| CVE-2026-44496 | 7.5 | — | — | — | axios / axios | Axios is a promise based HTTP client for the browser and Node.js. | 122d ago |
| CVE-2026-44488 | 7.5 | — | — | — | axios / axios | Axios is a promise based HTTP client for the browser and Node.js. | 122d ago |
| CVE-2026-44487 | 7.5 | — | — | — | axios / axios | Axios is a promise based HTTP client for the browser and Node.js. | 122d ago |
| CVE-2026-44486 | 7.5 | — | — | — | axios / axios | Axios is a promise based HTTP client for the browser and Node.js. | 122d ago |
| CVE-2026-7787 | 7.5 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by b | 122d ago |
| CVE-2026-7250 | 7.5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11 | 122d ago |
| CVE-2026-5497 | 7.5 | — | — | — | vllm / vllm | vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unboun | 122d ago |
| CVE-2026-41856 | 7.5 | — | — | — | vmware / spring for graphql | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotati | 122d ago |
| CVE-2026-53461 | 7.5 | — | — | — | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 122d ago |
| CVE-2026-53460 | 7.5 | — | — | — | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 122d ago |
| CVE-2026-52726 | 7.5 | — | — | — | — | Dulwich is a pure-Python implementation of the Git file formats and protocols. | 122d ago |
| CVE-2026-49218 | 7.5 | — | — | — | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 122d ago |
| CVE-2026-48110 | 7.5 | — | — | — | — | Russh is a Rust SSH client & server library. | 122d ago |
| CVE-2026-46702 | 7.5 | — | — | — | — | Russh is a Rust SSH client & server library. | 122d ago |
| CVE-2026-46679 | 7.5 | — | — | — | — | libp2p is a JavaScript Implementation of libp2p networking stack. | 122d ago |
| CVE-2026-46673 | 7.5 | — | — | — | — | Russh is a Rust SSH client & server library. | 122d ago |
| CVE-2026-46669 | 7.5 | — | — | — | openvm / openvm | OpenVM is a performant and modular zkVM framework built for customization and extensibility. | 122d ago |
| CVE-2026-46625 | 7.5 | — | — | — | js-cookie / javascript cookie | JavaScript Cookie is a JavaScript API for handling cookies, client-side. | 122d ago |
| CVE-2026-46522 | 7.5 | — | — | — | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 122d ago |
| CVE-2026-46520 | 7.5 | — | — | — | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 122d ago |
| CVE-2026-45783 | 7.5 | — | — | — | — | libp2p is a JavaScript Implementation of libp2p networking stack. | 122d ago |
| CVE-2026-42542 | 7.5 | — | — | — | tdengine / tdengine | TDengine is an open source, time-series database optimized for Internet of Things devices. | 122d ago |
| CVE-2026-10143 | 7.5 | — | — | — | dpkp / kafka-python | kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allow | 122d ago |
| CVE-2026-10142 | 7.5 | — | — | — | dpkp / kafka-python | kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malici | 122d ago |
| CVE-2026-0270 | 7.5 | — | — | — | paloaltonetworks / cortex xsoar | A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauth | 122d ago |
| CVE-2026-6893 | 7.5 | — | — | — | — | A flaw was found in dracut. | 122d ago |
| CVE-2026-1220 | 7.5 | — | — | — | google / chrome | Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion | 122d ago |
| CVE-2025-71330 | 7.5 | — | — | — | image-size / image-size | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently bl | 123d ago |
| CVE-2025-71329 | 7.5 | — | — | — | image-size / image-size | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently bl | 123d ago |
| CVE-2026-3018zero day | 7.5 | 1.5% | 1/3 | same day | — | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ paramete | 123d ago |
| CVE-2026-10846 | 7.5 | — | — | — | nlnetlabs / ldns | NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, l | 123d ago |
| CVE-2026-26237 | 7.5 | — | — | — | qnap / qumagie | A missing authorization vulnerability has been reported to affect QuMagie. | 123d ago |
| CVE-2026-45541 | 7.5 | — | — | — | espressif / esp-idf | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. | 123d ago |
| CVE-2026-46545 | 7.5 | — | — | — | — | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. | 123d ago |
| CVE-2026-46541 | 7.5 | — | — | — | — | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. | 123d ago |
| CVE-2026-44716 | 7.5 | — | — | — | pipecat / pipecat | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. | 123d ago |
| CVE-2026-41728 | 7.5 | — | — | — | vmware / spring data rest | Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter | 123d ago |
| CVE-2026-41716 | 7.5 | — | — | — | broadcom / spring data commons | Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache ke | 123d ago |
| CVE-2026-41695 | 7.5 | — | — | — | broadcom / spring data commons | Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker- | 123d ago |
| CVE-2026-40988 | 7.5 | — | — | — | vmware / spring security | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout | 123d ago |
| CVE-2026-9742 | 7.5 | — | — | — | mongodb / mongodb | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter | 123d ago |
| CVE-2026-9740 | 7.5 | — | — | — | mongodb / mongodb | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod proces | 123d ago |
| CVE-2026-46374 | 7.5 | — | — | — | sqlfluff / sqlfluff | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. | 123d ago |
| CVE-2026-46373 | 7.5 | — | — | — | sqlfluff / sqlfluff | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. | 123d ago |
| CVE-2026-34713 | 7.5 | — | — | — | adobe / c2pa | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource | 123d ago |
| CVE-2026-34712 | 7.5 | — | — | — | adobe / c2pa | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Valida | 123d ago |
| CVE-2026-34711 | 7.5 | — | — | — | adobe / c2pa | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or W | 123d ago |
| CVE-2026-11799 | 7.5 | — | — | — | mozilla / focus | UXSS in Focus for iOS / Klar Webkit navigation. | 123d ago |
| CVE-2025-71319 | 7.5 | — | — | — | image-size / image-size | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently bl | 123d ago |
| CVE-2026-39169 | 7.5 | — | — | — | — | SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. | 123d ago |
| CVE-2026-36823 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAut | 123d ago |
| CVE-2026-36822 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAdd | 123d ago |
| CVE-2026-36821 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCro | 123d ago |
| CVE-2026-36820 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAut | 123d ago |
| CVE-2026-36819 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMA | 123d ago |
| CVE-2026-36818 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifi | 123d ago |
| CVE-2026-36817 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAu | 123d ago |
| CVE-2026-36816 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewif | 123d ago |
| CVE-2026-36815 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostn | 123d ago |
| CVE-2026-36813 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCr | 123d ago |