| CVE-2026-72694 | 7.1 | — | — | — | — | A flaw was found in MRTG. | 26d ago |
| CVE-2026-72910 | 7.1 | — | — | — | — | ERPNext is a free and open source Enterprise Resource Planning tool. | 26d ago |
| CVE-2026-18620 | 7.1 | — | — | — | — | A flaw was found in Data Science Pipelines. | 26d ago |
| CVE-2026-69112 | 7.1 | — | — | — | — | Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and loa | 26d ago |
| CVE-2026-72731 | 7.1 | — | — | — | — | Discourse is an open-source discussion platform. | 26d ago |
| CVE-2026-72690 | 7.1 | — | — | — | — | An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacke | 26d ago |
| CVE-2026-68425 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before r | 26d ago |
| CVE-2026-68420 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: reject optional IPTFS templates in outbo | 26d ago |
| CVE-2026-68402 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when che | 26d ago |
| CVE-2026-68348 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description stri | 26d ago |
| CVE-2026-68293 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on | 26d ago |
| CVE-2026-68262 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix user array stride in pvr_ | 26d ago |
| CVE-2026-68258 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue | 26d ago |
| CVE-2026-68229 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference li | 26d ago |
| CVE-2026-68173 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready() instead of ub-> | 26d ago |
| CVE-2026-68172 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handled unaligned ad | 26d ago |
| CVE-2026-68103 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject mapping a reserved doorbell | 26d ago |
| CVE-2026-21059 | 7.1 | — | — | — | samsung / android | Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local | 27d ago |
| CVE-2026-21058 | 7.1 | — | — | — | samsung / android | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete fil | 27d ago |
| CVE-2026-19389 | 7.1 | — | — | — | — | Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer ( | 27d ago |
| CVE-2026-66061 | 7.1 | — | — | — | — | Home Assistant is open source home automation software focused on local control and privacy. | 29d ago |
| CVE-2026-66060 | 7.1 | — | — | — | — | Home Assistant is open source home automation software focused on local control and privacy. | 29d ago |
| CVE-2025-71412 | 7.1 | — | — | — | — | Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational con | 29d ago |
| CVE-2025-71409 | 7.1 | — | — | — | — | Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC mes | 29d ago |
| CVE-2026-71556 | 7.1 | — | — | — | — | go-git is an extensible git implementation library written in pure Go. | 29d ago |
| CVE-2026-18497 | 7.1 | — | — | — | — | A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used | 29d ago |
| CVE-2026-49746 | 7.1 | — | — | — | — | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel | 30d ago |
| CVE-2026-70635 | 7.1 | — | — | — | timescale / timescaledb | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows auth | 30d ago |
| CVE-2026-5856 | 7.1 | — | — | — | — | Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no | 30d ago |
| CVE-2026-18277 | 7.1 | — | — | — | escriptorium / escriptorium | Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows | 30d ago |
| CVE-2026-66711 | 7.1 | — | — | — | — | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. | 30d ago |
| CVE-2026-66707 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | 30d ago |
| CVE-2026-66705 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. | 30d ago |
| CVE-2026-66702 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. | 30d ago |
| CVE-2026-66694 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. | 30d ago |
| CVE-2026-66690 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | 30d ago |
| CVE-2026-66664 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. | 30d ago |
| CVE-2026-66663 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | 30d ago |
| CVE-2026-66470 | 7.1 | — | — | — | — | Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | 30d ago |
| CVE-2026-66457 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | 30d ago |
| CVE-2026-66440 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | 30d ago |
| CVE-2026-66439 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | 30d ago |
| CVE-2026-65565 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | 30d ago |
| CVE-2026-65560 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | 30d ago |
| CVE-2026-65554 | 7.1 | — | — | — | — | Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. | 30d ago |
| CVE-2026-65545 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | 30d ago |
| CVE-2026-65544 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | 30d ago |
| CVE-2026-65517 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | 30d ago |
| CVE-2026-65515 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | 30d ago |
| CVE-2026-65513 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | 30d ago |
| CVE-2026-65509 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | 30d ago |
| CVE-2026-61982 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | 30d ago |
| CVE-2026-61964 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | 30d ago |
| CVE-2026-61963 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | 30d ago |
| CVE-2026-61961 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | 30d ago |
| CVE-2026-28177 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | 30d ago |
| CVE-2026-28172 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | 30d ago |
| CVE-2026-28143 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | 30d ago |
| CVE-2026-28141 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | 30d ago |
| CVE-2026-28082 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | 30d ago |