| CVE-2026-39968 | 7.1 | high | — | TypeBot is a chatbot builder tool. | 106d ago |
| CVE-2026-7325 | 7.1 | high | devolutions / devolutions server | Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authe | 106d ago |
| CVE-2026-48240 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id an | 107d ago |
| CVE-2026-48239 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST | 107d ago |
| CVE-2026-48238 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET pa | 107d ago |
| CVE-2026-48237 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and | 107d ago |
| CVE-2026-48236 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST pa | 107d ago |
| CVE-2026-48234 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the | 107d ago |
| CVE-2026-48233 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset | 107d ago |
| CVE-2026-48232 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the off | 107d ago |
| CVE-2026-48231 | 7.1 | high | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST param | 107d ago |
| CVE-2025-13477 | 7.1 | high | — | Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerabil | 107d ago |
| CVE-2026-44066 | 7.1 | high | — | Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a | 107d ago |
| CVE-2026-44064 | 7.1 | high | — | An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker | 107d ago |
| CVE-2026-32882 | 7.1 | high | — | libheif is a HEIF and AVIF file format decoder and encoder. | 109d ago |
| CVE-2026-32741 | 7.1 | high | — | libheif is a HEIF and AVIF file format decoder and encoder. | 109d ago |
| CVE-2026-7571 | 7.1 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 109d ago |
| CVE-2026-30950 | 7.1 | high | — | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence | 110d ago |
| CVE-2026-45242 | 7.1 | high | steipete / summarize | Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows | 110d ago |
| CVE-2026-6495 | 7.1 | high | — | The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back | 110d ago |
| CVE-2018-25319 | 7.1 | high | — | Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to man | 111d ago |
| CVE-2021-47980 | 7.1 | high | — | Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate dat | 112d ago |
| CVE-2026-45350 | 7.1 | high | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 113d ago |
| CVE-2026-44569 | 7.1 | high | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 113d ago |
| CVE-2026-45399 | 7.1 | high | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 113d ago |
| CVE-2026-45349 | 7.1 | high | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 113d ago |
| CVE-2026-44556 | 7.1 | high | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 113d ago |
| CVE-2026-45037 | 7.1 | high | tabby / tabby | Tabby (formerly Terminus) is a highly configurable terminal emulator. | 113d ago |
| CVE-2026-44641 | 7.1 | high | — | Microsoft APM is an open-source, community-driven dependency manager for AI agents. | 113d ago |
| CVE-2026-46333 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic | 113d ago |
| CVE-2026-44637 | 7.1 | high | saitoha / libsixel | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. | 114d ago |
| CVE-2026-41935 | 7.1 | high | — | Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where | 114d ago |
| CVE-2026-46446 | 7.1 | high | — | SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. | 115d ago |
| CVE-2026-46445 | 7.1 | high | — | SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection. | 115d ago |
| CVE-2026-32991 | 7.1 | high | — | Improper authorization checks of team members privileges allow a team member to escalate privileges to the team ow | 115d ago |
| CVE-2026-33377 | 7.1 | high | grafana / grafana | An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. | 115d ago |
| CVE-2020-37226 | 7.1 | high | — | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to | 115d ago |
| CVE-2020-37224 | 7.1 | high | — | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to | 115d ago |
| CVE-2026-4609 | 7.1 | high | — | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access d | 115d ago |
| CVE-2026-5371 | 7.1 | high | — | The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vu | 116d ago |
| CVE-2026-45226 | 7.1 | high | — | Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated | 116d ago |
| CVE-2026-41102 | 7.1 | high | microsoft / powerpoint | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. | 116d ago |
| CVE-2026-41101 | 7.1 | high | microsoft / word | Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. | 116d ago |
| CVE-2026-40401 | 7.1 | high | microsoft / windows 10 1607 | Windows TCP/IP Denial of Service Vulnerability | 116d ago |
| CVE-2026-25789 | 7.1 | high | — | Affected devices do not properly validate and sanitize filenames on the Firmware Update page. | 116d ago |
| CVE-2026-45430 | 7.1 | high | — | The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect | 117d ago |
| CVE-2026-28941 | 7.1 | high | apple / ipados | The issue was addressed with improved checks. | 117d ago |
| CVE-2026-45224 | 7.1 | high | — | Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that | 117d ago |
| CVE-2026-45001 | 7.1 | high | openclaw / openclaw | OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and confi | 117d ago |
| CVE-2026-2393 | 7.1 | high | lfprojects / mlflow | A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. | 117d ago |
| CVE-2019-25638 | 7.1 | high | — | Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to e | 165d ago |
| CVE-2026-33252 | 7.1 | high | lfprojects / mcp go sdk | The Go MCP SDK used Go's standard encoding/json. | 166d ago |
| CVE-2026-33723 | 7.1 | high | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-33493 | 7.1 | high | wwbn / avideo | WWBN AVideo is an open source video platform. | 166d ago |
| CVE-2026-23555 | 7.1 | high | xen / xen | Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash x | 166d ago |
| CVE-2019-25573 | 7.1 | high | njtech / greencms | Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL | 168d ago |
| CVE-2026-32057 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control U | 169d ago |
| CVE-2026-33125 | 7.1 | high | frigate / frigate | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. | 169d ago |
| CVE-2024-32537 | 7.1 | high | — | Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forger | 169d ago |
| CVE-2026-32954 | 7.1 | high | frappe / erpnext | ERP is a free and open source Enterprise Resource Planning tool. | 170d ago |