| CVE-2026-46321 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun | 88d ago |
| CVE-2016-20063 | 7.1 | — | — | — | — | Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute a | 88d ago |
| CVE-2026-24349 | 7.1 | — | — | — | siemens / simatic wincc unified pc runtime | A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified | 88d ago |
| CVE-2026-41845 | 7.1 | — | — | — | vmware / spring framework | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in | 89d ago |
| CVE-2026-44751 | 7.1 | — | — | — | — | Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an atta | 89d ago |
| CVE-2026-49141 | 7.1 | — | — | — | — | WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows a | 89d ago |
| CVE-2026-48507 | 7.1 | — | — | — | snipeitapp / snipe-it | Snipe-IT is an IT asset/license management system. | 89d ago |
| CVE-2026-46293 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds ac | 89d ago |
| CVE-2026-46657 | 7.1 | — | — | — | — | Bludit is a content management system. | 89d ago |
| CVE-2026-34194 | 7.1 | — | — | — | — | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement o | 89d ago |
| CVE-2026-11422 | 7.1 | — | — | — | — | Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDr | 92d ago |
| CVE-2026-21037 | 7.1 | — | — | — | samsung / members | Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary | 92d ago |
| CVE-2026-21033 | 7.1 | — | — | — | samsung / assistant | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to versi | 92d ago |
| CVE-2026-21032 | 7.1 | — | — | — | samsung / assistant | Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version | 92d ago |
| CVE-2026-11269 | 7.1 | — | — | — | google / chrome | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privil | 93d ago |
| CVE-2025-67448 | 7.1 | — | — | — | — | The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. | 93d ago |
| CVE-2026-36176 | 7.1 | — | — | — | — | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the se | 93d ago |
| CVE-2026-10840 | 7.1 | — | — | — | — | A flaw was found in the OpenShift Pipelines operator. | 93d ago |
| CVE-2025-52612 | 7.1 | — | — | — | hcltech / icontrol | HCL iControl was affected by Export CSV - CSV Injection vulnerability. | 93d ago |
| CVE-2026-8874 | 7.1 | — | — | — | securly / securly | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering r | 94d ago |
| CVE-2026-36606 | 7.1 | — | — | — | — | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DE | 94d ago |
| CVE-2025-15654 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes P | 94d ago |
| CVE-2026-31942 | 7.1 | — | — | — | librechat / librechat | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. | 95d ago |
| CVE-2026-8036 | 7.1 | — | — | — | ni / ni-pal | Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potenti | 95d ago |
| CVE-2026-8035 | 7.1 | — | — | — | ni / ni-pal | Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of ser | 95d ago |
| CVE-2026-42654 | 7.1 | — | — | — | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce | 95d ago |
| CVE-2026-42685 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job | 95d ago |
| CVE-2025-52759 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudi | 95d ago |
| CVE-2026-24090 | 7.1 | — | — | — | qualcomm / snapdragon 460 mobile platform firmware | Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. | 96d ago |
| CVE-2018-25431 | 7.1 | — | — | — | — | No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoi | 96d ago |
| CVE-2018-25430 | 7.1 | — | — | — | — | Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary S | 96d ago |
| CVE-2018-25429 | 7.1 | — | — | — | — | Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary S | 96d ago |
| CVE-2026-49135 | 7.1 | — | — | — | — | CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to | 96d ago |
| CVE-2026-49134 | 7.1 | — | — | — | — | CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local atta | 96d ago |
| CVE-2026-45722 | 7.1 | — | — | — | nextcloud / tables | Nextcloud is an open source content collaboration platform. | 96d ago |
| CVE-2026-46243 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego desc | 96d ago |
| CVE-2026-42678 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / | 96d ago |
| CVE-2026-48865 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Le | 96d ago |
| CVE-2026-48839 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs W | 96d ago |
| CVE-2026-42683 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp Vik | 96d ago |
| CVE-2026-42681 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2 | 96d ago |
| CVE-2026-48827 | 7.1 | — | — | — | apache / mina sshd | Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. | 96d ago |
| CVE-2026-48209 | 7.1 | — | — | — | otrs / otrs | An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows | 97d ago |
| CVE-2018-25410 | 7.1 | — | — | — | — | SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL | 98d ago |
| CVE-2026-49373 | 7.1 | — | — | — | jetbrains / teamcity | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | 99d ago |
| CVE-2026-49371 | 7.1 | — | — | — | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | 99d ago |
| CVE-2018-25392 | 7.1 | — | — | — | — | MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbi | 99d ago |
| CVE-2026-9808 | 7.1 | — | — | — | — | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). | 99d ago |
| CVE-2026-4776 | 7.1 | — | — | — | — | An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. | 99d ago |
| CVE-2026-44798 | 7.1 | — | — | — | networktocode / nautobot | Nautobot is a Network Source of Truth and Network Automation Platform. | 100d ago |
| CVE-2026-46230 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB reads when parsin | 100d ago |
| CVE-2026-46218 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add bounds checking to ib_{get,set | 100d ago |
| CVE-2026-46204 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsin | 100d ago |
| CVE-2026-46203 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclocked access on | 100d ago |
| CVE-2026-46199 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsin | 100d ago |
| CVE-2026-46191 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fbcon: Avoid OOB font access if console rotati | 100d ago |
| CVE-2026-46190 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: debugfs: fix out-of-bounds read | 100d ago |
| CVE-2026-46175 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency caused by FGGC of | 100d ago |
| CVE-2026-46150 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on permission eve | 100d ago |
| CVE-2026-46149 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: scsi: target: configfs: Bound snprintf() retur | 100d ago |