| CVE-2026-13568 | 7.3 | — | — | — | — | A weakness has been identified in SourceCodester Inventory Management System 1.0. | 102d ago |
| CVE-2026-13566 | 7.3 | — | — | — | — | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. | 102d ago |
| CVE-2026-13565 | 7.3 | — | — | — | — | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. | 102d ago |
| CVE-2026-13559 | 7.3 | — | — | — | — | A weakness has been identified in code-projects Real State Services 1.0. | 102d ago |
| CVE-2026-13555 | 7.3 | — | — | — | — | A vulnerability was found in itsourcecode Online Hotel Management System 1.0. | 102d ago |
| CVE-2026-13553 | 7.3 | — | — | — | — | A flaw has been found in itsourcecode Online Hotel Management System 1.0. | 102d ago |
| CVE-2026-13552 | 7.3 | — | — | — | — | A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. | 102d ago |
| CVE-2026-22078 | 7.3 | — | — | — | — | Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and | 102d ago |
| CVE-2026-13551 | 7.3 | — | — | — | — | A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. | 102d ago |
| CVE-2026-13550 | 7.3 | — | — | — | — | A weakness has been identified in itsourcecode Baptism Information Management System 1.0. | 102d ago |
| CVE-2026-13547 | 7.3 | — | — | — | — | A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. | 102d ago |
| CVE-2026-13546 | 7.3 | — | — | — | — | A vulnerability was found in Feehi CMS up to 2.1.1. | 102d ago |
| CVE-2026-13528 | 7.3 | — | — | — | — | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. | 103d ago |
| CVE-2026-13527 | 7.3 | — | — | — | — | A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. | 103d ago |
| CVE-2026-13526 | 7.3 | — | — | — | — | A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. | 103d ago |
| CVE-2026-13521 | 7.3 | — | — | — | — | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. | 103d ago |
| CVE-2026-13500 | 7.3 | — | — | — | — | A weakness has been identified in antlr ANTLR4 up to 4.13.2. | 103d ago |
| CVE-2026-13498 | 7.3 | — | — | — | — | A vulnerability was identified in yashpokharna2555 restaurent-management-system. | 103d ago |
| CVE-2026-13488 | 7.3 | — | — | — | — | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. | 103d ago |
| CVE-2026-13487 | 7.3 | — | — | — | — | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. | 103d ago |
| CVE-2026-13486 | 7.3 | — | — | — | — | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. | 103d ago |
| CVE-2026-13485 | 7.3 | — | — | — | — | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. | 103d ago |
| CVE-2026-50132 | 7.3 | — | — | — | budibase / budibase | Budibase is an open-source low-code platform. | 105d ago |
| CVE-2026-54840 | 7.3 | — | — | — | — | Unauthenticated Broken Access Control in Newsletters <= 4.13 versions. | 105d ago |
| CVE-2026-57915 | 7.3 | — | — | — | — | It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unreco | 105d ago |
| CVE-2026-54479 | 7.3 | — | — | — | — | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoin | 106d ago |
| CVE-2026-56790 | 7.3 | — | — | — | — | CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() | 106d ago |
| CVE-2026-50015 | 7.3 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 106d ago |
| CVE-2026-9086 | 7.3 | — | — | — | redhat / build of keycloak | A flaw was found in Keycloak. | 106d ago |
| CVE-2026-46734 | 7.3 | — | — | — | dell / display and peripheral manager | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation | 106d ago |
| CVE-2026-13201 | 7.3 | — | — | — | kubevirt / kubevirt | A flaw was found in KubeVirt's safepath package used by virt-handler. | 107d ago |
| CVE-2026-54328 | 7.3 | — | — | — | — | Pi is a minimal terminal coding harness. | 108d ago |
| CVE-2026-49401 | 7.3 | — | — | — | deno / deno | Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 108d ago |
| CVE-2026-41046 | 7.3 | — | — | — | presire / qsnapper | A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attac | 109d ago |
| CVE-2026-10845 | 7.3 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unaut | 109d ago |
| CVE-2026-9029 | 7.3 | — | — | — | grafana / grafana | A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile l | 109d ago |
| CVE-2026-12795 | 7.3 | — | — | — | litellm / litellm | A vulnerability was determined in BerriAI litellm up to 1.82.2. | 110d ago |
| CVE-2026-12775 | 7.3 | — | — | — | — | A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. | 111d ago |
| CVE-2026-12773 | 7.3 | — | — | — | litellm / litellm | A weakness has been identified in BerriAI litellm up to 1.59.8. | 111d ago |
| CVE-2026-12530 | 7.3 | — | — | — | — | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SD | 114d ago |
| CVE-2026-12529 | 7.3 | — | — | — | — | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analy | 114d ago |
| CVE-2025-69189 | 7.3 | — | — | — | — | Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Securit | 114d ago |
| CVE-2026-40768 | 7.3 | — | — | — | — | Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions. | 114d ago |
| CVE-2026-35314 | 7.3 | — | — | — | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin). | 114d ago |
| CVE-2026-0131 | 7.3 | — | — | — | google / android | In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. | 115d ago |
| CVE-2026-12324 | 7.3 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Graphics: CanvasWebGL component. | 115d ago |
| CVE-2026-12318 | 7.3 | — | — | — | mozilla / firefox | Incorrect boundary conditions in the Libraries component in NSS. | 115d ago |
| CVE-2026-49063 | 7.3 | — | — | — | — | Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions. | 116d ago |
| CVE-2026-40775 | 7.3 | — | — | — | — | Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions. | 116d ago |
| CVE-2026-6040 | 7.3 | — | — | — | — | A heap use-after-free existed when importing the blank-width characters of an ODF number format. | 116d ago |
| CVE-2026-12204 | 7.3 | — | — | — | — | A vulnerability was determined in ShopXO up to 6.7.1. | 117d ago |
| CVE-2026-12200 | 7.3 | — | — | — | — | A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. | 117d ago |
| CVE-2026-12198 | 7.3 | — | — | — | — | A weakness has been identified in Microweber up to 2.0.20. | 117d ago |
| CVE-2026-45011 | 7.3 | — | — | — | — | ApostropheCMS is an open-source Node.js content management system. | 119d ago |
| CVE-2026-12066 | 7.3 | — | — | — | — | A security flaw has been discovered in PbootCMS up to 3.2.12. | 119d ago |
| CVE-2026-48547 | 7.3 | — | — | — | — | KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute ar | 120d ago |
| CVE-2026-48546 | 7.3 | — | — | — | — | KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code b | 120d ago |
| CVE-2026-8589 | 7.3 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5 | 120d ago |
| CVE-2026-11417 | 7.3 | — | — | — | — | OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windo | 121d ago |
| CVE-2026-53473 | 7.3 | — | — | — | kubev2v / migration planner ui | A flaw was found in migration-planner-ui-app. | 121d ago |