| CVE-2026-50163 | 7.1 | — | — | — | — | oras-go is a Go library for managing OCI artifacts. | 50d ago |
| CVE-2026-49284 | 7.1 | — | — | — | simplesamlphp / simplesamlphp | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. | 50d ago |
| CVE-2026-16118 | 7.1 | — | — | — | — | A flaw was found in xdgmime. | 50d ago |
| CVE-2026-62387 | 7.1 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its def | 51d ago |
| CVE-2026-62219 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds val | 51d ago |
| CVE-2026-62212 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. | 51d ago |
| CVE-2026-62206 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. | 51d ago |
| CVE-2026-62205 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams m | 51d ago |
| CVE-2024-34268 | 7.1 | — | — | — | — | EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to | 51d ago |
| CVE-2026-46336 | 7.1 | — | — | — | — | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focus | 51d ago |
| CVE-2026-59867 | 7.1 | — | — | — | — | Kiota is an OpenAPI based HTTP Client code generator. | 51d ago |
| CVE-2026-12978 | 7.1 | — | — | — | — | The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into | 52d ago |
| CVE-2026-52890 | 7.1 | — | — | — | — | Wekan is open source kanban built with Meteor. | 52d ago |
| CVE-2026-52869 | 7.1 | — | — | — | lfprojects / mcp python sdk | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). | 52d ago |
| CVE-2026-50144 | 7.1 | — | — | — | — | ncnn is a high-performance neural network inference framework optimized for the mobile platform. | 52d ago |
| CVE-2026-59255 | 7.1 | — | — | — | — | BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-no | 52d ago |
| CVE-2026-53515 | 7.1 | — | — | — | better-auth / better-auth\/sso | Better Auth is an authentication and authorization library for TypeScript. | 52d ago |
| CVE-2026-54563 | 7.1 | — | — | — | — | Cloudreve is a self-hosted file management and sharing system. | 52d ago |
| CVE-2026-15641 | 7.1 | — | — | — | devolutions / devolutions server | Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an | 53d ago |
| CVE-2026-58529 | 7.1 | — | — | — | microsoft / windows 11 26h1 | Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose infor | 53d ago |
| CVE-2026-57101 | 7.1 | — | — | — | microsoft / visual studio code | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows | 53d ago |
| CVE-2026-55122 | 7.1 | — | — | — | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 53d ago |
| CVE-2026-50682 | 7.1 | — | — | — | microsoft / windows 10 21h2 | Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. | 53d ago |
| CVE-2026-50465 | 7.1 | — | — | — | microsoft / windows 11 24h2 | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | 53d ago |
| CVE-2026-50451 | 7.1 | — | — | — | microsoft / windows 10 1607 | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authori | 53d ago |
| CVE-2026-50428 | 7.1 | — | — | — | microsoft / windows 11 26h1 | Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to | 53d ago |
| CVE-2026-56193 | 7.1 | — | — | — | microsoft / 365 apps | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 53d ago |
| CVE-2026-55144 | 7.1 | — | — | — | microsoft / windows 11 24h2 | Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. | 53d ago |
| CVE-2026-50354 | 7.1 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49791 | 7.1 | — | — | — | microsoft / windows 10 1607 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) | 53d ago |
| CVE-2026-49165 | 7.1 | — | — | — | microsoft / windows 10 1607 | Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information | 53d ago |
| CVE-2026-55651 | 7.1 | — | — | — | — | Easy!Appointments is a self hosted appointment scheduler. | 53d ago |
| CVE-2026-10671 | 7.1 | — | — | — | zephyrproject / zephyr | In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used | 53d ago |
| CVE-2026-62191 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handl | 54d ago |
| CVE-2026-62189 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows | 54d ago |
| CVE-2026-58410 | 7.1 | — | — | — | — | ChurchCRM is an open-source church management system. | 54d ago |
| CVE-2026-61956 | 7.1 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basala | 54d ago |
| CVE-2026-59516 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Crea | 54d ago |
| CVE-2026-57816 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Fu | 54d ago |
| CVE-2026-57814 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Y | 54d ago |
| CVE-2026-57745 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Th | 54d ago |
| CVE-2026-57741 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing N | 54d ago |
| CVE-2026-57740 | 7.1 | — | — | — | — | Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exp | 54d ago |
| CVE-2026-57734 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 54d ago |
| CVE-2026-57733 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 54d ago |
| CVE-2026-57732 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 54d ago |
| CVE-2026-57728 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Fl | 54d ago |
| CVE-2026-57725 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirk | 54d ago |
| CVE-2026-57718 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited El | 54d ago |
| CVE-2026-57715 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinj | 54d ago |
| CVE-2026-57712 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOO | 54d ago |
| CVE-2026-57708 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Co | 54d ago |
| CVE-2026-57706 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. | 54d ago |
| CVE-2026-57695 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter | 54d ago |
| CVE-2026-57668 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Fo | 54d ago |
| CVE-2026-57423 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome | 54d ago |
| CVE-2026-57422 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme B | 54d ago |
| CVE-2026-57421 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CR | 54d ago |
| CVE-2026-57417 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme Car | 54d ago |
| CVE-2026-57416 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround S | 54d ago |