| CVE-2026-61438 | 7.3 | — | — | — | — | PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python( | 86d ago |
| CVE-2026-61427 | 7.3 | — | — | — | — | PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key | 86d ago |
| CVE-2026-56398 | 7.3 | — | — | — | openwebui / open webui | Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow wher | 86d ago |
| CVE-2026-15752 | 7.3 | — | — | — | — | A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. | 87d ago |
| CVE-2026-24229 | 7.3 | — | — | — | — | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attac | 87d ago |
| CVE-2026-15643 | 7.3 | — | — | — | — | AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assis | 87d ago |
| CVE-2026-45073 | 7.3 | — | — | — | sensiolabs / symfony | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 87d ago |
| CVE-2026-55126 | 7.3 | — | — | — | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 87d ago |
| CVE-2026-55034 | 7.3 | — | — | — | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 87d ago |
| CVE-2026-55021 | 7.3 | — | — | — | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 87d ago |
| CVE-2026-50482 | 7.3 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 87d ago |
| CVE-2026-58640 | 7.3 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 87d ago |
| CVE-2026-50364 | 7.3 | — | — | — | microsoft / windows 10 21h2 | Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attac | 87d ago |
| CVE-2026-49790 | 7.3 | — | — | — | microsoft / windows 10 1607 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 87d ago |
| CVE-2026-49789 | 7.3 | — | — | — | microsoft / windows 10 1607 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | 87d ago |
| CVE-2026-15703 | 7.3 | — | — | — | — | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. | 87d ago |
| CVE-2026-8314 | 7.3 | — | — | — | rockwellautomation / arena | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) | 87d ago |
| CVE-2026-8313 | 7.3 | — | — | — | rockwellautomation / arena | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) | 87d ago |
| CVE-2026-8312 | 7.3 | — | — | — | rockwellautomation / arena | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) | 87d ago |
| CVE-2026-8085 | 7.3 | — | — | — | rockwellautomation / arena | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) | 87d ago |
| CVE-2026-15677 | 7.3 | — | — | — | — | A weakness has been identified in code-projects Online Job Portal 1.0. | 88d ago |
| CVE-2026-15676 | 7.3 | — | — | — | — | A security flaw has been discovered in code-projects Online Job Portal up to 1.0. | 88d ago |
| CVE-2026-15675 | 7.3 | — | — | — | — | A vulnerability was identified in code-projects Online Job Portal 1.0. | 88d ago |
| CVE-2026-15684 | 7.3 | — | — | — | — | Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. | 88d ago |
| CVE-2026-15597 | 7.3 | — | — | — | — | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. | 88d ago |
| CVE-2025-45869 | 7.3 | — | — | — | — | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). | 88d ago |
| CVE-2026-15557 | 7.3 | — | — | — | — | A weakness has been identified in waooAI waoowaoo up to 0.4.1. | 88d ago |
| CVE-2026-15542 | 7.3 | — | — | — | — | A vulnerability has been found in will-moss Isaiah up to 1.36.9. | 89d ago |
| CVE-2026-15541 | 7.3 | — | — | — | — | A flaw has been found in will-moss Isaiah up to 1.36.9. | 89d ago |
| CVE-2026-15537 | 7.3 | — | — | — | — | A security flaw has been discovered in SourceCodester Online Book Store System 1.0. | 89d ago |
| CVE-2026-15517 | 7.3 | — | — | — | — | A flaw has been found in Jinher OA 1.0. | 89d ago |
| CVE-2026-15514 | 7.3 | — | — | — | — | A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. | 89d ago |
| CVE-2026-56308 | 7.3 | — | — | — | — | Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verific | 89d ago |
| CVE-2026-15498 | 7.3 | — | — | — | — | A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. | 89d ago |
| CVE-2026-15497 | 7.3 | — | — | — | — | A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. | 89d ago |
| CVE-2026-15491 | 7.3 | — | — | — | — | A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. | 89d ago |
| CVE-2026-15490 | 7.3 | — | — | — | — | A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. | 89d ago |
| CVE-2026-15489 | 7.3 | — | — | — | — | A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. | 89d ago |
| CVE-2026-15488 | 7.3 | — | — | — | — | A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. | 89d ago |
| CVE-2026-15482 | 7.3 | — | — | — | — | A weakness has been identified in Aster Telecom Azcall 10/11. | 90d ago |
| CVE-2026-15479 | 7.3 | — | — | — | — | A vulnerability was found in H3C NX15 V100R017. | 90d ago |
| CVE-2026-61428 | 7.3 | — | — | — | — | PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated a | 90d ago |
| CVE-2026-55452 | 7.3 | — | — | — | snipeitapp / snipe-it | Snipe-IT is an IT asset/license management system. | 91d ago |
| CVE-2026-56667 | 7.3 | — | — | — | — | ZITADEL is an open source identity management platform. | 91d ago |
| CVE-2026-55501 | 7.3 | — | — | — | — | 9Router is an AI router & token saver. | 91d ago |
| CVE-2026-59794 | 7.3 | — | — | — | jetbrains / teamcity | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | 91d ago |
| CVE-2026-15330 | 7.3 | — | — | — | — | A vulnerability was determined in zhayujie CowAgent up to 2.1.1. | 92d ago |
| CVE-2026-15319 | 7.3 | — | — | — | — | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. | 92d ago |
| CVE-2026-57028 | 7.3 | — | — | — | juniper / junos os evolved | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS | 92d ago |
| CVE-2026-53963 | 7.3 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 92d ago |
| CVE-2026-59214 | 7.3 | — | — | — | openwebui / open webui | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. | 92d ago |
| CVE-2026-15190 | 7.3 | — | — | — | — | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. | 92d ago |
| CVE-2026-15137 | 7.3 | — | — | — | — | A weakness has been identified in code-projects Interview Management System 1.0. | 93d ago |
| CVE-2026-15135 | 7.3 | — | — | — | — | A security flaw has been discovered in code-projects Online Food Order System 1.0. | 93d ago |
| CVE-2026-15134 | 7.3 | — | — | — | — | A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. | 93d ago |
| CVE-2026-13320 | 7.3 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4 | 93d ago |
| CVE-2026-58384 | 7.3 | — | — | — | gimp / gimp | A flaw was found in GIMP's PSD parser. | 94d ago |
| CVE-2026-43825 | 7.3 | — | — | — | apache / opennlp | Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm documen | 95d ago |
| CVE-2026-58380 | 7.3 | — | — | — | gimp / gimp | A flaw was found in GIMP's PNM file format parser. | 95d ago |
| CVE-2026-49042 | 7.3 | — | — | — | apache / camel | Improper Input Validation vulnerability in Apache Camel. | 95d ago |