| CVE-2026-52954 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in deco | 109d ago |
| CVE-2026-52946 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fas | 109d ago |
| CVE-2026-52945 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAP | 109d ago |
| CVE-2026-11877 | 7.5 | — | — | — | microfocus / access manager | An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. | 109d ago |
| CVE-2026-57281 | 7.5 | — | — | — | jenkins / script security | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotation | 109d ago |
| CVE-2026-56270exploited | 7.5 | 2.0% | 1/3 | +14d | flowiseai / flowise | Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/ | 109d ago |
| CVE-2026-52932 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: xfrm: ipcomp: Free destination pages on acomp | 109d ago |
| CVE-2026-52929 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-strea | 109d ago |
| CVE-2026-52922 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation err | 109d ago |
| CVE-2026-9179 | 7.5 | — | — | — | — | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-jso | 109d ago |
| CVE-2026-9178 | 7.5 | — | — | — | — | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includ | 109d ago |
| CVE-2026-8705 | 7.5 | — | — | — | — | The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter | 109d ago |
| CVE-2026-10735zero day | 7.5 | 0.43% | 1/3 | 8d before | — | Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3. | 109d ago |
| CVE-2026-50193 | 7.5 | — | — | — | fasterxml / jackson-databind | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor | 110d ago |
| CVE-2026-53754 | 7.5 | — | — | — | kidocode / crawl4ai | Crawl4AI is an open-source LLM friendly web crawler & scraper. | 110d ago |
| CVE-2026-52844 | 7.5 | — | — | — | caddyserver / caddy | Caddy is an extensible server platform that uses TLS by default. | 110d ago |
| CVE-2025-61029 | 7.5 | — | — | — | — | An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of | 110d ago |
| CVE-2025-61024 | 7.5 | — | — | — | — | An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den | 110d ago |
| CVE-2026-55446 | 7.5 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 110d ago |
| CVE-2026-13007 | 7.5 | — | — | — | tenable / identity exposure | Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive app | 110d ago |
| CVE-2025-61028 | 7.5 | — | — | — | — | An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial | 110d ago |
| CVE-2025-61027 | 7.5 | — | — | — | — | An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of | 110d ago |
| CVE-2025-61025 | 7.5 | — | — | — | — | An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial | 110d ago |
| CVE-2025-61023 | 7.5 | — | — | — | — | An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of | 110d ago |
| CVE-2025-61022 | 7.5 | — | — | — | — | An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a De | 110d ago |
| CVE-2025-61021 | 7.5 | — | — | — | — | An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause | 110d ago |
| CVE-2025-61020 | 7.5 | — | — | — | — | An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a D | 110d ago |
| CVE-2025-61019 | 7.5 | — | — | — | — | An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a D | 110d ago |
| CVE-2025-61018 | 7.5 | — | — | — | — | An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a De | 110d ago |
| CVE-2026-54314 | 7.5 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 110d ago |
| CVE-2026-56322 | 7.5 | — | — | — | — | Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint th | 110d ago |
| CVE-2026-56248 | 7.5 | — | — | — | — | Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising | 110d ago |
| CVE-2023-54365 | 7.5 | — | — | — | traefik / traefik | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling | 110d ago |
| CVE-2026-8379 | 7.5 | — | — | — | — | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the fil | 110d ago |
| CVE-2026-53923 | 7.5 | — | — | — | vllm / vllm | vLLM is an inference and serving engine for large language models (LLMs). | 110d ago |
| CVE-2026-41523 | 7.5 | — | — | — | vllm / vllm | vLLM is an inference and serving engine for large language models (LLMs). | 110d ago |
| CVE-2026-56323 | 7.5 | — | — | — | — | Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint | 110d ago |
| CVE-2026-48517 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48516 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48515 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48514 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48513 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48512 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48511 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48510 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48506 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-48502 | 7.5 | — | — | — | messagepack / messagepack | MessagePack for C# is a MessagePack serializer for C#. | 110d ago |
| CVE-2026-55603 | 7.5 | — | — | — | chimurai / http-proxy-middleware | http-proxy-middleware is node.js http-proxy middleware. | 111d ago |
| CVE-2026-54299 | 7.5 | — | — | — | astro / astro | Astro is a web framework. | 111d ago |
| CVE-2026-54293 | 7.5 | — | — | — | nltk / nltk | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting rese | 111d ago |
| CVE-2026-53779 | 7.5 | — | — | — | — | WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attac | 111d ago |
| CVE-2026-54283 | 7.5 | — | — | — | encode / starlette | Starlette is a lightweight ASGI framework/toolkit. | 111d ago |
| CVE-2026-54280 | 7.5 | — | — | — | aiohttp / aiohttp | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. | 111d ago |
| CVE-2026-54279 | 7.5 | — | — | — | aiohttp / aiohttp | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. | 111d ago |
| CVE-2026-54278 | 7.5 | — | — | — | aiohttp / aiohttp | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. | 111d ago |
| CVE-2026-54277 | 7.5 | — | — | — | aiohttp / aiohttp | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. | 111d ago |
| CVE-2026-54275 | 7.5 | — | — | — | aiohttp / aiohttp | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. | 111d ago |
| CVE-2026-54274 | 7.5 | — | — | — | aiohttp / aiohttp | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. | 111d ago |
| CVE-2026-54273 | 7.5 | — | — | — | aiohttp / aiohttp | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. | 111d ago |
| CVE-2026-53571 | 7.5 | — | — | — | vitejs / vite | Vite is a frontend tooling framework for JavaScript. | 111d ago |