| CVE-2026-64436 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp | 43d ago |
| CVE-2026-64422 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes | 43d ago |
| CVE-2026-64412 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null | 43d ago |
| CVE-2026-64411 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name befo | 43d ago |
| CVE-2026-64407 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix out-of-bounds firmwa | 43d ago |
| CVE-2026-64403 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length befor | 43d ago |
| CVE-2026-64379 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 0777 | 43d ago |
| CVE-2026-64339 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: bound bulk IN response lengt | 43d ago |
| CVE-2026-64323 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VA | 43d ago |
| CVE-2026-64318 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: partitions: aix: bound the pp_count scan to th | 43d ago |
| CVE-2026-64317 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink components to | 43d ago |
| CVE-2026-64299 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent out-of-bounds read in glob ma | 43d ago |
| CVE-2026-64298 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: NFSv4: include MAY_WRITE in open permission ma | 43d ago |
| CVE-2026-64284 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure vendor's exit handler runs be | 43d ago |
| CVE-2026-65710 | 7.1 | — | — | — | — | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with | 43d ago |
| CVE-2026-64243 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bou | 43d ago |
| CVE-2026-64237 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size befor | 43d ago |
| CVE-2026-64209 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array a | 43d ago |
| CVE-2026-9765 | 7.1 | — | — | — | — | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. | 43d ago |
| CVE-2026-15968 | 7.1 | — | — | — | progress / moveit transfer | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOV | 44d ago |
| CVE-2026-65918 | 7.1 | — | — | — | linuxfoundation / torchvision | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in | 44d ago |
| CVE-2026-65896 | 7.1 | — | — | — | — | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field | 44d ago |
| CVE-2026-65540 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | 44d ago |
| CVE-2026-65539 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | 44d ago |
| CVE-2026-65511 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme < | 44d ago |
| CVE-2026-65510 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | 44d ago |
| CVE-2026-65494 | 7.1 | — | — | — | — | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | 44d ago |
| CVE-2026-65492 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions. | 44d ago |
| CVE-2026-65488 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | 44d ago |
| CVE-2026-61947 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | 44d ago |
| CVE-2026-61944 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | 44d ago |
| CVE-2026-59517 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | 44d ago |
| CVE-2026-59512 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. | 44d ago |
| CVE-2026-57809 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. | 44d ago |
| CVE-2026-57769 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. | 44d ago |
| CVE-2026-57767 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | 44d ago |
| CVE-2026-57735 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. | 44d ago |
| CVE-2026-57704 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. | 44d ago |
| CVE-2026-57701 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | 44d ago |
| CVE-2026-57699 | 7.1 | — | — | — | — | Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. | 44d ago |
| CVE-2026-57696 | 7.1 | — | — | — | — | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | 44d ago |
| CVE-2026-57626 | 7.1 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. | 44d ago |
| CVE-2026-57428 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. | 44d ago |
| CVE-2026-57427 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | 44d ago |
| CVE-2026-57397 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions. | 44d ago |
| CVE-2026-57374 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. | 44d ago |
| CVE-2026-57370 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. | 44d ago |
| CVE-2026-57367 | 7.1 | — | — | — | — | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | 44d ago |
| CVE-2026-13077 | 7.1 | — | — | — | mongodb / mongodb | A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds hea | 45d ago |
| CVE-2026-64833 | 7.1 | — | — | — | ffmpeg / ffmpeg | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows at | 45d ago |
| CVE-2026-48029 | 7.1 | — | — | — | struktur / libheif | libheif is a HEIF and AVIF file format decoder and encoder. | 45d ago |
| CVE-2026-62565 | 7.1 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). | 46d ago |
| CVE-2026-62557 | 7.1 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). | 46d ago |
| CVE-2026-62469 | 7.1 | — | — | — | oracle / human resources | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Cent | 46d ago |
| CVE-2026-62443 | 7.1 | — | — | — | oracle / e-business suite | Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operatio | 46d ago |
| CVE-2026-61334 | 7.1 | — | — | — | oracle / price protection | Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). | 46d ago |
| CVE-2026-61299 | 7.1 | — | — | — | oracle / e-business suite | Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Interna | 46d ago |
| CVE-2026-61165 | 7.1 | — | — | — | oracle / commerce guided search platform services | Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge) | 46d ago |
| CVE-2026-61162 | 7.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 46d ago |
| CVE-2026-61151 | 7.1 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 46d ago |