ago |
| CVE-2026-48442 | 7.1 | — | — | — | adobe / c2pa | CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trave | 25d ago |
| CVE-2026-53416 | 7.1 | — | — | — | — | Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure vi | 25d ago |
| CVE-2026-48495 | 7.1 | — | — | — | — | TypeBot is a chatbot builder tool. | 25d ago |
| CVE-2026-42142 | 7.1 | — | — | — | — | TypeBot is a chatbot builder tool. | 25d ago |
| CVE-2026-18640 | 7.1 | — | — | — | — | The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDI | 25d ago |
| CVE-2026-72609 | 7.1 | — | — | — | — | An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta | 25d ago |
| CVE-2026-72607 | 7.1 | — | — | — | — | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticat | 25d ago |
| CVE-2026-72547 | 7.1 | — | — | — | — | An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated eve | 25d ago |
| CVE-2026-72546 | 7.1 | — | — | — | — | An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated eve | 25d ago |