| CVE-2026-42944 | 7.5 | — | — | — | nlnetlabs / unbound | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow whe | 144d ago |
| CVE-2026-41292 | 7.5 | — | — | — | nlnetlabs / unbound | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to | 144d ago |
| CVE-2026-40622 | 7.5 | — | — | — | nlnetlabs / unbound | NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' famil | 144d ago |
| CVE-2026-9010 | 7.5 | — | — | — | — | The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' para | 144d ago |
| CVE-2026-9003 | 7.5 | — | — | — | — | E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remot | 144d ago |
| CVE-2026-24210 | 7.5 | — | — | — | nvidia / triton inference server | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. | 144d ago |
| CVE-2026-24209 | 7.5 | — | — | — | nvidia / triton inference server | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. | 144d ago |
| CVE-2026-24163 | 7.5 | — | — | — | nvidia / tensorrt llm | NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe d | 144d ago |
| CVE-2025-33255 | 7.5 | — | — | — | nvidia / tensorrt llm | NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe de | 144d ago |
| CVE-2026-3985 | 7.5 | — | — | — | — | The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Inject | 144d ago |
| CVE-2026-8073 | 7.5 | — | — | — | — | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary fil | 144d ago |
| CVE-2026-33633 | 7.5 | — | — | — | kovidgoyal / kitty | Kitty is a cross-platform GPU based terminal. | 144d ago |
| CVE-2026-47358 | 7.5 | — | — | — | tenable / terrascan | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in up | 144d ago |
| CVE-2026-47357 | 7.5 | — | — | — | tenable / terrascan | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in t | 144d ago |
| CVE-2026-47356 | 7.5 | — | — | — | tenable / terrascan | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in | 144d ago |
| CVE-2026-47100zero day | 7.5 | 0.49% | 1/3 | 5d before | — | Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the pu | 144d ago |
| CVE-2026-43634 | 7.5 | — | — | — | — | HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote atta | 144d ago |
| CVE-2026-8968 | 7.5 | — | — | — | mozilla / firefox | Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. | 144d ago |
| CVE-2026-8967 | 7.5 | — | — | — | mozilla / firefox | Information disclosure in the Graphics: WebGPU component. | 144d ago |
| CVE-2026-8966 | 7.5 | — | — | — | mozilla / firefox | Information disclosure in the IP Protection component. | 144d ago |
| CVE-2026-8965 | 7.5 | — | — | — | mozilla / firefox | Information disclosure in the DOM: Security component. | 144d ago |
| CVE-2026-8964 | 7.5 | — | — | — | mozilla / firefox | Spoofing issue in the Popup Blocker component. | 144d ago |
| CVE-2026-8963 | 7.5 | — | — | — | mozilla / firefox | Spoofing issue in the Web Speech component. | 144d ago |
| CVE-2026-8960 | 7.5 | — | — | — | mozilla / firefox | Spoofing issue in WebExtensions. | 144d ago |
| CVE-2026-8954 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions, integer overflow in the Audio/Video component. | 144d ago |
| CVE-2026-8949 | 7.5 | — | — | — | mozilla / firefox | Integer overflow in the Widget: Win32 component. | 144d ago |
| CVE-2026-8946 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: Web Codecs component. | 144d ago |
| CVE-2026-8945 | 7.5 | — | — | — | mozilla / firefox | Sandbox escape in Firefox and Firefox Focus for Android. | 144d ago |
| CVE-2026-42100 | 7.5 | — | — | — | sparxsystems / pro cloud server | Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) atta | 144d ago |
| CVE-2026-42099 | 7.5 | — | — | — | sparxsystems / pro cloud server | Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. | 144d ago |
| CVE-2026-8912 | 7.5 | — | — | — | — | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions | 144d ago |
| CVE-2026-7507 | 7.5 | — | — | — | redhat / build of keycloak | A session fixation vulnerability was found in Keycloak's login-actions endpoints. | 144d ago |
| CVE-2026-7307 | 7.5 | — | — | — | redhat / build of keycloak | A flaw was found in Keycloak. | 144d ago |
| CVE-2026-31910 | 7.5 | — | — | — | apache / ofbiz | Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. | 145d ago |
| CVE-2026-31909 | 7.5 | — | — | — | apache / ofbiz | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. | 145d ago |
| CVE-2026-8813 | 7.5 | — | — | — | — | This affects versions of the package exifreader before 4.39.0. | 145d ago |
| CVE-2025-15609 | 7.5 | — | — | — | — | The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, | 145d ago |
| CVE-2026-33232 | 7.5 | — | — | — | — | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence | 145d ago |
| CVE-2026-29963 | 7.5 | — | — | — | hsclabs / mailinspector | HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in | 145d ago |
| CVE-2026-29962 | 7.5 | — | — | — | hsclabs / mailinspector | HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user- | 145d ago |
| CVE-2025-56352 | 7.5 | — | — | — | — | In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violation | 145d ago |
| CVE-2026-39079 | 7.5 | — | — | — | — | An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitiv | 145d ago |
| CVE-2026-42009 | 7.5 | — | — | — | gnu / gnutls | A flaw was found in gnutls. | 145d ago |
| CVE-2026-6381 | 7.5 | — | — | — | — | The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, al | 146d ago |
| CVE-2018-25329 | 7.5 | — | — | — | — | WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated att | 146d ago |
| CVE-2018-25326 | 7.5 | — | — | — | — | Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to re | 146d ago |
| CVE-2018-25325 | 7.5 | — | — | — | — | Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete a | 146d ago |
| CVE-2021-47977 | 7.5 | — | — | — | — | WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerabilit | 147d ago |
| CVE-2021-47973 | 7.5 | — | — | — | — | Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the applicatio | 147d ago |
| CVE-2021-47972 | 7.5 | — | — | — | — | Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the a | 147d ago |
| CVE-2021-47971 | 7.5 | — | — | — | — | My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pas | 147d ago |
| CVE-2021-47970 | 7.5 | — | — | — | — | Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by cre | 147d ago |
| CVE-2021-47969 | 7.5 | — | — | — | — | Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasti | 147d ago |
| CVE-2021-47942 | 7.5 | — | — | — | hacs / home assistant community store | Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthen | 147d ago |
| CVE-2020-37245 | 7.5 | — | — | — | — | Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows | 147d ago |
| CVE-2026-8696 | 7.5 | — | — | — | radare / radare2 | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core t | 148d ago |
| CVE-2026-45398 | 7.5 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 148d ago |
| CVE-2026-8686 | 7.5 | — | — | — | freertos / coremqtt | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause | 148d ago |
| CVE-2026-46366 | 7.5 | — | — | — | — | phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that la | 148d ago |
| CVE-2026-46359 | 7.5 | — | — | — | — | phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticate | 148d ago |