| CVE-2026-56314 | 7.1 | — | — | — | — | Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allo | 75d ago |
| CVE-2026-56280 | 7.1 | — | — | — | — | Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-onl | 75d ago |
| CVE-2026-50146 | 7.1 | — | — | — | astro / astro | Astro is a web framework. | 75d ago |
| CVE-2026-54290 | 7.1 | — | — | — | — | Hono is a Web application framework that provides support for any JavaScript runtime. | 75d ago |
| CVE-2026-41049 | 7.1 | — | — | — | presire / qsnapper | Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allo | 75d ago |
| CVE-2026-41048 | 7.1 | — | — | — | presire / qsnapper | Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a lo | 75d ago |
| CVE-2026-6858 | 7.1 | — | — | — | — | The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing una | 76d ago |
| CVE-2026-4259 | 7.1 | — | — | — | — | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before | 76d ago |
| CVE-2026-49346 | 7.1 | — | — | — | struktur / libde265 | libde265 is an open source implementation of the h.265 video codec. | 78d ago |
| CVE-2026-49295 | 7.1 | — | — | — | struktur / libde265 | libde265 is an open source implementation of the h.265 video codec. | 78d ago |
| CVE-2026-49339 | 7.1 | — | — | — | — | gonic is a music streaming server / free-software subsonic server API implementation. | 78d ago |
| CVE-2026-49338 | 7.1 | — | — | — | — | gonic is a music streaming server / free-software subsonic server API implementation. | 78d ago |
| CVE-2019-25761 | 7.1 | — | — | — | joomboost / joomcrm | Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to exe | 78d ago |
| CVE-2019-25759 | 7.1 | — | — | — | wdmtech / vbizz | Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execu | 78d ago |
| CVE-2019-25757 | 7.1 | — | — | — | wdmtech / vwishlist | Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbi | 78d ago |
| CVE-2019-25749 | 7.1 | — | — | — | cmsjunkie / j-cruiseportal | Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute | 78d ago |
| CVE-2026-56211 | 7.1 | — | — | — | — | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. | 78d ago |
| CVE-2026-56210 | 7.1 | — | — | — | — | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. | 78d ago |
| CVE-2026-56209 | 7.1 | — | — | — | — | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. | 78d ago |
| CVE-2017-20265 | 7.1 | — | — | — | pulseextensions / flip wall | Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to e | 78d ago |
| CVE-2017-20264 | 7.1 | — | — | — | pulseextensions / sponsor wall | Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers t | 78d ago |
| CVE-2026-53915 | 7.1 | — | — | — | jetbrains / goland | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | 78d ago |
| CVE-2026-48759 | 7.1 | — | — | — | — | TypeBot is a chatbot builder tool. | 80d ago |
| CVE-2026-48997 | 7.1 | — | — | — | — | e107 is a content management system (CMS). | 80d ago |
| CVE-2026-35066 | 7.1 | — | — | — | dell / powerflex manager | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. | 80d ago |
| CVE-2026-40720 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | 80d ago |
| CVE-2026-10641 | 7.1 | — | — | — | zephyrproject / zephyr | Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c | 80d ago |
| CVE-2025-69140 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions. | 80d ago |
| CVE-2025-68524 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions. | 80d ago |
| CVE-2026-9570 | 7.1 | — | — | — | — | The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inl | 80d ago |
| CVE-2026-8089 | 7.1 | — | — | — | — | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress pl | 80d ago |
| CVE-2026-54195 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. | 80d ago |
| CVE-2026-54192 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions. | 80d ago |
| CVE-2026-54189 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. | 80d ago |
| CVE-2026-54188 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. | 80d ago |
| CVE-2026-49778 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions. | 80d ago |
| CVE-2026-49074 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions. | 80d ago |
| CVE-2026-48869 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions. | 80d ago |
| CVE-2026-42385 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions. | 80d ago |
| CVE-2026-41557 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions. | 80d ago |
| CVE-2026-40765 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions. | 80d ago |
| CVE-2026-39597 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions. | 80d ago |
| CVE-2026-39548 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions. | 80d ago |
| CVE-2026-22339 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WPJobster <= 6.3.5 versions. | 80d ago |
| CVE-2026-22329 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Skillate <= 1.2.10 versions. | 80d ago |
| CVE-2026-22328 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions. | 80d ago |
| CVE-2025-69151 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions. | 80d ago |
| CVE-2025-69104 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions. | 80d ago |
| CVE-2025-59560 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions. | 80d ago |
| CVE-2025-31013 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo | 80d ago |
| CVE-2024-49269 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions. | 80d ago |
| CVE-2026-46932 | 7.1 | — | — | — | oracle / enterprise asset management | Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Op | 80d ago |
| CVE-2026-46914 | 7.1 | — | — | — | oracle / solaris | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). | 80d ago |
| CVE-2026-53865 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspa | 81d ago |
| CVE-2026-53863 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unva | 81d ago |
| CVE-2026-53858 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIREC | 81d ago |
| CVE-2026-53846 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env | 81d ago |
| CVE-2026-53842 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to | 81d ago |
| CVE-2026-53840 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that for | 81d ago |
| CVE-2026-54198 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions. | 81d ago |