| CVE-2026-31247 | 7.5 | — | — | — | — | Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. | 152d ago |
| CVE-2025-65418 | 7.5 | — | — | — | — | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arb | 152d ago |
| CVE-2026-8177 | 7.5 | — | — | — | — | XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing | 153d ago |
| CVE-2026-45180 | 7.5 | — | — | — | — | Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. | 153d ago |
| CVE-2021-47944 | 7.5 | — | — | — | — | memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pa | 153d ago |
| CVE-2026-7263 | 7.5 | — | — | — | php / php | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorre | 154d ago |
| CVE-2026-7568 | 7.5 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphon | 154d ago |
| CVE-2026-7262 | 7.5 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP | 154d ago |
| CVE-2026-7258 | 7.5 | — | — | — | php / php | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functio | 154d ago |
| CVE-2026-33538 | 7.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 200d ago |
| CVE-2026-33508 | 7.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 200d ago |
| CVE-2026-33498 | 7.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 200d ago |
| CVE-2026-32854 | 7.5 | — | — | — | libvncserver project / libvncserver | LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities | 200d ago |
| CVE-2026-33680 | 7.5 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 200d ago |
| CVE-2026-33554 | 7.5 | — | — | — | — | ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. | 200d ago |
| CVE-2026-30653 | 7.5 | — | — | — | free5gc / free5gc | An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function Hand | 200d ago |
| CVE-2026-27651 | 7.5 | — | — | — | f5 / nginx open source | When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can | 200d ago |
| CVE-2026-33497exploited | 7.5 | 2.0% | 1/3 | +140d | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 200d ago |
| CVE-2026-33484 | 7.5 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 200d ago |
| CVE-2026-33418 | 7.5 | — | — | — | dicebear / dicebear | DiceBear is an avatar library for designers and developers. | 200d ago |
| CVE-2026-4727 | 7.5 | — | — | — | mozilla / firefox | Denial-of-service in the Libraries component in NSS. | 200d ago |
| CVE-2026-4726 | 7.5 | — | — | — | mozilla / firefox | Denial-of-service in the XML component. | 200d ago |
| CVE-2026-4719 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics: Text component. | 200d ago |
| CVE-2026-4714 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video component. | 200d ago |
| CVE-2026-4713 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics component. | 200d ago |
| CVE-2026-4712 | 7.5 | — | — | — | mozilla / firefox | Information disclosure in the Widget: Cocoa component. | 200d ago |
| CVE-2026-4709 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: GMP component. | 200d ago |
| CVE-2026-4708 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics component. | 200d ago |
| CVE-2026-4707 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics: Canvas2D component. | 200d ago |
| CVE-2026-4706 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics: Canvas2D component. | 200d ago |
| CVE-2026-4704 | 7.5 | — | — | — | mozilla / firefox | Denial-of-service in the WebRTC: Signaling component. | 200d ago |
| CVE-2026-4699 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Layout: Text and Fonts component. | 200d ago |
| CVE-2026-4697 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: Web Codecs component. | 200d ago |
| CVE-2026-4695 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: Web Codecs component. | 200d ago |
| CVE-2026-4694 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions, integer overflow in the Graphics component. | 200d ago |
| CVE-2026-4693 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: Playback component. | 200d ago |
| CVE-2026-4686 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics: Canvas2D component. | 200d ago |
| CVE-2026-4685 | 7.5 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics: Canvas2D component. | 200d ago |
| CVE-2026-4684 | 7.5 | — | — | — | mozilla / firefox | Race condition, use-after-free in the Graphics: WebRender component. | 200d ago |
| CVE-2026-3509 | 7.5 | — | — | — | — | An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log | 200d ago |
| CVE-2026-33852 | 7.5 | — | — | — | molotovcherry / android-imagemagick7 | Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue | 201d ago |
| CVE-2026-33856 | 7.5 | — | — | — | molotovcherry / android-imagemagick7 | Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue | 201d ago |
| CVE-2026-4662 | 7.5 | — | — | — | — | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all ve | 201d ago |
| CVE-2026-4640 | 7.5 | — | — | — | gss / vitalsesp | Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticat | 201d ago |
| CVE-2026-33307 | 7.5 | — | — | — | mod gnutls project / mod gnutls | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. | 201d ago |
| CVE-2026-33306 | 7.5 | — | — | — | bcrypt-ruby project / bcrypt-ruby | bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. | 201d ago |
| CVE-2026-33282 | 7.5 | — | — | — | ellanetworks / ella core | Ella Core is a 5G core designed for private networks. | 201d ago |
| CVE-2026-33250 | 7.5 | — | — | — | — | Freeciv21 is a free open source, turn-based, empire-building strategy game. | 201d ago |
| CVE-2026-33242 | 7.5 | — | — | — | salvo / salvo | Salvo is a Rust web framework. | 201d ago |
| CVE-2026-33241 | 7.5 | — | — | — | salvo / salvo | Salvo is a Rust web framework. | 201d ago |
| CVE-2026-33176 | 7.5 | — | — | — | rubyonrails / rails | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. | 201d ago |
| CVE-2026-33174 | 7.5 | — | — | — | rubyonrails / rails | Active Storage allows users to attach cloud and local files in Rails applications. | 201d ago |
| CVE-2026-4306 | 7.5 | — | — | — | — | The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up | 201d ago |
| CVE-2026-32299 | 7.5 | — | — | — | opensource-workshop / connect-cms | Connect-CMS is a content management system. | 201d ago |
| CVE-2026-23482 | 7.5 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 201d ago |
| CVE-2026-33512 | 7.5 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 201d ago |
| CVE-2026-26209 | 7.5 | — | — | — | agronholm / cbor2 | cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. | 201d ago |
| CVE-2026-25075 | 7.5 | — | — | — | — | strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser tha | 201d ago |
| CVE-2025-15606 | 7.5 | — | — | — | tp-link / td-w8961nd firmware | A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input s | 201d ago |
| CVE-2026-26829 | 7.5 | — | — | — | — | A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allow | 201d ago |