| CVE-2026-53539 | 7.5 | — | — | — | fastapiexpert / python-multipart | Python-Multipart is a streaming multipart parser for Python. | 111d ago |
| CVE-2026-50269 | 7.5 | — | — | — | aiohttp / aiohttp | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. | 111d ago |
| CVE-2026-50170 | 7.5 | — | — | — | angular / angular | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and | 111d ago |
| CVE-2026-48712 | 7.5 | — | — | — | protobufjs project / protobufjs | protobufjs compiles protobuf definitions into JavaScript (JS) functions. | 111d ago |
| CVE-2026-42127 | 7.5 | — | — | — | grafana / grafana | The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated a | 111d ago |
| CVE-2026-9071 | 7.5 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0. | 111d ago |
| CVE-2026-8858 | 7.5 | — | — | — | ibm / i | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code executi | 111d ago |
| CVE-2026-54268 | 7.5 | — | — | — | angular / angular | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and | 111d ago |
| CVE-2025-66389 | 7.5 | — | — | — | microsoft / github copilot | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-h | 111d ago |
| CVE-2026-12581 | 7.5 | — | — | — | — | EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. | 111d ago |
| CVE-2026-56253 | 7.5 | — | — | — | — | Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function | 112d ago |
| CVE-2026-56242 | 7.5 | — | — | — | — | Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that retu | 112d ago |
| CVE-2026-56341 | 7.5 | — | — | — | — | AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking a | 113d ago |
| CVE-2020-37255 | 7.5 | — | — | — | — | WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated | 113d ago |
| CVE-2026-11912 | 7.5 | — | — | — | — | The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authori | 113d ago |
| CVE-2026-11911 | 7.5 | — | — | — | — | The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v | 113d ago |
| CVE-2026-56214 | 7.5 | — | — | — | — | Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_tria | 113d ago |
| CVE-2026-56082 | 7.5 | — | — | — | — | Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER Pos | 113d ago |
| CVE-2026-50559 | 7.5 | — | — | — | quarkus / quarkus | Quarkus is a Java framework for building cloud-native applications. | 113d ago |
| CVE-2026-48774 | 7.5 | — | — | — | proxysql / proxysql | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. | 113d ago |
| CVE-2026-49293 | 7.5 | — | — | — | sunnyadn / js-toml | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. | 114d ago |
| CVE-2023-54357 | 7.5 | — | — | — | artio / book it\! | Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated at | 114d ago |
| CVE-2019-25762 | 7.5 | — | — | — | joomboost / joomproject | Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated | 114d ago |
| CVE-2026-48139 | 7.5 | — | — | — | ni / instrumentstudio | There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an | 114d ago |
| CVE-2026-48138 | 7.5 | — | — | — | ni / instrumentstudio | There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check tha | 114d ago |
| CVE-2026-11576 | 7.5 | — | — | — | eclipse / threadx netx duo | The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT pro | 114d ago |
| CVE-2026-47633 | 7.5 | — | — | — | microsoft / cost management | Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an un | 114d ago |
| CVE-2026-48937 | 7.5 | — | — | — | nodejs / node.js | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. | 115d ago |
| CVE-2026-55204 | 7.5 | — | — | — | haproxy / haproxy | HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_ins | 115d ago |
| CVE-2026-55203 | 7.5 | — | — | — | haproxy / haproxy | HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn struct | 115d ago |
| CVE-2026-38718 | 7.5 | — | — | — | inhandnetworks / ir915l-fq39-s firmware | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contai | 115d ago |
| CVE-2025-53114 | 7.5 | — | — | — | — | CometD is a scalable comet implementation for web messaging. | 115d ago |
| CVE-2026-45617 | 7.5 | — | — | — | — | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. | 115d ago |
| CVE-2026-45357 | 7.5 | — | — | — | — | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. | 115d ago |
| CVE-2026-8050 | 7.5 | — | — | — | — | In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer w | 115d ago |
| CVE-2026-50200 | 7.5 | — | — | — | — | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native app | 115d ago |
| CVE-2026-50196 | 7.5 | — | — | — | — | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native app | 115d ago |
| CVE-2026-48979 | 7.5 | — | — | — | — | PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, | 115d ago |
| CVE-2026-10696 | 7.5 | — | — | — | devolutions / unigetui | Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlie | 115d ago |
| CVE-2026-53869 | 7.5 | — | — | — | — | Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attack | 116d ago |
| CVE-2026-48818 | 7.5 | — | — | — | encode / starlette | Starlette is a lightweight ASGI framework/toolkit. | 116d ago |
| CVE-2026-6734 | 7.5 | — | — | — | nodejs / undici | Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verify | 116d ago |
| CVE-2026-47774 | 7.5 | — | — | — | envoyproxy / envoy | Envoy is an open source edge and service proxy designed for cloud-native applications. | 116d ago |
| CVE-2026-9675 | 7.5 | — | — | — | nodejs / undici | Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of f | 116d ago |
| CVE-2026-53872 | 7.5 | — | — | — | — | picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attacker | 116d ago |
| CVE-2026-20190 | 7.5 | — | — | — | cisco / identity services engine | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive informa | 116d ago |
| CVE-2026-12151 | 7.5 | — | — | — | nodejs / undici | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message | 116d ago |
| CVE-2026-54810 | 7.5 | — | — | — | — | Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Con | 116d ago |
| CVE-2026-22283 | 7.5 | — | — | — | dell / powerflex manager | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Contr | 116d ago |
| CVE-2026-54816 | 7.5 | — | — | — | — | Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote | 116d ago |
| CVE-2026-54417 | 7.5 | — | — | — | — | An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to | 116d ago |
| CVE-2026-9690 | 7.5 | — | — | — | — | Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. | 116d ago |
| CVE-2026-54802 | 7.5 | — | — | — | — | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. | 116d ago |
| CVE-2026-52696 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. | 116d ago |
| CVE-2026-49057 | 7.5 | — | — | — | — | Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. | 116d ago |
| CVE-2026-48929 | 7.5 | — | — | — | rocket.chat / rocket.chat | Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to una | 116d ago |
| CVE-2026-48779 | 7.5 | — | — | — | ws project / ws | ws is an open source WebSocket client and server for Node.js. | 116d ago |
| CVE-2026-40721 | 7.5 | — | — | — | — | Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions. | 116d ago |
| CVE-2026-34888 | 7.5 | — | — | — | — | Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions. | 116d ago |
| CVE-2026-22334 | 7.5 | — | — | — | — | Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions. | 116d ago |