| CVE-2026-36811 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picNa | 123d ago |
| CVE-2026-36810 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoU | 123d ago |
| CVE-2026-36809 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAu | 123d ago |
| CVE-2026-36808 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAu | 123d ago |
| CVE-2026-36807 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAu | 123d ago |
| CVE-2026-36806 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAu | 123d ago |
| CVE-2026-36805 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple buffer overflows in the | 123d ago |
| CVE-2026-36803 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow in the page par | 123d ago |
| CVE-2026-36802 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow in the page par | 123d ago |
| CVE-2026-36801 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBin | 123d ago |
| CVE-2026-36800 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBin | 123d ago |
| CVE-2026-36799 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAu | 123d ago |
| CVE-2026-36797 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBind | 123d ago |
| CVE-2026-36796 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the picCropNa | 123d ago |
| CVE-2026-36794 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain multiple stac | 123d ago |
| CVE-2026-36793 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain multiple stac | 123d ago |
| CVE-2026-36792 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overf | 123d ago |
| CVE-2026-36791 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda O3v3 v1.0.0.5 was discovered to contain a stack overflow in the save_list | 123d ago |
| CVE-2026-36784 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overf | 123d ago |
| CVE-2026-36783 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overf | 123d ago |
| CVE-2026-36779 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain multiple stac | 123d ago |
| CVE-2026-36771 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overf | 123d ago |
| CVE-2026-36770 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered to contain a stack overflow in the Go | 123d ago |
| CVE-2026-36719 | 7.5 | — | — | — | — | An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticat | 123d ago |
| CVE-2025-55657 | 7.5 | — | — | — | gpac / gpac | A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows | 123d ago |
| CVE-2025-52293 | 7.5 | — | — | — | gpac / gpac | A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2. | 123d ago |
| CVE-2025-52292 | 7.5 | — | — | — | gpac / gpac | A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a | 123d ago |
| CVE-2023-43688 | 7.5 | — | — | — | — | An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). | 123d ago |
| CVE-2026-9076 | 7.5 | — | — | — | openssl / openssl | Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data | 123d ago |
| CVE-2026-49847 | 7.5 | — | — | — | freeswitch / freeswitch | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switch | 123d ago |
| CVE-2026-49842 | 7.5 | — | — | — | freeswitch / freeswitch | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switch | 123d ago |
| CVE-2026-49475 | 7.5 | — | — | — | freeswitch / freeswitch | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switch | 123d ago |
| CVE-2026-49160 | 7.5 | — | — | — | microsoft / windows 10 1607 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. | 123d ago |
| CVE-2026-48563 | 7.5 | — | — | — | microsoft / windows 10 1809 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 123d ago |
| CVE-2026-47654 | 7.5 | — | — | — | microsoft / windows server 2016 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 123d ago |
| CVE-2026-45771 | 7.5 | — | — | — | freeswitch / freeswitch | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switch | 123d ago |
| CVE-2026-45639 | 7.5 | — | — | — | microsoft / remote desktop client | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 123d ago |
| CVE-2026-45591 | 7.5 | — | — | — | microsoft / asp.net core | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 123d ago |
| CVE-2026-45583 | 7.5 | — | — | — | microsoft / exchange server | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized atta | 123d ago |
| CVE-2026-45445 | 7.5 | — | — | — | openssl / openssl | Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, t | 123d ago |
| CVE-2026-44801 | 7.5 | — | — | — | microsoft / remote desktop client | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 123d ago |
| CVE-2026-44799 | 7.5 | — | — | — | microsoft / remote desktop client | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 123d ago |
| CVE-2026-42993 | 7.5 | — | — | — | microsoft / windows 10 21h2 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 123d ago |
| CVE-2026-42992 | 7.5 | — | — | — | microsoft / windows app | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 123d ago |
| CVE-2026-42913 | 7.5 | — | — | — | microsoft / remote desktop client | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Clie | 123d ago |
| CVE-2026-42909 | 7.5 | — | — | — | microsoft / remote desktop client | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Clie | 123d ago |
| CVE-2026-42908 | 7.5 | — | — | — | microsoft / windows app | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 123d ago |
| CVE-2026-42765 | 7.5 | — | — | — | openssl / openssl | Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for t | 123d ago |
| CVE-2026-42764 | 7.5 | — | — | — | openssl / openssl | Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the | 123d ago |
| CVE-2026-42570 | 7.5 | — | — | — | svelte / devalue | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient fo | 123d ago |
| CVE-2026-42567 | 7.5 | — | — | — | svelte / svelte | Svelte is a performance oriented web framework. | 123d ago |
| CVE-2026-40376 | 7.5 | — | — | — | microsoft / visual studio code | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a netwo | 123d ago |
| CVE-2026-34183 | 7.5 | — | — | — | openssl / openssl | Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets contai | 123d ago |
| CVE-2026-34180 | 7.5 | — | — | — | openssl / openssl | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 giga | 123d ago |
| CVE-2017-20250 | 7.5 | — | — | — | — | Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download ar | 124d ago |
| CVE-2017-20248 | 7.5 | — | — | — | — | Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to downloa | 124d ago |
| CVE-2026-46749 | 7.5 | — | — | — | siemens / sinec ins | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). | 124d ago |
| CVE-2026-9185 | 7.5 | — | — | — | — | The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all | 124d ago |
| CVE-2026-41850 | 7.5 | — | — | — | vmware / spring framework | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algori | 124d ago |
| CVE-2026-41849 | 7.5 | — | — | — | vmware / spring framework | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). | 124d ago |