| CVE-2026-9130 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that all | 31d ago |
| CVE-2026-9081 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulne | 31d ago |
| CVE-2026-70448 | 7.1 | — | — | — | — | Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) a | 31d ago |
| CVE-2026-71276 | 7.1 | — | — | — | — | Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/tr | 31d ago |
| CVE-2026-71211 | 7.1 | — | — | — | — | MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.p | 32d ago |
| CVE-2026-64576 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_mi | 32d ago |
| CVE-2026-70485 | 7.1 | — | — | — | — | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. | 32d ago |
| CVE-2026-11368 | 7.1 | — | — | — | zephyrproject / zephyr | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning | 32d ago |
| CVE-2026-18806 | 7.1 | — | — | — | — | External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute par | 32d ago |
| CVE-2026-66322 | 7.1 | — | — | — | microsoft / edge chromium | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove | 33d ago |
| CVE-2026-65875 | 7.1 | — | — | — | — | BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. | 34d ago |
| CVE-2026-9856 | 7.1 | — | — | — | — | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writ | 34d ago |
| CVE-2025-71400 | 7.1 | — | — | — | — | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey | 34d ago |
| CVE-2026-67329 | 7.1 | — | — | — | — | @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authoriza | 35d ago |
| CVE-2025-71403 | 7.1 | — | — | — | — | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting abs | 35d ago |
| CVE-2026-13725 | 7.1 | — | — | — | — | The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or | 36d ago |
| CVE-2026-65981 | 7.1 | — | — | — | — | Coturn is a free open source implementation of TURN and STUN Server. | 36d ago |
| CVE-2026-55502 | 7.1 | — | — | — | — | Cloudreve is a self-hosted file management and sharing system. | 37d ago |
| CVE-2026-12945 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs | 37d ago |
| CVE-2026-44097 | 7.1 | — | — | — | — | A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended | 38d ago |
| CVE-2026-14239 | 7.1 | — | — | — | — | The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label tak | 38d ago |
| CVE-2026-17888 | 7.1 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attac | 38d ago |
| CVE-2026-17867 | 7.1 | — | — | — | google / chrome | Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attack | 38d ago |
| CVE-2026-17811 | 7.1 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentiall | 38d ago |
| CVE-2026-17750 | 7.1 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a | 38d ago |
| CVE-2026-17744 | 7.1 | — | — | — | google / chrome | Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attac | 38d ago |
| CVE-2026-17741 | 7.1 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a | 38d ago |
| CVE-2026-14234 | 7.1 | — | — | — | — | The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, al | 39d ago |
| CVE-2026-14976 | 7.1 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the | 39d ago |
| CVE-2026-13442 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owne | 39d ago |
| CVE-2026-16192 | 7.1 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerabil | 39d ago |
| CVE-2026-54545 | 7.1 | — | — | — | — | wakaru is a JavaScript decompiler and unminifier toolkit. | 39d ago |
| CVE-2026-14870 | 7.1 | — | — | — | — | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise | 40d ago |
| CVE-2026-65447 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | 40d ago |
| CVE-2026-65446 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | 40d ago |
| CVE-2026-65443 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. | 40d ago |
| CVE-2026-65441 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | 40d ago |
| CVE-2026-65440 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | 40d ago |
| CVE-2026-65439 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | 40d ago |
| CVE-2026-65438 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | 40d ago |
| CVE-2026-65437 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | 40d ago |
| CVE-2026-61957 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | 40d ago |
| CVE-2026-64725 | 7.1 | — | — | — | apple / ipados | An out-of-bounds write issue was addressed with improved bounds checking. | 40d ago |
| CVE-2026-64692 | 7.1 | — | — | — | apple / ipados | An out-of-bounds read was addressed with improved bounds checking. | 40d ago |
| CVE-2026-64546 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/edid: fix OOB read in drm_parse_tiled_bloc | 40d ago |
| CVE-2026-43813 | 7.1 | — | — | — | apple / ipados | A validation issue was addressed with improved input sanitization. | 40d ago |
| CVE-2026-43771 | 7.1 | — | — | — | apple / macos | A stack overflow was addressed with improved input validation. | 40d ago |
| CVE-2026-43747 | 7.1 | — | — | — | apple / macos | An out-of-bounds read was addressed with improved bounds checking. | 40d ago |
| CVE-2026-43681 | 7.1 | — | — | — | apple / macos | A buffer overflow was addressed with improved bounds checking. | 40d ago |
| CVE-2026-43672 | 7.1 | — | — | — | apple / macos | An authorization issue was addressed with improved state management. | 40d ago |
| CVE-2026-28945 | 7.1 | — | — | — | apple / macos | A permissions issue was addressed with additional sandbox restrictions. | 40d ago |
| CVE-2026-65922 | 7.1 | — | — | — | jfrog / artifactory | An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited reposito | 40d ago |
| CVE-2026-66759 | 7.1 | — | — | — | gimp / gimp | A flaw was found in the file-icns plugin in GIMP. | 40d ago |
| CVE-2026-59558 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | 40d ago |
| CVE-2026-59556 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versio | 40d ago |
| CVE-2026-59553zero day | 7.1 | 0.18% | 1/3 | 3d before | — | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | 40d ago |
| CVE-2026-13726 | 7.1 | — | — | — | — | The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the re | 41d ago |
| CVE-2026-64501 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted | 43d ago |
| CVE-2026-64496 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iio: event: Fix event FIFO reset race `iio_eve | 43d ago |
| CVE-2026-64452 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix NHC entry use-after-free on error | 43d ago |