| CVE-2026-68320 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sc | 60d ago |
| CVE-2026-68265 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_AD | 60d ago |
| CVE-2026-68230 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: media: amlogic-c3: Add validations for ae and | 60d ago |
| CVE-2026-68134 | 7.3 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ptp: ptp_s390: Add missing facility check Only | 60d ago |
| CVE-2026-65948 | 7.3 | — | — | — | apache / ranger | UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. | 60d ago |
| CVE-2026-19384 | 7.3 | — | — | — | — | A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. | 61d ago |
| CVE-2026-19379 | 7.3 | — | — | — | — | A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. | 61d ago |
| CVE-2026-19376 | 7.3 | — | — | — | — | A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. | 61d ago |
| CVE-2026-19374 | 7.3 | — | — | — | — | A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. | 61d ago |
| CVE-2026-19355 | 7.3 | — | — | — | — | A vulnerability was determined in MingSoft MCMS up to 3.0.6. | 61d ago |
| CVE-2026-19351 | 7.3 | — | — | — | — | A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. | 61d ago |
| CVE-2026-19344 | 7.3 | — | — | — | — | A vulnerability has been found in code-projects Task Management System 1.0. | 62d ago |
| CVE-2026-19343 | 7.3 | — | — | — | — | A flaw has been found in code-projects Task Management System 1.0. | 62d ago |
| CVE-2026-19342 | 7.3 | — | — | — | — | A vulnerability was detected in code-projects Task Management System 1.0. | 62d ago |
| CVE-2026-19263 | 7.3 | — | — | — | — | A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. | 63d ago |
| CVE-2026-48098 | 7.3 | — | — | — | — | NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address | 63d ago |
| CVE-2026-19231 | 7.3 | — | — | — | — | A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. | 63d ago |
| CVE-2026-11430 | 7.3 | — | — | — | — | Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. | 63d ago |
| CVE-2026-19211 | 7.3 | — | — | — | — | A vulnerability was found in SourceCodester Photo Share Website 1.0. | 63d ago |
| CVE-2026-19196 | 7.3 | — | — | — | — | A vulnerability was found in SourceCodester Photo Share Website 1.0. | 64d ago |
| CVE-2026-19062 | 7.3 | — | — | — | — | A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. | 64d ago |
| CVE-2026-65541 | 7.3 | — | — | — | — | Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | 64d ago |
| CVE-2026-19021 | 7.3 | — | — | — | — | A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. | 65d ago |
| CVE-2026-19010 | 7.3 | — | — | — | — | A security vulnerability has been detected in TinyAGI 0.0.20. | 65d ago |
| CVE-2026-19009 | 7.3 | — | — | — | — | A weakness has been identified in TinyAGI 0.0.20. | 65d ago |
| CVE-2026-19000 | 7.3 | — | — | — | — | A vulnerability was identified in JeecgBoot up to 3.9.2. | 65d ago |
| CVE-2026-18991 | 7.3 | — | — | — | — | A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. | 65d ago |
| CVE-2026-18990 | 7.3 | — | — | — | — | A vulnerability was detected in letta-ai LettaBot 0.2.0. | 65d ago |
| CVE-2026-18973 | 7.3 | — | — | — | — | A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. | 65d ago |
| CVE-2026-18970 | 7.3 | — | — | — | — | A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. | 65d ago |
| CVE-2026-18969 | 7.3 | — | — | — | — | A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. | 65d ago |
| CVE-2026-18958 | 7.3 | — | — | — | — | A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/ | 65d ago |
| CVE-2026-71226 | 7.3 | — | — | — | redhat / hardened images | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before al | 65d ago |
| CVE-2026-25703 | 7.3 | — | — | — | — | NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authent | 66d ago |
| CVE-2026-6079 | 7.3 | — | — | — | — | The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to mi | 66d ago |
| CVE-2026-18859 | 7.3 | — | — | — | — | A vulnerability was identified in ESAFENET CDG up to 20260615. | 66d ago |
| CVE-2026-18854 | 7.3 | — | — | — | — | A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. | 66d ago |
| CVE-2026-18810 | 7.3 | — | — | — | — | A security vulnerability has been detected in H3C NX15 V100R017. | 66d ago |
| CVE-2026-18788 | 7.3 | — | — | — | — | A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. | 66d ago |
| CVE-2026-18770 | 7.3 | — | — | — | — | A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. | 66d ago |
| CVE-2026-18755 | 7.3 | — | — | — | — | A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe sea | 67d ago |
| CVE-2026-42169 | 7.3 | — | — | — | — | A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. | 67d ago |
| CVE-2026-18647 | 7.3 | — | — | — | — | A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. | 67d ago |
| CVE-2026-18641 | 7.3 | — | — | — | — | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. | 67d ago |
| CVE-2026-4793 | 7.3 | — | — | — | synology / assistant | An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read | 68d ago |
| CVE-2026-18481 | 7.3 | — | — | — | — | Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authent | 70d ago |
| CVE-2026-54737 | 7.3 | — | — | — | — | @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. | 70d ago |
| CVE-2026-11980 | 7.3 | — | — | — | ibm / aspera | IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up. | 71d ago |
| CVE-2026-16527 | 7.3 | — | — | — | — | An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /stor | 72d ago |
| CVE-2025-69949 | 7.3 | — | — | — | — | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the paramet | 72d ago |
| CVE-2025-69945 | 7.3 | — | — | — | — | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. | 72d ago |
| CVE-2025-69944 | 7.3 | — | — | — | — | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via t | 72d ago |
| CVE-2025-67408 | 7.3 | — | — | — | — | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the para | 72d ago |
| CVE-2025-67407 | 7.3 | — | — | — | — | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via para | 72d ago |
| CVE-2025-67406 | 7.3 | — | — | — | — | https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. | 72d ago |
| CVE-2025-67405 | 7.3 | — | — | — | — | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the | 72d ago |
| CVE-2026-15144 | 7.3 | — | — | — | fastify / fastify\/rate-limit | @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.i | 72d ago |
| CVE-2026-65947 | 7.3 | — | — | — | balbooa / gridbox | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 | 72d ago |
| CVE-2026-23904 | 7.3 | — | — | — | apache / kyuubi | Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination | 73d ago |
| CVE-2026-14893 | 7.3 | — | — | — | — | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana | 73d ago |