| CVE-2026-37222 | 7.5 | — | — | — | — | FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. | 131d ago |
| CVE-2026-37221 | 7.5 | — | — | — | — | FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding | 131d ago |
| CVE-2026-37220 | 7.5 | — | — | — | — | FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. | 131d ago |
| CVE-2026-49361 | 7.5 | — | — | — | apache / fluss | Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as th | 132d ago |
| CVE-2026-41084 | 7.5 | — | — | — | apache / airflow | A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskIn | 132d ago |
| CVE-2018-25426 | 7.5 | — | — | — | winmtr / winmtr | WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a | 133d ago |
| CVE-2018-25408 | 7.5 | — | — | — | — | The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows | 133d ago |
| CVE-2026-9757 | 7.5 | — | — | — | — | The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in a | 134d ago |
| CVE-2026-7459 | 7.5 | — | — | — | — | The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (S | 134d ago |
| CVE-2026-47123 | 7.5 | — | — | — | — | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. | 134d ago |
| CVE-2026-46599 | 7.5 | — | — | — | — | The TIFF decoder does not place a limit on the size of PackBits-compressed data. | 134d ago |
| CVE-2026-46527 | 7.5 | — | — | — | yhirose / cpp-httplib | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. | 134d ago |
| CVE-2026-46385 | 7.5 | — | — | — | — | iskorotkov/avro is a fast Go Avro codec. | 134d ago |
| CVE-2026-46384 | 7.5 | — | — | — | — | iskorotkov/avro is a fast Go Avro codec. | 134d ago |
| CVE-2026-44422 | 7.5 | — | — | — | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 134d ago |
| CVE-2026-49372 | 7.5 | — | — | — | jetbrains / teamcity | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | 134d ago |
| CVE-2026-44648 | 7.5 | — | — | — | — | SillyTavern is a locally installed user interface that allows users to interact with text generation large languag | 134d ago |
| CVE-2026-10108 | 7.5 | — | — | — | — | xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpo | 134d ago |
| CVE-2026-10069 | 7.5 | — | — | — | — | A vulnerability has been found in Shibby Tomato 1.28. | 134d ago |
| CVE-2018-25396 | 7.5 | — | — | — | — | Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers | 134d ago |
| CVE-2018-25391 | 7.5 | — | — | — | — | HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers t | 134d ago |
| CVE-2026-10073 | 7.5 | — | — | — | — | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attacke | 134d ago |
| CVE-2025-41271 | 7.5 | — | — | — | waterfall-security / wf-500 firmware | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and | 135d ago |
| CVE-2026-10056 | 7.5 | — | — | — | — | CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the de | 135d ago |
| CVE-2026-9990 | 7.5 | — | — | — | google / chrome | Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who conv | 135d ago |
| CVE-2026-9963 | 7.5 | — | — | — | google / chrome | Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a | 135d ago |
| CVE-2026-9960 | 7.5 | — | — | — | google / chrome | Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised t | 135d ago |
| CVE-2026-9956 | 7.5 | — | — | — | google / chrome | Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a use | 135d ago |
| CVE-2026-9954 | 7.5 | — | — | — | google / chrome | Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user | 135d ago |
| CVE-2026-9934 | 7.5 | — | — | — | google / chrome | Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to e | 135d ago |
| CVE-2026-9933 | 7.5 | — | — | — | google / chrome | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to | 135d ago |
| CVE-2026-9922 | 7.5 | — | — | — | google / chrome | Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised | 135d ago |
| CVE-2026-9909 | 7.5 | — | — | — | google / chrome | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the | 135d ago |
| CVE-2026-9901 | 7.5 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the | 135d ago |
| CVE-2026-10022 | 7.5 | — | — | — | google / chrome | Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install | 135d ago |
| CVE-2026-10009 | 7.5 | — | — | — | google / chrome | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised th | 135d ago |
| CVE-2026-10006 | 7.5 | — | — | — | google / chrome | Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code insi | 135d ago |
| CVE-2026-10005 | 7.5 | — | — | — | google / chrome | Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who con | 135d ago |
| CVE-2026-10003 | 7.5 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to | 135d ago |
| CVE-2026-48116 | 7.5 | — | — | — | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 135d ago |
| CVE-2026-44883 | 7.5 | — | — | — | portainer / portainer | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be | 135d ago |
| CVE-2026-39929 | 7.5 | — | — | — | — | Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read | 135d ago |
| CVE-2026-10044 | 7.5 | — | — | — | — | Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts | 135d ago |
| CVE-2026-46835 | 7.5 | — | — | — | oracle / database server | Vulnerability in the Net Service component of Oracle Database Server. | 135d ago |
| CVE-2026-46834 | 7.5 | — | — | — | oracle / database server | Vulnerability in the Net Service component of Oracle Database Server. | 135d ago |
| CVE-2026-46829 | 7.5 | — | — | — | oracle / rest data services | Vulnerability in Oracle REST Data Services (component: Mongoapi). | 135d ago |
| CVE-2026-49128 | 7.5 | — | — | — | — | Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrT | 135d ago |
| CVE-2026-32847 | 7.5 | — | — | — | hkuds / deepcode | DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backe | 135d ago |
| CVE-2026-45332 | 7.5 | — | — | — | — | Automad is a flat-file content management system and template engine. | 135d ago |
| CVE-2026-34126 | 7.5 | — | — | — | tp-link / tapo l535e firmware | TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Blu | 135d ago |
| CVE-2026-9096 | 7.5 | — | — | — | — | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. | 135d ago |
| CVE-2026-45017 | 7.5 | — | — | — | jg-rp / python liquid | Python Liquid is a Python engine for the Liquid template language. | 135d ago |
| CVE-2026-44594 | 7.5 | — | — | — | — | esm.sh is a no-build content delivery network (CDN) for web development. | 135d ago |
| CVE-2026-41565 | 7.5 | — | — | — | — | CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. | 135d ago |
| CVE-2026-35672 | 7.5 | — | — | — | — | phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiC | 135d ago |
| CVE-2026-46177 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and receive message | 136d ago |
| CVE-2026-46133 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject unknown opcodes before ICRC p | 136d ago |
| CVE-2026-46124 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file han | 136d ago |
| CVE-2026-46114 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE paylo | 136d ago |
| CVE-2026-46110 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Prevent NULL deref when RX memory | 136d ago |