| CVE-2026-46140 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: validate WMT event SKB lengt | 100d ago |
| CVE-2026-46130 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split | 100d ago |
| CVE-2026-47272 | 7.1 | high | — | pam_usb provides hardware authentication for Linux using ordinary removable media. | 101d ago |
| CVE-2026-45134 | 7.1 | high | — | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. | 101d ago |
| CVE-2026-44473 | 7.1 | high | — | Ella Core is a 5G core designed for private networks. | 101d ago |
| CVE-2026-42280 | 7.1 | high | auth0 / auth0.js | Auth0.js is a client-side JavaScript library for Auth0. | 101d ago |
| CVE-2026-7528 | 7.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption. | 101d ago |
| CVE-2026-46094 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ext4: fix bounds check in check_xattrs() to pr | 101d ago |
| CVE-2026-46078 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: erofs: fix the out-of-bounds nameoff handling | 101d ago |
| CVE-2026-46070 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: md/raid5: validate payload size before accessi | 101d ago |
| CVE-2026-46067 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: validate damos_quota_goal->nid | 101d ago |
| CVE-2026-46064 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ibmasm: fix heap over-read in ibmasm_send_i2o_ | 101d ago |
| CVE-2026-46055 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix string overrun due to missing te | 101d ago |
| CVE-2026-46054 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() a | 101d ago |
| CVE-2026-46033 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject short ahash digest | 101d ago |
| CVE-2026-46022 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: misc: ibmasm: fix OOB MMIO read in ibmasm_hand | 101d ago |
| CVE-2026-46020 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: validate damos_quota_goal->nid | 101d ago |
| CVE-2026-45999 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: erofs: fix unsigned underflow in z_erofs_lz4_h | 101d ago |
| CVE-2026-45994 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ibmasm: fix OOB reads in command_file_write du | 101d ago |
| CVE-2026-45958 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: fix to avoid directly derefe | 101d ago |
| CVE-2026-45957 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: rcu: Fix rcu_read_unlock() deadloop due to sof | 101d ago |
| CVE-2026-45955 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: fix percpu_ref not resurrected | 101d ago |
| CVE-2026-45943 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: erofs: fix inline data read failure for ztailp | 101d ago |
| CVE-2026-45903 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix memory access flags in helper prototy | 101d ago |
| CVE-2026-45893 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix & Optimize table creation from p | 101d ago |
| CVE-2026-45856 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Validate wqe_size before using it | 101d ago |
| CVE-2026-45851 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: efi: Fix reservation of unaccepted memory tabl | 101d ago |
| CVE-2026-1933 | 7.1 | high | redhat / openshift container platform | A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. | 101d ago |
| CVE-2026-1718 | 7.1 | high | ibm / db2 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially craf | 101d ago |
| CVE-2025-71306 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ima: Fix stack-out-of-bounds in is_bprm_creds_ | 101d ago |
| CVE-2026-42762 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp Vik | 101d ago |
| CVE-2026-42759 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affilia | 101d ago |
| CVE-2026-42754 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Fa | 101d ago |
| CVE-2026-42749 | 7.1 | high | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post | 101d ago |
| CVE-2026-42739 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Adva | 101d ago |
| CVE-2026-42738 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smar | 101d ago |
| CVE-2026-42734 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn G | 101d ago |
| CVE-2026-42733 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 W | 101d ago |
| CVE-2026-42729 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hiv | 101d ago |
| CVE-2026-42728 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins H | 101d ago |
| CVE-2026-40836 | 7.1 | high | — | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage mode | 101d ago |
| CVE-2026-40834 | 7.1 | high | — | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.ph | 101d ago |
| CVE-2026-40833 | 7.1 | high | — | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files | 101d ago |
| CVE-2025-52747 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Them | 101d ago |
| CVE-2025-22741 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Fe | 101d ago |
| CVE-2026-6268 | 7.1 | high | — | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customi | 101d ago |
| CVE-2026-42012 | 7.1 | high | — | A flaw was found in gnutls. | 102d ago |
| CVE-2025-14361 | 7.1 | high | — | Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Pr | 102d ago |
| CVE-2026-3603 | 7.1 | high | ibm / engineering lifecycle management | IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through I | 102d ago |
| CVE-2026-24196 | 7.1 | high | nvidia / gpu display driver | NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. | 102d ago |
| CVE-2026-24195 | 7.1 | high | nvidia / gpu display driver | NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validatio | 102d ago |
| CVE-2026-48690 | 7.1 | high | pavel-odintsov / fastnetmon | FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer | 102d ago |
| CVE-2026-39436 | 7.1 | high | — | Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. | 103d ago |
| CVE-2018-25381 | 7.1 | high | — | Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to e | 103d ago |
| CVE-2018-25380 | 7.1 | high | — | Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to e | 103d ago |
| CVE-2018-25352 | 7.1 | high | — | WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that a | 105d ago |
| CVE-2018-25347 | 7.1 | high | — | WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attack | 105d ago |
| CVE-2018-25346 | 7.1 | high | — | WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated atta | 105d ago |
| CVE-2026-41074 | 7.1 | high | — | RT is an open source, enterprise-grade issue and ticket tracking system. | 106d ago |
| CVE-2026-9291 | 7.1 | high | — | Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a | 106d ago |