| CVE-2026-57317 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. | 71d ago |
| CVE-2026-57314 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. | 71d ago |
| CVE-2026-57312 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. | 71d ago |
| CVE-2026-56072 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions. | 71d ago |
| CVE-2026-56047 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions. | 71d ago |
| CVE-2026-56045 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. | 71d ago |
| CVE-2026-56044 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. | 71d ago |
| CVE-2026-56043 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | 71d ago |
| CVE-2026-56041 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions. | 71d ago |
| CVE-2026-56040 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions. | 71d ago |
| CVE-2026-56039 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. | 71d ago |
| CVE-2026-56011zero day | 7.1 | 0.25% | 1/3 | 7d before | — | Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. | 71d ago |
| CVE-2026-57918 | 7.1 | — | — | — | — | libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/sock | 71d ago |
| CVE-2026-57520 | 7.1 | — | — | — | bitwarden / server | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom us | 72d ago |
| CVE-2026-55700 | 7.1 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 72d ago |
| CVE-2026-49839 | 7.1 | — | — | — | jqlang / jq | jq is a command-line JSON processor. | 72d ago |
| CVE-2026-56071 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. | 72d ago |
| CVE-2026-56051 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. | 72d ago |
| CVE-2026-56042 | 7.1 | — | — | — | — | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | 72d ago |
| CVE-2026-56014 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. | 72d ago |
| CVE-2026-56006 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions. | 72d ago |
| CVE-2026-56005 | 7.1 | — | — | — | — | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. | 72d ago |
| CVE-2026-47151 | 7.1 | — | — | — | silabs / emberznet | In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Doo | 72d ago |
| CVE-2026-47150 | 7.1 | — | — | — | silabs / emberznet | In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table w | 72d ago |
| CVE-2026-47147 | 7.1 | — | — | — | silabs / emberznet | In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. | 72d ago |
| CVE-2026-53255 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV befo | 72d ago |
| CVE-2026-53253 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before pa | 72d ago |
| CVE-2026-53223 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue | 72d ago |
| CVE-2026-53205 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log | 72d ago |
| CVE-2026-53203 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add buffer overflow check in MS ge | 72d ago |
| CVE-2026-53187 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate cpu_id against nr_cpu_ids | 72d ago |
| CVE-2026-53179 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix buffer over-read in rt | 72d ago |
| CVE-2026-53149 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to b | 72d ago |
| CVE-2026-53146 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to ac | 72d ago |
| CVE-2026-53138 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk | 72d ago |
| CVE-2026-53132 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queu | 72d ago |
| CVE-2026-9154 | 7.1 | — | — | — | gnu / sed | Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to w | 73d ago |
| CVE-2026-54070 | 7.1 | — | — | — | — | SiYuan is an open-source personal knowledge management system. | 73d ago |
| CVE-2026-52808 | 7.1 | — | — | — | — | Gogs is an open source self-hosted Git service. | 73d ago |
| CVE-2026-53076 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix OOB in pcpu_init_value An out-of-boun | 73d ago |
| CVE-2026-53068 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/komeda: fix integer overflow in AFBC frame | 73d ago |
| CVE-2026-53044 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fa | 73d ago |
| CVE-2026-53041 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix listxattr handling when the buffer | 73d ago |
| CVE-2026-53040 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate bg_bits during freefrag scan [ | 73d ago |
| CVE-2026-52988 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: join hook list via splic | 73d ago |
| CVE-2026-52953 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix oops due to out of scope acces | 73d ago |
| CVE-2026-57303 | 7.1 | — | — | — | jenkins / assembla | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) att | 73d ago |
| CVE-2026-56257 | 7.1 | — | — | — | — | Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_ap | 73d ago |
| CVE-2026-56256 | 7.1 | — | — | — | — | Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. | 73d ago |
| CVE-2026-56244 | 7.1 | — | — | — | — | Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insuffici | 73d ago |
| CVE-2026-52942 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set | 74d ago |
| CVE-2026-52917 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_ | 74d ago |
| CVE-2026-52915 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option l | 74d ago |
| CVE-2026-54761 | 7.1 | — | — | — | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 74d ago |
| CVE-2026-54318 | 7.1 | — | — | — | home-assistant / home assistant companion | Home Assistant is open source home automation software that puts local control and privacy first. | 74d ago |
| CVE-2026-54012 | 7.1 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 74d ago |
| CVE-2026-56275 | 7.1 | — | — | — | flowiseai / flowise | Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows att | 74d ago |
| CVE-2026-8172 | 7.1 | — | — | — | — | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecti | 75d ago |
| CVE-2026-10658 | 7.1 | — | — | — | zephyrproject / zephyr | bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is se | 75d ago |
| CVE-2026-10651 | 7.1 | — | — | — | zephyrproject / zephyr | bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the | 75d ago |