| CVE-2026-40629 | 7.5 | — | — | — | f5 / big-ip access policy manager | When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop pro | 150d ago |
| CVE-2026-40618 | 7.5 | — | — | — | f5 / big-ip access policy manager | When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Tec | 150d ago |
| CVE-2026-40423 | 7.5 | — | — | — | f5 / big-ip access policy manager | When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microke | 150d ago |
| CVE-2026-40067 | 7.5 | — | — | — | f5 / big-ip access policy manager | When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process | 150d ago |
| CVE-2026-40060 | 7.5 | — | — | — | f5 / big-ip application security manager | When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can caus | 150d ago |
| CVE-2026-39458 | 7.5 | — | — | — | f5 / big-ip access policy manager | When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanc | 150d ago |
| CVE-2026-39455 | 7.5 | — | — | — | f5 / big-ip access policy manager | When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentica | 150d ago |
| CVE-2025-28344 | 7.5 | — | — | — | — | striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack. | 150d ago |
| CVE-2025-28343 | 7.5 | — | — | — | — | striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons. | 150d ago |
| CVE-2020-37220 | 7.5 | — | — | — | — | Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to ob | 150d ago |
| CVE-2020-37219 | 7.5 | — | — | — | — | Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to lis | 150d ago |
| CVE-2026-39806 | 7.5 | — | — | — | mtrudel / bandit | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remo | 150d ago |
| CVE-2026-39803 | 7.5 | — | — | — | mtrudel / bandit | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote | 150d ago |
| CVE-2026-6276 | 7.5 | — | — | — | haxx / curl | Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently d | 150d ago |
| CVE-2026-5773 | 7.5 | — | — | — | haxx / curl | libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. | 150d ago |
| CVE-2026-4798 | 7.5 | — | — | — | — | The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter | 150d ago |
| CVE-2026-6929 | 7.5 | — | — | — | — | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based | 151d ago |
| CVE-2026-8336 | 7.5 | — | — | — | mongodb / mongodb | After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map functi | 151d ago |
| CVE-2026-1250 | 7.5 | — | — | — | — | The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injecti | 151d ago |
| CVE-2026-44302 | 7.5 | — | — | — | — | Snappier is a high performance C# implementation of the Snappy compression algorithm. | 151d ago |
| CVE-2026-44296 | 7.5 | — | — | — | — | Deskflow is a keyboard and mouse sharing app. | 151d ago |
| CVE-2026-44241 | 7.5 | — | — | — | — | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM ap | 151d ago |
| CVE-2026-42855 | 7.5 | — | — | — | espressif / arduino-esp32 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrolle | 151d ago |
| CVE-2026-42544 | 7.5 | — | — | — | — | Granian is a Rust HTTP server for Python applications. | 151d ago |
| CVE-2026-42268 | 7.5 | — | — | — | owasp / modsecurity | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. | 151d ago |
| CVE-2026-40902 | 7.5 | — | — | — | phpoffice / phpspreadsheet | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. | 151d ago |
| CVE-2026-40863 | 7.5 | — | — | — | phpoffice / phpspreadsheet | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. | 151d ago |
| CVE-2026-44240 | 7.5 | — | — | — | — | basic-ftp is an FTP client for Node.js. | 151d ago |
| CVE-2026-34665 | 7.5 | — | — | — | adobe / c2pa | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource | 151d ago |
| CVE-2026-34652 | 7.5 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-34651 | 7.5 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-34650 | 7.5 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-34649 | 7.5 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-34648 | 7.5 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-34646 | 7.5 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-34645 | 7.5 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-23827 | 7.5 | — | — | — | arubanetworks / arubaos | A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could a | 151d ago |
| CVE-2026-23826 | 7.5 | — | — | — | arubanetworks / arubaos | A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote at | 151d ago |
| CVE-2026-23825 | 7.5 | — | — | — | arubanetworks / arubaos | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. | 151d ago |
| CVE-2026-23824 | 7.5 | — | — | — | arubanetworks / arubaos | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. | 151d ago |
| CVE-2026-44167 | 7.5 | — | — | — | — | phpseclib is a PHP secure communications library. | 151d ago |
| CVE-2026-43891 | 7.5 | — | — | — | webtechnologies / changedetection | changedetection.io is a free open source web page change detection tool. | 151d ago |
| CVE-2026-42899 | 7.5 | — | — | — | microsoft / .net | Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny ser | 151d ago |
| CVE-2026-41895 | 7.5 | — | — | — | webtechnologies / changedetection | changedetection.io is a free open source web page change detection tool. | 151d ago |
| CVE-2026-40406 | 7.5 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network. | 151d ago |
| CVE-2026-40405 | 7.5 | — | — | — | microsoft / windows 11 24h2 | Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 151d ago |
| CVE-2026-35424 | 7.5 | — | — | — | microsoft / windows 10 1607 | Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unaut | 151d ago |
| CVE-2026-32161 | 7.5 | — | — | — | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi | 151d ago |
| CVE-2026-31240 | 7.5 | — | — | — | — | The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. | 151d ago |
| CVE-2025-46311 | 7.5 | — | — | — | apple / ipados | An inconsistent user interface issue was addressed with improved state management. | 151d ago |
| CVE-2026-20887 | 7.5 | — | — | — | intel / vision | Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow | 151d ago |
| CVE-2026-43513 | 7.5 | — | — | — | apache / tomcat | Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. | 151d ago |
| CVE-2026-41284 | 7.5 | — | — | — | apache / tomcat | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. | 151d ago |
| CVE-2026-6866 | 7.5 | — | — | — | schneider-electric / ecostruxure panel server pas400 firmware | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized d | 151d ago |
| CVE-2026-41712 | 7.5 | — | — | — | vmware / spring ai | Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could resu | 151d ago |
| CVE-2026-8162 | 7.5 | — | — | — | pillarjs / multiparty | multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. | 151d ago |
| CVE-2026-8161 | 7.5 | — | — | — | pillarjs / multiparty | multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. | 151d ago |
| CVE-2026-8159 | 7.5 | — | — | — | pillarjs / multiparty | multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the | 151d ago |
| CVE-2026-33893 | 7.5 | — | — | — | siemens / teamcenter | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All version | 151d ago |
| CVE-2026-22925 | 7.5 | — | — | — | siemens / simatic cn 4100 firmware | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). | 151d ago |