| CVE-2026-26828 | 7.5 | — | — | — | — | A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652 | 201d ago |
| CVE-2026-33485 | 7.5 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 201d ago |
| CVE-2026-33483 | 7.5 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 201d ago |
| CVE-2026-32969 | 7.5 | — | — | — | — | An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoi | 201d ago |
| CVE-2026-4602 | 7.5 | — | — | — | kjur / jsrsasign | Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to | 201d ago |
| CVE-2026-4598 | 7.5 | — | — | — | kjur / jsrsasign | Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ex | 201d ago |
| CVE-2026-2580 | 7.5 | — | — | — | — | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vu | 202d ago |
| CVE-2026-33292 | 7.5 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 202d ago |
| CVE-2019-25613 | 7.5 | — | — | — | echatserver / easy chat server | Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the applicat | 202d ago |
| CVE-2019-25605 | 7.5 | — | — | — | — | EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user creden | 202d ago |
| CVE-2019-25579 | 7.5 | — | — | — | codnloc / phptransformer | phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access | 203d ago |
| CVE-2019-25560 | 7.5 | — | — | — | lyricvideocreator / lyric video creator | Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application | 203d ago |
| CVE-2019-25552 | 7.5 | — | — | — | cewe / photo show | CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by | 203d ago |
| CVE-2026-4373 | 7.5 | — | — | — | — | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up | 203d ago |
| CVE-2026-2468 | 7.5 | — | — | — | — | The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions u | 203d ago |
| CVE-2026-1800 | 7.5 | — | — | — | — | The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSele | 203d ago |
| CVE-2026-32056 | 7.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the | 204d ago |
| CVE-2026-32049 | 7.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buff | 204d ago |
| CVE-2026-32048 | 7.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operatio | 204d ago |
| CVE-2026-33427 | 7.5 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 204d ago |
| CVE-2026-32666 | 7.5 | — | — | — | — | WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. | 204d ago |
| CVE-2026-33476 | 7.5 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 204d ago |
| CVE-2026-33231 | 7.5 | — | — | — | nltk / nltk | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting rese | 204d ago |
| CVE-2026-33204 | 7.5 | — | — | — | kelvinmo / simplejwt | SimpleJWT is a simple JSON web token library written in PHP. | 204d ago |
| CVE-2026-33203 | 7.5 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 204d ago |
| CVE-2026-33180 | 7.5 | — | — | — | — | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. | 204d ago |
| CVE-2026-31904 | 7.5 | — | — | — | ctek / charge portal | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. | 204d ago |
| CVE-2026-31903 | 7.5 | — | — | — | igl / eparking.fi | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. | 204d ago |
| CVE-2026-23536exploited | 7.5 | 2.4% | 1/3 | +178d | — | A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthentic | 204d ago |
| CVE-2026-33164 | 7.5 | — | — | — | struktur / libde265 | libde265 is an open source implementation of the h.265 video codec. | 204d ago |
| CVE-2026-33155 | 7.5 | — | — | — | qluster / deepdiff | DeepDiff is a project focused on Deep Difference and search of any Python data. | 204d ago |
| CVE-2026-33154 | 7.5 | — | — | — | dynaconf / dynaconf | dynaconf is a configuration management tool for Python. | 204d ago |
| CVE-2026-33151 | 7.5 | — | — | — | socket / socket.io-parser | Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. | 204d ago |
| CVE-2026-33143 | 7.5 | — | — | — | hackerbay / oneuptime | OneUptime is a solution for monitoring and managing online services. | 204d ago |
| CVE-2026-4437 | 7.5 | — | — | — | gnu / glibc | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend i | 204d ago |
| CVE-2026-32309 | 7.5 | — | — | — | cryptomator / cryptomator | Cryptomator encrypts data being stored on cloud infrastructure. | 204d ago |
| CVE-2025-46597 | 7.5 | — | — | — | bitcoin / bitcoin core | Bitcoin Core 0.13.0 through 29.x has an integer overflow. | 204d ago |
| CVE-2026-33128 | 7.5 | — | — | — | h3 / h3 | H3 is a minimal H(TTP) framework. | 204d ago |
| CVE-2026-33069 | 7.5 | — | — | — | pjsip / pjsip | PJSIP is a free and open source multimedia communication library written in C. | 204d ago |
| CVE-2026-32701 | 7.5 | — | — | — | qwik / qwik | Qwik is a performance-focused JavaScript framework. | 204d ago |
| CVE-2026-33064 | 7.5 | — | — | — | free5gc / udm | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. | 204d ago |
| CVE-2026-33040 | 7.5 | — | — | — | protocol / libp2p-gossipsub | libp2p-rust is the official rust language Implementation of the libp2p networking stack. | 204d ago |
| CVE-2026-33036 | 7.5 | — | — | — | naturalintelligence / fast-xml-parser | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. | 204d ago |
| CVE-2026-33013 | 7.5 | — | — | — | objectcomputing / micronaut | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM ap | 204d ago |
| CVE-2026-33012 | 7.5 | — | — | — | objectcomputing / micronaut | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM ap | 204d ago |
| CVE-2026-33011 | 7.5 | — | — | — | nestjs / nest | Nest is a framework for building scalable Node.js server-side applications. | 204d ago |
| CVE-2026-32949 | 7.5 | — | — | — | fit2cloud / sqlbot | SQLBot is an intelligent data query system based on a large language model and RAG. | 204d ago |
| CVE-2026-33063 | 7.5 | — | — | — | free5gc / free5gc | free5GC is an open source 5G core network. | 205d ago |
| CVE-2026-33062 | 7.5 | — | — | — | free5gc / free5gc | free5GC is an open source 5G core network. | 205d ago |
| CVE-2026-32933 | 7.5 | — | — | — | luckypennysoftware / automapper | AutoMapper is a convention-based object-object mapper in .NET. | 205d ago |
| CVE-2026-32875 | 7.5 | — | — | — | ultrajson project / ultrajson | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. | 205d ago |
| CVE-2026-32874 | 7.5 | — | — | — | ultrajson project / ultrajson | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. | 205d ago |
| CVE-2026-32873 | 7.5 | — | — | — | vshakitskiy / ewe | ewe is a Gleam web server. | 205d ago |
| CVE-2026-32829 | 7.5 | — | — | — | pseitz / lz4 flex | lz4_flex is a pure Rust implementation of LZ4 compression/decompression. | 205d ago |
| CVE-2026-29097 | 7.5 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 205d ago |
| CVE-2026-32815 | 7.5 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 205d ago |
| CVE-2026-32030 | 7.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that | 205d ago |
| CVE-2026-32025 | 7.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients t | 205d ago |
| CVE-2026-32011 | 7.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles | 205d ago |
| CVE-2026-29072 | 7.5 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 205d ago |