| CVE-2026-29100 | 7.1 | high | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 170d ago |
| CVE-2026-32023 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode | 170d ago |
| CVE-2026-32017 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that al | 170d ago |
| CVE-2026-27953 | 7.1 | high | collerek / ormar | ormar is a async mini ORM for Python. | 170d ago |
| CVE-2026-0819 | 7.1 | high | wolfssl / wolfssl | A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. | 170d ago |
| CVE-2026-27070 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Ev | 170d ago |
| CVE-2026-27068 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard | 170d ago |
| CVE-2026-25442 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes | 170d ago |
| CVE-2026-25438 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gu | 170d ago |
| CVE-2025-68836 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars | 170d ago |
| CVE-2025-67618 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWor | 170d ago |
| CVE-2025-53222 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 170d ago |
| CVE-2025-50001 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 170d ago |
| CVE-2026-28073 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tri | 170d ago |
| CVE-2026-32000 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execu | 171d ago |
| CVE-2026-31994 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task scr | 171d ago |
| CVE-2026-31992 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allow | 171d ago |
| CVE-2026-28460 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers | 171d ago |
| CVE-2026-27566 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fa | 171d ago |
| CVE-2026-23269 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: apparmor: validate DFA start states are in bou | 171d ago |
| CVE-2025-55045 | 7.1 | high | murasoftware / mura cms | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address infor | 171d ago |
| CVE-2026-23244 | 7.1 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_ke | 171d ago |
| CVE-2026-22323 | 7.1 | high | — | A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to | 171d ago |
| CVE-2026-22322 | 7.1 | high | — | A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauth | 171d ago |
| CVE-2026-32254 | 7.1 | high | kube-router / kube-router | Kube-router is a turnkey solution for Kubernetes networking. | 172d ago |
| CVE-2026-22175 | 7.1 | high | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-a | 172d ago |
| CVE-2026-26001 | 7.1 | high | glpi-project / glpi inventory | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI | 172d ago |
| CVE-2026-1264 | 7.1 | high | ibm / sterling b2b integrator | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2 | 172d ago |
| CVE-2026-25369 | 7.1 | high | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flex | 173d ago |
| CVE-2026-32706 | 7.1 | high | dronecode / px4 drone autopilot | PX4 autopilot is a flight control solution for drones. | 173d ago |
| CVE-2026-32617 | 7.1 | high | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 173d ago |
| CVE-2026-26133 | 7.1 | high | microsoft / 365 copilot | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 173d ago |
| CVE-2025-15553 | 7.1 | high | truesec / lapswebui | Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a wor | 173d ago |
| CVE-2019-25529 | 7.1 | high | — | Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate d | 177d ago |
| CVE-2019-25473 | 7.1 | high | — | Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queri | 177d ago |
| CVE-2026-32126 | 7.1 | high | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 178d ago |
| CVE-2026-2368 | 7.1 | high | lenovo / filez | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a us | 178d ago |
| CVE-2026-1716 | 7.1 | high | lenovo / vantage | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo B | 178d ago |
| CVE-2026-1715 | 7.1 | high | lenovo / vantage | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo B | 178d ago |
| CVE-2026-71221 | 7 | high | — | A stack out-of-bounds write vulnerability was found in gfs2-utils. | 2d ago |
| CVE-2026-71220 | 7 | high | — | A stack out-of-bounds write vulnerability was found in gfs2-utils. | 2d ago |
| CVE-2026-78409 | 7 | high | — | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdire | 3d ago |
| CVE-2026-73725 | 7 | high | arubanetworks / fabric composer | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. | 4d ago |
| CVE-2026-84233 | 7 | high | — | A flaw was found in rpm. | 4d ago |
| CVE-2026-13732 | 7 | high | — | A flaw was found in GDB's STABS debug format parser. | 5d ago |
| CVE-2026-16821 | 7 | high | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a fo | 8d ago |
| CVE-2026-81726 | 7 | high | nltk / nltk | NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement | 9d ago |
| CVE-2026-81714 | 7 | high | jahlives / openssl encrypt | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_ | 9d ago |
| CVE-2026-58093 | 7 | high | — | The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. | 10d ago |
| CVE-2026-54467 | 7 | high | — | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2 | 11d ago |
| CVE-2026-65082 | 7 | high | nvidia / nemoclaw | NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause co | 11d ago |
| CVE-2026-66153 | 7 | high | — | The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which | 11d ago |
| CVE-2026-75037 | 7 | high | — | Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. | 11d ago |
| CVE-2026-78465 | 7 | high | gimp / gimp | A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. | 12d ago |
| CVE-2026-78367 | 7 | high | — | A vulnerability was found in RPM's rpmbuild tarball processing. | 12d ago |
| CVE-2026-77584 | 7 | high | — | Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached stream | 16d ago |
| CVE-2026-63387 | 7 | high | — | Libevent is an event notification library. | 16d ago |
| CVE-2026-18268 | 7 | high | — | Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. | 16d ago |
| CVE-2026-16923 | 7 | high | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to impr | 16d ago |
| CVE-2026-16922 | 7 | high | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time | 16d ago |