| CVE-2026-48897 | 7.5 | — | — | — | joomla / joomla\! | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | 137d ago |
| CVE-2026-48896 | 7.5 | — | — | — | joomla / joomla\! | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | 137d ago |
| CVE-2026-45728 | 7.5 | — | — | — | — | Algernon is a small self-contained pure-Go web server. | 137d ago |
| CVE-2026-40384 | 7.5 | — | — | — | joomla / joomla\! | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulne | 137d ago |
| CVE-2026-24212 | 7.5 | — | — | — | nvidia / isaac launchable | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear tex | 137d ago |
| CVE-2026-48688 | 7.5 | — | — | — | pavel-odintsov / fastnetmon | FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 att | 137d ago |
| CVE-2026-48133 | 7.5 | — | — | — | — | When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be abl | 137d ago |
| CVE-2025-11482 | 7.5 | — | — | — | — | An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating | 137d ago |
| CVE-2026-39661 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 138d ago |
| CVE-2026-8047 | 7.5 | — | — | — | — | The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-lim | 138d ago |
| CVE-2026-9496 | 7.5 | — | — | — | — | Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addG | 138d ago |
| CVE-2026-9538 | 7.5 | — | — | — | archive\ / \ | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar | 138d ago |
| CVE-2026-42497 | 7.5 | — | — | — | archive\ / \ | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction d | 138d ago |
| CVE-2026-45438 | 7.5 | — | — | — | — | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Confi | 138d ago |
| CVE-2026-45209 | 7.5 | — | — | — | — | Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured | 138d ago |
| CVE-2026-48844 | 7.5 | — | — | — | — | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autova | 138d ago |
| CVE-2026-47077 | 7.5 | — | — | — | benoitc / hackney | Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. | 138d ago |
| CVE-2026-47075 | 7.5 | — | — | — | benoitc / hackney | Improper Neutralization of CRLF Sequences vulnerability in benoitc hackney allows HTTP Request Splitting. | 138d ago |
| CVE-2026-47073 | 7.5 | — | — | — | benoitc / hackney | Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. | 138d ago |
| CVE-2026-47072 | 7.5 | — | — | — | benoitc / hackney | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Request/ | 138d ago |
| CVE-2026-47071 | 7.5 | — | — | — | benoitc / hackney | Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. | 138d ago |
| CVE-2026-47067 | 7.5 | — | — | — | benoitc / hackney | Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. | 138d ago |
| CVE-2026-47066 | 7.5 | — | — | — | benoitc / hackney | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocatio | 138d ago |
| CVE-2018-25374 | 7.5 | — | — | — | — | Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthentic | 138d ago |
| CVE-2018-25368 | 7.5 | — | — | — | — | Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the app | 138d ago |
| CVE-2018-25365 | 7.5 | — | — | — | — | PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitra | 138d ago |
| CVE-2026-48829 | 7.5 | — | — | — | — | In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a know | 140d ago |
| CVE-2018-25358 | 7.5 | — | — | — | — | D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retri | 140d ago |
| CVE-2026-23663 | 7.5 | — | — | — | microsoft / global secure access | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a netwo | 141d ago |
| CVE-2025-45145 | 7.5 | — | — | — | — | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote | 141d ago |
| CVE-2026-8671 | 7.5 | — | — | — | avantra / avantra | Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows all | 141d ago |
| CVE-2026-44417 | 7.5 | — | — | — | apache / cxf | The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that | 141d ago |
| CVE-2026-5740 | 7.5 | — | — | — | mattermost / mattermost server | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly vali | 141d ago |
| CVE-2026-9011 | 7.5 | — | — | — | — | The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass | 142d ago |
| CVE-2026-8679 | 7.5 | — | — | — | — | The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and incl | 142d ago |
| CVE-2026-4834 | 7.5 | — | — | — | — | The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions u | 142d ago |
| CVE-2026-46597 | 7.5 | — | — | — | golang / crypto | An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well- | 142d ago |
| CVE-2026-39829 | 7.5 | — | — | — | golang / crypto | The RSA and DSA public key parsers did not enforce size limits on key parameters. | 142d ago |
| CVE-2026-46473 | 7.5 | — | — | — | — | Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. | 142d ago |
| CVE-2025-13479 | 7.5 | — | — | — | — | Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. | 142d ago |
| CVE-2026-45255 | 7.5 | — | — | — | freebsd / freebsd | When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names | 143d ago |
| CVE-2026-42001 | 7.5 | — | — | — | powerdns / authoritative | Insufficient Validation of Autoprimary SOA Queries | 143d ago |
| CVE-2026-44062 | 7.5 | — | — | — | — | A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authe | 143d ago |
| CVE-2026-44060 | 7.5 | — | — | — | — | An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker t | 143d ago |
| CVE-2026-44055 | 7.5 | — | — | — | — | A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attack | 143d ago |
| CVE-2026-44052 | 7.5 | — | — | — | — | Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an atta | 143d ago |
| CVE-2026-44049 | 7.5 | — | — | — | — | An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allow | 143d ago |
| CVE-2026-40092 | 7.5 | — | — | — | — | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. | 143d ago |
| CVE-2026-47373 | 7.5 | — | — | — | — | Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. | 143d ago |
| CVE-2026-9137 | 7.5 | — | — | — | misp-project / misp | The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to | 143d ago |
| CVE-2026-9123 | 7.5 | — | — | — | google / chrome | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a l | 143d ago |
| CVE-2026-9117 | 7.5 | — | — | — | google / chrome | Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had | 143d ago |
| CVE-2026-20239 | 7.5 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2. | 143d ago |
| CVE-2026-39047 | 7.5 | — | — | — | — | Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RA | 143d ago |
| CVE-2025-32750 | 7.5 | — | — | — | dell / powerflex appliance intelligent catalog | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulner | 143d ago |
| CVE-2026-5947 | 7.5 | — | — | — | isc / bind | Undefined behavior may result due to a race condition leading to a use-after-free violation. | 143d ago |
| CVE-2026-5946 | 7.5 | — | — | — | isc / bind | Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet | 143d ago |
| CVE-2026-3039 | 7.5 | — | — | — | isc / bind | BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive me | 143d ago |
| CVE-2026-9064 | 7.5 | — | — | — | redhat / directory server | A flaw was found in 389-ds-base. | 144d ago |
| CVE-2026-42959 | 7.5 | — | — | — | nlnetlabs / unbound | NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validato | 144d ago |