| CVE-2026-10976 | 7.4 | — | — | — | google / chrome | Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially | 127d ago |
| CVE-2026-10973 | 7.4 | — | — | — | google / chrome | Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin d | 127d ago |
| CVE-2026-10968 | 7.4 | — | — | — | google / chrome | Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a re | 127d ago |
| CVE-2026-50292 | 7.4 | — | — | — | freedesktop / libinput | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev pr | 127d ago |
| CVE-2026-44393 | 7.4 | — | — | — | — | An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. | 127d ago |
| CVE-2025-14774 | 7.4 | — | — | — | abb / t-mac plus | Incorrect Authorization vulnerability in ABB T-MAC Plus. | 129d ago |
| CVE-2025-64390 | 7.4 | — | — | — | — | A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. | 129d ago |
| CVE-2026-10629 | 7.4 | — | — | — | — | SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protecti | 129d ago |
| CVE-2022-4991 | 7.4 | — | — | — | — | Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllab | 130d ago |
| CVE-2026-48555 | 7.4 | — | — | — | — | Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allo | 133d ago |
| CVE-2026-48501 | 7.4 | — | — | — | github / cli | GitHub CLI (gh) is GitHub’s official command line tool. | 133d ago |
| CVE-2026-46579 | 7.4 | — | — | — | redhat / openshift container platform | A flaw was found in the OpenShift Router. | 134d ago |
| CVE-2026-5343 | 7.4 | — | — | — | miniorange / saml sso - service provider | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Pri | 134d ago |
| CVE-2026-46818 | 7.4 | — | — | — | oracle / e-business suite | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). | 134d ago |
| CVE-2026-45373 | 7.4 | — | — | — | — | CodeWhale is a DeepSeek + MiMo coding agent in terminal. | 134d ago |
| CVE-2026-45310 | 7.4 | — | — | — | — | CodeWhale is a DeepSeek + MiMo coding agent in terminal. | 134d ago |
| CVE-2026-48526 | 7.4 | — | — | — | pyjwt project / pyjwt | PyJWT is a JSON Web Token implementation in Python. | 134d ago |
| CVE-2026-47269 | 7.4 | — | — | — | — | pam_usb provides hardware authentication for Linux using ordinary removable media. | 135d ago |
| CVE-2026-44460 | 7.4 | — | — | — | — | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. | 135d ago |
| CVE-2026-49014 | 7.4 | — | — | — | osgeo / gdal | In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-bas | 136d ago |
| CVE-2026-45575 | 7.4 | — | — | — | — | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. | 136d ago |
| CVE-2026-48697 | 7.4 | — | — | — | pavel-odintsov / fastnetmon | FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. | 136d ago |
| CVE-2026-44053 | 7.4 | — | — | — | — | Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote att | 142d ago |
| CVE-2026-39850 | 7.4 | — | — | — | — | Yii 2 is a PHP application framework. | 142d ago |
| CVE-2026-3593 | 7.4 | — | — | — | isc / bind | A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. | 143d ago |
| CVE-2026-45245 | 7.4 | — | — | — | steipete / summarize | Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dis | 144d ago |
| CVE-2026-45539 | 7.4 | — | — | — | — | Microsoft APM is an open-source, community-driven dependency manager for AI agents. | 147d ago |
| CVE-2026-44636 | 7.4 | — | — | — | saitoha / libsixel | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. | 148d ago |
| CVE-2026-44511 | 7.4 | — | — | — | — | Katalyst Koi is a framework for building Rails admin functionality. | 148d ago |
| CVE-2026-33376 | 7.4 | — | — | — | grafana / grafana | When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. | 149d ago |
| CVE-2026-41132 | 7.4 | — | — | — | okfn / ckan | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. | 149d ago |
| CVE-2026-34647 | 7.4 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 150d ago |
| CVE-2026-42893 | 7.4 | — | — | — | microsoft / outlook | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unau | 150d ago |
| CVE-2026-41107 | 7.4 | — | — | — | microsoft / edge chromium | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo | 150d ago |
| CVE-2026-40414 | 7.4 | — | — | — | microsoft / windows 10 1607 | Windows TCP/IP Denial of Service Vulnerability | 150d ago |
| CVE-2026-40413 | 7.4 | — | — | — | microsoft / windows 10 1607 | Windows TCP/IP Denial of Service Vulnerability | 150d ago |
| CVE-2026-27851 | 7.4 | — | — | — | dovecot / dovecot | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly inter | 151d ago |
| CVE-2026-41872 | 7.4 | — | — | — | — | "Kura Sushi Official App" provided by EPG, Inc. | 151d ago |
| CVE-2026-33488 | 7.4 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 200d ago |
| CVE-2026-4600 | 7.4 | — | — | — | kjur / jsrsasign | Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature | 201d ago |
| CVE-2026-32887 | 7.4 | — | — | — | effectful / effect | Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript app | 203d ago |
| CVE-2026-2378 | 7.4 | — | — | — | thebrowser / arc search | ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content | 203d ago |
| CVE-2026-33131 | 7.4 | — | — | — | h3 / h3 | H3 is a minimal H(TTP) framework. | 204d ago |
| CVE-2026-32019 | 7.4 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() f | 204d ago |
| CVE-2026-4428 | 7.4 | — | — | — | — | A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectl | 204d ago |
| CVE-2026-31989 | 7.4 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation red | 205d ago |
| CVE-2026-32775 | 7.4 | — | — | — | libexif project / libexif | libexif through 0.6.25 has a flaw in decoding MakerNotes. | 208d ago |
| CVE-2025-71263 | 7.4 | — | — | — | opengroup / unix | In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' vari | 210d ago |
| CVE-2026-32242 | 7.4 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 211d ago |
| CVE-2026-28791 | 7.4 | — | — | — | ssw / tinacms\/cli | Tina is a headless content management system. | 211d ago |
| CVE-2026-32132 | 7.4 | — | — | — | zitadel / zitadel | ZITADEL is an open source identity management platform. | 212d ago |
| CVE-2026-20074 | 7.4 | — | — | — | cisco / ios xr | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco | 212d ago |
| CVE-2026-85702 | 7.3 | — | — | — | — | A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1 | 35d ago |
| CVE-2026-85638 | 7.3 | — | — | — | — | A weakness has been identified in jofpin trape 2.0. | 35d ago |
| CVE-2026-85516 | 7.3 | — | — | — | — | A vulnerability was detected in code-projects Vehicle Management System 1.0. | 36d ago |
| CVE-2026-85512 | 7.3 | — | — | — | — | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. | 36d ago |
| CVE-2026-85403 | 7.3 | — | — | — | — | A flaw has been found in code-projects Doctor Appointment System 1.0. | 36d ago |
| CVE-2026-85402 | 7.3 | — | — | — | — | A vulnerability was detected in code-projects Doctor Appointment System 1.0. | 36d ago |
| CVE-2026-85399 | 7.3 | — | — | — | — | A security flaw has been discovered in code-projects Hospital Information System 1.0. | 36d ago |
| CVE-2026-85398 | 7.3 | — | — | — | — | A vulnerability was identified in code-projects Hospital Information System 1.0. | 36d ago |