| CVE-2026-55697 | 7.5 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 108d ago |
| CVE-2026-55487 | 7.5 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 108d ago |
| CVE-2026-48995 | 7.5 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 108d ago |
| CVE-2026-11999 | 7.5 | — | — | — | wolfssl / wolfssl | X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_v | 108d ago |
| CVE-2026-55092 | 7.5 | — | — | — | aquasec / trivy | Trivy is a security scanner. | 108d ago |
| CVE-2026-13351 | 7.5 | — | — | — | zephyrproject / zephyr | Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a sma | 108d ago |
| CVE-2026-9716 | 7.5 | — | — | — | schneider-electric / powerlogic p7 firmware | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the | 108d ago |
| CVE-2026-9650 | 7.5 | — | — | — | schneider-electric / easylogic t150 firmware | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sen | 108d ago |
| CVE-2026-12844 | 7.5 | — | — | — | — | List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. | 108d ago |
| CVE-2026-57435 | 7.5 | — | — | — | nokogiri / nokogiri | Nokogiri is an open source XML and HTML library for the Ruby programming language. | 108d ago |
| CVE-2026-57434 | 7.5 | — | — | — | nokogiri / nokogiri | Nokogiri is an open source XML and HTML library for the Ruby programming language. | 108d ago |
| CVE-2026-56122 | 7.5 | — | — | — | — | Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attacke | 108d ago |
| CVE-2026-54844 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. | 108d ago |
| CVE-2026-54841 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. | 108d ago |
| CVE-2026-54830 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. | 108d ago |
| CVE-2026-54829 | 7.5 | — | — | — | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. | 108d ago |
| CVE-2026-54828 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. | 108d ago |
| CVE-2026-27366 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. | 108d ago |
| CVE-2026-33612 | 7.5 | — | — | — | — | A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisonin | 108d ago |
| CVE-2026-53244 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: VFS: fix possible failure to unlock in nfsd4_c | 108d ago |
| CVE-2026-53235 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: add pskb_may_pull() to skb_gro_receive_li | 108d ago |
| CVE-2026-53229 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on | 108d ago |
| CVE-2026-53199 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: use kmap_local_page in netvsc_copy_ | 108d ago |
| CVE-2026-53184 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: udp: clear skb->dev before running a sockmap v | 108d ago |
| CVE-2026-53183 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTC | 108d ago |
| CVE-2026-53180 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: timers/migration: Fix livelock in tmigr_handle | 108d ago |
| CVE-2026-53165 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iomap: avoid potential null folio->mapping der | 108d ago |
| CVE-2026-12937 | 7.5 | — | — | — | — | The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulne | 108d ago |
| CVE-2026-9702 | 7.5 | — | — | — | — | The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer b | 108d ago |
| CVE-2026-12490 | 7.5 | — | — | — | nlnetlabs / nsd | When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certif | 108d ago |
| CVE-2026-12245 | 7.5 | — | — | — | nlnetlabs / nsd | NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the | 108d ago |
| CVE-2026-13311 | 7.5 | — | — | — | shell-quote project / shell-quote | shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator | 108d ago |
| CVE-2026-12077 | 7.5 | — | — | — | — | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude | 108d ago |
| CVE-2025-60474 | 7.5 | — | — | — | gpac / gpac | A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02. | 108d ago |
| CVE-2025-60467 | 7.5 | — | — | — | gpac / gpac | A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/M | 108d ago |
| CVE-2026-9776 | 7.5 | — | — | — | aten / unizon | ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. | 108d ago |
| CVE-2026-54066exploited | 7.5 | 2.4% | 1/3 | +40d | — | SiYuan is an open-source personal knowledge management system. | 108d ago |
| CVE-2026-52794 | 7.5 | — | — | — | sentry / sentry | Sentry is an error tracking and performance monitoring tool. | 108d ago |
| CVE-2026-52799 | 7.5 | — | — | — | — | Gogs is an open source self-hosted Git service. | 109d ago |
| CVE-2026-50129 | 7.5 | — | — | — | — | Mastodon is a free, open-source social network server based on ActivityPub. | 109d ago |
| CVE-2026-1840 | 7.5 | — | — | — | — | The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication | 109d ago |
| CVE-2026-53950 | 7.5 | — | — | — | — | @tryghost/activitypub is Ghost’s social/federation client app. | 109d ago |
| CVE-2026-13029 | 7.5 | — | — | — | google / chrome | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a | 109d ago |
| CVE-2026-49851 | 7.5 | — | — | — | — | Mistune is a Python Markdown parser with renderers and plugins. | 109d ago |
| CVE-2026-44020 | 7.5 | — | — | — | docling / docling | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative A | 109d ago |
| CVE-2026-44017 | 7.5 | — | — | — | docling / docling | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative A | 109d ago |
| CVE-2026-54904 | 7.5 | — | — | — | rubyconcurrency / concurrent ruby | concurrent-ruby is a modern concurrency tools for Ruby. | 109d ago |
| CVE-2026-54297 | 7.5 | — | — | — | faraday project / faraday | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. | 109d ago |
| CVE-2026-53087 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix leaking free_bds While recl | 109d ago |
| CVE-2026-53070 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sctp: disable BH before calling udp_tunnel_xmi | 109d ago |
| CVE-2026-53069 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net, bpf: fix null-ptr-deref in xdp_master_red | 109d ago |
| CVE-2026-53026 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: NFSD: fix nfs4_file access extra count in nfsd | 109d ago |
| CVE-2026-53003 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: pppoe: drop PFC frames RFC 2516 Section 7 stat | 109d ago |
| CVE-2026-52998 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL d | 109d ago |
| CVE-2026-52983 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix BQL imbalance in TX path Fix | 109d ago |
| CVE-2026-52981 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: neigh: let neigh_xmit take skb ownership neigh | 109d ago |
| CVE-2026-52974 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: tls: fix strparser anchor skb leak on off | 109d ago |
| CVE-2026-52960 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ceph: put folios not suitable for writeback Th | 109d ago |
| CVE-2026-52957 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential null-ptr-deref in decod | 109d ago |
| CVE-2026-52956 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in | 109d ago |