| CVE-2026-44826 | 7.5 | — | — | — | — | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. | 148d ago |
| CVE-2021-47959 | 7.5 | — | — | — | — | WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers | 148d ago |
| CVE-2026-46474 | 7.5 | — | — | — | — | Trog::TOTP versions before 1.006 for Perl generate secrets using rand. | 148d ago |
| CVE-2026-8695 | 7.5 | — | — | — | radare / radare2 | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attack | 148d ago |
| CVE-2026-44714 | 7.5 | — | — | — | — | The bitcoinj library is a Java implementation of the Bitcoin protocol. | 148d ago |
| CVE-2026-38728 | 7.5 | — | — | — | — | An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the S | 148d ago |
| CVE-2026-41552 | 7.5 | — | — | — | dhtmlx / pdf export module | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTM | 148d ago |
| CVE-2026-6403 | 7.5 | — | — | — | — | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. | 148d ago |
| CVE-2026-44671 | 7.5 | — | — | — | zitadel / zitadel | ZITADEL is an open source identity management platform. | 149d ago |
| CVE-2026-44673 | 7.5 | — | — | — | — | libyang is a YANG data modeling language library. | 149d ago |
| CVE-2026-8585 | 7.5 | — | — | — | google / chrome | Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who | 149d ago |
| CVE-2026-8557 | 7.5 | — | — | — | google / chrome | Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromi | 149d ago |
| CVE-2026-8547 | 7.5 | — | — | — | google / chrome | Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote a | 149d ago |
| CVE-2026-8521 | 7.5 | — | — | — | google / chrome | Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrar | 149d ago |
| CVE-2026-8510 | 7.5 | — | — | — | google / chrome | Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had comp | 149d ago |
| CVE-2026-46356 | 7.5 | — | — | — | fleetdm / fleet | Fleet is open source device management software. | 149d ago |
| CVE-2026-24899 | 7.5 | — | — | — | fleetdm / fleet | Fleet is open source device management software. | 149d ago |
| CVE-2026-27886 | 7.5 | — | — | — | strapi / strapi | Strapi is an open source headless content management system. | 149d ago |
| CVE-2026-23998 | 7.5 | — | — | — | fleetdm / fleet | Fleet is open source device management software. | 149d ago |
| CVE-2026-6332 | 7.5 | — | — | — | schneider-electric / ecostruxure machine expert hvac | CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensi | 149d ago |
| CVE-2026-42334 | 7.5 | — | — | — | mongoosejs / mongoose | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. | 149d ago |
| CVE-2026-42594 | 7.5 | — | — | — | thecodingmachine / gotenberg | Gotenberg is a Docker-powered stateless API for PDF files. | 149d ago |
| CVE-2026-44375 | 7.5 | — | — | — | — | Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. | 149d ago |
| CVE-2026-44216 | 7.5 | — | — | — | bytecodealliance / wasmtime | Wasmtime is a runtime for WebAssembly. | 149d ago |
| CVE-2026-42186 | 7.5 | — | — | — | openbao / openbao | OpenBao is an open source identity-based secrets management system. | 149d ago |
| CVE-2026-6479 | 7.5 | — | — | — | postgresql / postgresql | Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_ | 149d ago |
| CVE-2026-4031 | 7.5 | — | — | — | — | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, | 149d ago |
| CVE-2026-4029 | 7.5 | — | — | — | — | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all version | 149d ago |
| CVE-2026-6514 | 7.5 | — | — | — | — | The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, | 149d ago |
| CVE-2026-1659 | 7.5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, | 150d ago |
| CVE-2025-14870 | 7.5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10. | 150d ago |
| CVE-2025-14869 | 7.5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10. | 150d ago |
| CVE-2026-46419 | 7.5 | — | — | — | — | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return v | 150d ago |
| CVE-2026-44478 | 7.5 | — | — | — | — | hoppscotch is an open source API development ecosystem. | 150d ago |
| CVE-2026-44439 | 7.5 | — | — | — | lookyloo / playwright capture | PlaywrightCapture is a simple replacement for splash using playwright. | 150d ago |
| CVE-2026-42561 | 7.5 | — | — | — | — | Python-Multipart is a streaming multipart parser for Python. | 150d ago |
| CVE-2026-42304 | 7.5 | — | — | — | twisted / twisted | Twisted is an event-based framework for internet applications, supporting Python 3.6+. | 150d ago |
| CVE-2025-27850 | 7.5 | — | — | — | garmin / empirbus wireless display unit firmware | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. | 150d ago |
| CVE-2026-42552 | 7.5 | — | — | — | — | Flight is an extensible micro-framework for PHP. | 150d ago |
| CVE-2026-42551 | 7.5 | — | — | — | — | Flight is an extensible micro-framework for PHP. | 150d ago |
| CVE-2026-42587 | 7.5 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 150d ago |
| CVE-2026-42583 | 7.5 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 150d ago |
| CVE-2026-42582 | 7.5 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 150d ago |
| CVE-2026-42579 | 7.5 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 150d ago |
| CVE-2026-42578 | 7.5 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 150d ago |
| CVE-2026-42577 | 7.5 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 150d ago |
| CVE-2026-0262 | 7.5 | — | — | — | paloaltonetworks / pan-os | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker | 150d ago |
| CVE-2026-45109 | 7.5 | — | — | — | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 150d ago |
| CVE-2026-44579 | 7.5 | — | — | — | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 150d ago |
| CVE-2026-44004 | 7.5 | — | — | — | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 150d ago |
| CVE-2026-44575 | 7.5 | — | — | — | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 150d ago |
| CVE-2026-44573 | 7.5 | — | — | — | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 150d ago |
| CVE-2026-44432 | 7.5 | — | — | — | python / urllib3 | urllib3 is an HTTP client library for Python. | 150d ago |
| CVE-2026-44290 | 7.5 | — | — | — | protobufjs project / protobufjs | protobufjs compiles protobuf definitions into JavaScript (JS) functions. | 150d ago |
| CVE-2026-44289 | 7.5 | — | — | — | protobufjs project / protobufjs | protobufjs compiles protobuf definitions into JavaScript (JS) functions. | 150d ago |
| CVE-2026-42920 | 7.5 | — | — | — | f5 / big-ip access policy manager | When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traf | 150d ago |
| CVE-2026-42409 | 7.5 | — | — | — | f5 / big-ip next cloud-native network functions | When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a vir | 150d ago |
| CVE-2026-41956 | 7.5 | — | — | — | f5 / big-ip access policy manager | When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Ma | 150d ago |
| CVE-2026-41227 | 7.5 | — | — | — | f5 / big-ip advanced web application firewall | On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase | 150d ago |
| CVE-2026-41218 | 7.5 | — | — | — | f5 / big-ip access policy manager | When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, C | 150d ago |