| CVE-2017-20220 | 7.5 | — | — | — | — | Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauth | 208d ago |
| CVE-2017-20217 | 7.5 | — | — | — | — | Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the | 208d ago |
| CVE-2013-20006 | 7.5 | — | — | — | — | Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where | 208d ago |
| CVE-2026-4111 | 7.5 | — | — | — | — | A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the ar | 211d ago |
| CVE-2026-3045 | 7.5 | — | — | — | — | The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized | 211d ago |
| CVE-2026-32597 | 7.5 | — | — | — | pyjwt project / pyjwt | PyJWT is a JSON Web Token implementation in Python. | 211d ago |
| CVE-2026-32426 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 211d ago |
| CVE-2026-32400 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 211d ago |
| CVE-2026-32393 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 211d ago |
| CVE-2026-32392 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 211d ago |
| CVE-2026-32384 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 211d ago |
| CVE-2026-32369 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 211d ago |
| CVE-2026-32364 | 7.5 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 211d ago |
| CVE-2026-32319 | 7.5 | — | — | — | ellanetworks / ella core | Ella Core is a 5G core designed for private networks. | 211d ago |
| CVE-2026-31899 | 7.5 | — | — | — | courtbouillon / cairosvg | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. | 211d ago |
| CVE-2026-31882 | 7.5 | — | — | — | dagu / dagu | Dagu is a workflow engine with a built-in Web user interface. | 211d ago |
| CVE-2026-31814 | 7.5 | — | — | — | protocol / yamux | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. | 211d ago |
| CVE-2026-2890 | 7.5 | — | — | — | — | The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and in | 211d ago |
| CVE-2026-29079 | 7.5 | — | — | — | lexbor / lexbor | Lexbor is a web browser engine library. | 211d ago |
| CVE-2026-29078 | 7.5 | — | — | — | lexbor / lexbor | Lexbor is a web browser engine library. | 211d ago |
| CVE-2026-25819 | 7.5 | — | — | — | — | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmw | 211d ago |
| CVE-2026-22199 | 7.5 | — | — | — | gvectors / wpdiscuz | Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload. | 211d ago |
| CVE-2026-22182 | 7.5 | — | — | — | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to | 211d ago |
| CVE-2025-12455 | 7.5 | — | — | — | opentext / vertica | Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. | 211d ago |
| CVE-2026-2229 | 7.5 | — | — | — | nodejs / undici | ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the ser | 212d ago |
| CVE-2026-1528 | 7.5 | — | — | — | nodejs / undici | ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. | 212d ago |
| CVE-2026-1526 | 7.5 | — | — | — | nodejs / undici | The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during per | 212d ago |
| CVE-2026-32274 | 7.5 | — | — | — | python / black | Black is the uncompromising Python code formatter. | 212d ago |
| CVE-2026-3497 | 7.5 | — | — | — | canonical / ubuntu linux | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. | 212d ago |
| CVE-2026-32236 | 7.5 | — | — | — | linuxfoundation / backstage | Backstage is an open framework for building developer portals. | 212d ago |
| CVE-2025-70873 | 7.5 | — | — | — | sqlite / sqlite | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earl | 212d ago |
| CVE-2026-32141 | 7.5 | — | — | — | webreflection / flatted | flatted is a circular JSON parser. | 212d ago |
| CVE-2026-28254 | 7.5 | — | — | — | trane / tracer sc firmware | A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthen | 212d ago |
| CVE-2026-28253 | 7.5 | — | — | — | trane / tracer sc firmware | A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge c | 212d ago |
| CVE-2026-28356 | 7.5 | — | — | — | — | multipart is a fast multipart/form-data parser for python. | 212d ago |
| CVE-2019-25515 | 7.5 | — | — | — | jettweb / php stock news site script | Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php adminis | 212d ago |
| CVE-2026-3657zero day | 7.5 | 0.58% | 1/3 | same day | — | The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX a | 212d ago |
| CVE-2026-3932 | 7.5 | — | — | — | google / chrome | Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker | 213d ago |
| CVE-2026-3924 | 7.5 | — | — | — | google / chrome | use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromise | 213d ago |
| CVE-2026-32130 | 7.5 | — | — | — | zitadel / zitadel | ZITADEL is an open source identity management platform. | 213d ago |
| CVE-2026-32098 | 7.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 213d ago |
| CVE-2026-31958 | 7.5 | — | — | — | tornadoweb / tornado | Tornado is a Python web framework and asynchronous networking library. | 213d ago |
| CVE-2026-31894 | 7.5 | — | — | — | wegia / wegia | WeGIA is a web manager for charitable institutions. | 213d ago |
| CVE-2026-27703 | 7.5 | — | — | — | riot-os / riot | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things | 213d ago |
| CVE-2026-31887 | 7.5 | — | — | — | shopware / shopware | Shopware is an open commerce platform. | 213d ago |
| CVE-2019-25480 | 7.5 | — | — | — | — | ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to u | 213d ago |
| CVE-2019-25478 | 7.5 | — | — | — | — | GetGo Download Manager 6.2.2.3300 contains a buffer overflow vulnerability that allows remote attackers to cause d | 213d ago |
| CVE-2019-25472 | 7.5 | — | — | — | — | IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dump | 213d ago |
| CVE-2019-25470 | 7.5 | — | — | — | — | eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with mini | 213d ago |
| CVE-2019-25465 | 7.5 | — | — | — | — | Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to a | 213d ago |
| CVE-2026-31872 | 7.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 213d ago |
| CVE-2026-31870 | 7.5 | — | — | — | yhirose / cpp-httplib | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. | 213d ago |
| CVE-2026-31866 | 7.5 | — | — | — | openfeature / flagd | flagd is a feature flag daemon with a Unix philosophy. | 213d ago |
| CVE-2026-30226 | 7.5 | — | — | — | svelte / devalue | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient fo | 213d ago |
| CVE-2026-21888 | 7.5 | — | — | — | emqx / nanomq | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. | 213d ago |
| CVE-2026-1069 | 7.5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allow | 213d ago |
| CVE-2025-14513 | 7.5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6 | 213d ago |
| CVE-2025-13929 | 7.5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, | 213d ago |
| CVE-2026-86098 | 7.4 | — | — | — | — | ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function | 36d ago |
| CVE-2026-85152 | 7.4 | — | — | — | — | undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or dedupli | 36d ago |