| CVE-2026-7797 | 7.5 | — | — | — | — | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable t | 136d ago |
| CVE-2026-32995 | 7.5 | — | — | — | — | The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0 | 136d ago |
| CVE-2026-44660 | 7.5 | — | — | — | ultrajson project / ultrajson | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. | 136d ago |
| CVE-2026-8361 | 7.5 | — | — | — | — | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome | 136d ago |
| CVE-2026-8360 | 7.5 | — | — | — | — | Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, | 136d ago |
| CVE-2026-8359 | 7.5 | — | — | — | — | When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loade | 136d ago |
| CVE-2026-45104 | 7.5 | — | — | — | osgeo / mapserver | MapServer is a system for developing web-based GIS applications. | 136d ago |
| CVE-2026-44635 | 7.5 | — | — | — | — | Kysely is a type-safe TypeScript SQL query builder. | 136d ago |
| CVE-2026-48151 | 7.5 | — | — | — | — | Budibase is an open-source low-code platform. | 136d ago |
| CVE-2026-45090 | 7.5 | — | — | — | — | Dalfox is a powerful open-source XSS scanner and utility focused on automation. | 136d ago |
| CVE-2026-45088 | 7.5 | — | — | — | — | Dalfox is a powerful open-source XSS scanner and utility focused on automation. | 136d ago |
| CVE-2026-45047 | 7.5 | — | — | — | — | bird-lg-go is a BIRD looking glass in Go. | 136d ago |
| CVE-2026-44378 | 7.5 | — | — | — | botan project / botan | Botan is a C++ cryptography library. | 136d ago |
| CVE-2026-44325 | 7.5 | — | — | — | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 136d ago |
| CVE-2026-44322 | 7.5 | — | — | — | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 136d ago |
| CVE-2026-44321 | 7.5 | — | — | — | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 136d ago |
| CVE-2026-44319 | 7.5 | — | — | — | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 136d ago |
| CVE-2026-44316 | 7.5 | — | — | — | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 136d ago |
| CVE-2026-42459 | 7.5 | — | — | — | free5gc / free5gc | free5GC is an open-source implementation of the 5G core network. | 136d ago |
| CVE-2026-48922 | 7.5 | — | — | — | jenkins / credentials binding | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file a | 137d ago |
| CVE-2026-48921 | 7.5 | — | — | — | jenkins / pipeline\ | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in sh | 137d ago |
| CVE-2026-48544 | 7.5 | — | — | — | — | Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() | 137d ago |
| CVE-2026-45022 | 7.5 | — | — | — | go-git project / go-git | go-git is an extensible git implementation library written in pure Go. | 137d ago |
| CVE-2026-44902 | 7.5 | — | — | — | opentelemetry / opentelemetry\/auto-instrumentations-node | opentelemetry-js is the OpenTelemetry JavaScript Client. | 137d ago |
| CVE-2026-8180 | 7.5 | — | — | — | ibm / aspera high-speed transfer endpoint | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3. | 137d ago |
| CVE-2026-48972 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 137d ago |
| CVE-2026-46102 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: strparser: fix skb_head leak in strp_abor | 137d ago |
| CVE-2026-46085 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix rxkad crypto unalignment handling F | 137d ago |
| CVE-2026-46052 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ceph: only d_add() negative dentries when they | 137d ago |
| CVE-2026-46031 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Reinstate disabling of BHs around | 137d ago |
| CVE-2026-46027 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid early lgr access in smc_clc_wai | 137d ago |
| CVE-2026-46024 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: libceph: Prevent potential null-ptr-deref in c | 137d ago |
| CVE-2026-45944 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing d | 137d ago |
| CVE-2026-45860 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connecti | 137d ago |
| CVE-2026-45859 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: do shared-unconfir | 137d ago |
| CVE-2026-3366 | 7.5 | — | — | — | ibm / infosphere optim test data fabrication | IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0. | 137d ago |
| CVE-2026-42760 | 7.5 | — | — | — | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Ca | 137d ago |
| CVE-2026-42736 | 7.5 | — | — | — | — | Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages a | 137d ago |
| CVE-2026-40850 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountDat | 137d ago |
| CVE-2025-14713 | 7.5 | — | — | — | synology / c2 identity edge server | An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1. | 137d ago |
| CVE-2026-40819 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 t | 137d ago |
| CVE-2026-40818 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_ge | 137d ago |
| CVE-2026-40817 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfi | 137d ago |
| CVE-2026-40816 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php | 137d ago |
| CVE-2026-40815 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getU | 137d ago |
| CVE-2026-40814 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php f | 137d ago |
| CVE-2026-40813 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues | 137d ago |
| CVE-2026-40812 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues | 137d ago |
| CVE-2026-40811 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractse | 137d ago |
| CVE-2026-40810 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endp | 137d ago |
| CVE-2026-9200 | 7.5 | — | — | — | — | The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including | 137d ago |
| CVE-2026-48959 | 7.5 | — | — | — | — | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. | 137d ago |
| CVE-2026-44905 | 7.5 | — | — | — | — | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. | 137d ago |
| CVE-2026-43988 | 7.5 | — | — | — | — | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. | 137d ago |
| CVE-2026-44847 | 7.5 | — | — | — | — | MaxKB is an open-source AI assistant for enterprise. | 137d ago |
| CVE-2026-44209 | 7.5 | — | — | — | — | Banks generates meaningful LLM prompts using a template language that makes sense. | 137d ago |
| CVE-2026-8854 | 7.5 | — | — | — | ibm / http server | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. | 137d ago |
| CVE-2026-8620 | 7.5 | — | — | — | ibm / websphere application server | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application S | 137d ago |
| CVE-2026-8850 | 7.5 | — | — | — | ibm / http server | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload. | 137d ago |
| CVE-2026-48901 | 7.5 | — | — | — | joomla / joomla\! | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. | 137d ago |