| CVE-2026-27934 | 7.5 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 205d ago |
| CVE-2026-3547 | 7.5 | — | — | — | wolfssl / wolfssl | Out-of-bounds read in ALPN parsing due to incomplete validation. | 205d ago |
| CVE-2026-25667 | 7.5 | — | — | — | microsoft / .net | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to ca | 205d ago |
| CVE-2026-2645 | 7.5 | — | — | — | wolfssl / wolfssl | In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. | 205d ago |
| CVE-2026-30403 | 7.5 | — | — | — | wgstart / wgcloud | There is an arbitrary file read vulnerability in the test connection function of backend database management in wg | 205d ago |
| CVE-2026-3029 | 7.5 | — | — | — | — | A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPD | 205d ago |
| CVE-2026-30404 | 7.5 | — | — | — | wgstart / wgcloud | The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) | 205d ago |
| CVE-2026-4424 | 7.5 | — | — | — | libarchive / libarchive | A flaw was found in libarchive. | 205d ago |
| CVE-2026-3658 | 7.5 | — | — | — | — | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable t | 205d ago |
| CVE-2006-10002 | 7.5 | — | — | — | toddr / xml\ | XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (d | 205d ago |
| CVE-2026-25443 | 7.5 | — | — | — | — | Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-ord | 205d ago |
| CVE-2026-25312 | 7.5 | — | — | — | — | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting | 205d ago |
| CVE-2026-28461 | 7.5 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint | 206d ago |
| CVE-2026-32805 | 7.5 | — | — | — | ctfer-io / romeo | Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for fu | 206d ago |
| CVE-2026-32944 | 7.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 206d ago |
| CVE-2026-32886 | 7.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 206d ago |
| CVE-2026-32878 | 7.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 206d ago |
| CVE-2026-31973 | 7.5 | — | — | — | samtools / samtools | SAMtools is a program for reading, manipulating and writing bioinformatics file formats. | 206d ago |
| CVE-2026-31964 | 7.5 | — | — | — | htslib / htslib | HTSlib is a library for reading and writing bioinformatics file formats. | 206d ago |
| CVE-2026-29858 | 7.5 | — | — | — | aapanel / aapanel | A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot s | 206d ago |
| CVE-2026-29856 | 7.5 | — | — | — | aapanel / aapanel | An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a | 206d ago |
| CVE-2026-27135 | 7.5 | — | — | — | nghttp2 / nghttp2 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. | 206d ago |
| CVE-2025-71269 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallbac | 206d ago |
| CVE-2025-71268 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error path | 206d ago |
| CVE-2026-30345 | 7.5 | — | — | — | — | A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write a | 206d ago |
| CVE-2026-33002 | 7.5 | — | — | — | jenkins / jenkins | Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin val | 206d ago |
| CVE-2026-32609 | 7.5 | — | — | — | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 206d ago |
| CVE-2026-23242 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereferen | 206d ago |
| CVE-2026-32596 | 7.5 | — | — | — | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 206d ago |
| CVE-2026-32256 | 7.5 | — | — | — | borewit / music-metadata | music-metadata is a metadata parser for audio and video media files. | 207d ago |
| CVE-2026-30922 | 7.5 | — | — | — | pyasn1 / pyasn1 | pyasn1 is a generic ASN.1 library for Python. | 207d ago |
| CVE-2026-29112 | 7.5 | — | — | — | dicebear / dicebear | DiceBear is an avatar library for designers and developers. | 207d ago |
| CVE-2026-27980 | 7.5 | — | — | — | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 207d ago |
| CVE-2026-27979 | 7.5 | — | — | — | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 207d ago |
| CVE-2026-22727 | 7.5 | — | — | — | — | Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and belo | 207d ago |
| CVE-2025-14031 | 7.5 | — | — | — | ibm / sterling b2b integrator | IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1 | 207d ago |
| CVE-2026-32838 | 7.5 | — | — | — | edimax / gs-5008pl firmware | Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without im | 207d ago |
| CVE-2026-1376 | 7.5 | — | — | — | ibm / i | IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to | 207d ago |
| CVE-2026-32981 | 7.5 | — | — | — | anyscale / ray | A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. | 207d ago |
| CVE-2026-32297 | 7.5 | — | — | — | angeet / es3 kvm firmware | The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration fil | 207d ago |
| CVE-2026-32295 | 7.5 | — | — | — | jetkvm / kvm | JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials. | 207d ago |
| CVE-2026-32292 | 7.5 | — | — | — | gl-inet / comet gl-rm1 firmware | The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess | 207d ago |
| CVE-2026-28779 | 7.5 | — | — | — | apache / airflow | Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the c | 207d ago |
| CVE-2026-4258 | 7.5 | — | — | — | bitwiseshiftleft / stanford javascript crypto library | All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing | 207d ago |
| CVE-2026-2579 | 7.5 | — | — | — | — | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection v | 208d ago |
| CVE-2026-4269 | 7.5 | — | — | — | amazon / bedrock agentcore starter toolkit | A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a rem | 208d ago |
| CVE-2026-4224 | 7.5 | — | — | — | python / python | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a de | 208d ago |
| CVE-2026-3644 | 7.5 | — | — | — | python / python | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. | 208d ago |
| CVE-2026-28498 | 7.5 | — | — | — | authlib / authlib | Authlib is a Python library which builds OAuth and OpenID Connect servers. | 208d ago |
| CVE-2025-69768 | 7.5 | — | — | — | chyrp / chyrp | SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information v | 208d ago |
| CVE-2025-66687 | 7.5 | — | — | — | — | Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extracti | 208d ago |
| CVE-2026-30405 | 7.5 | — | — | — | osrg / gobgp | An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attri | 208d ago |
| CVE-2026-4276 | 7.5 | — | — | — | librechat / librechat | LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries | 208d ago |
| CVE-2026-32614 | 7.5 | — | — | — | — | Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial | 208d ago |
| CVE-2026-32314 | 7.5 | — | — | — | protocol / yamux | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. | 208d ago |
| CVE-2026-2493 | 7.5 | — | — | — | — | IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. | 208d ago |
| CVE-2026-24458 | 7.5 | — | — | — | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long pass | 208d ago |
| CVE-2026-20999 | 7.5 | — | — | — | samsung / smart switch | Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger priv | 208d ago |
| CVE-2026-1947 | 7.5 | — | — | — | — | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Re | 208d ago |
| CVE-2017-20222 | 7.5 | — | — | — | telesquare / sdt-cs3b1 firmware | Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability | 208d ago |