| CVE-2025-62043 | 6.5 | medium | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCa | 170d ago |
| CVE-2025-32223 | 6.5 | medium | — | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorr | 170d ago |
| CVE-2026-27397 | 6.5 | medium | — | Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. | 170d ago |
| CVE-2026-28449 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid s | 171d ago |
| CVE-2026-32743 | 6.5 | medium | dronecode / px4 drone autopilot | PX4 is an open-source autopilot stack for drones and unmanned vehicles. | 171d ago |
| CVE-2026-33163 | 6.5 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 171d ago |
| CVE-2026-25745 | 6.5 | medium | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 171d ago |
| CVE-2025-55043 | 6.5 | medium | murasoftware / mura cms | MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBu | 171d ago |
| CVE-2026-22320 | 6.5 | medium | — | A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker wi | 171d ago |
| CVE-2026-22316 | 6.5 | medium | — | A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request | 171d ago |
| CVE-2026-33058 | 6.5 | medium | kanboard / kanboard | Kanboard is project management software focused on Kanban methodology. | 172d ago |
| CVE-2026-31865 | 6.5 | medium | elysiajs / elysia | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server | 172d ago |
| CVE-2026-27522 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGrou | 172d ago |
| CVE-2026-22178 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in t | 172d ago |
| CVE-2026-22170 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnera | 172d ago |
| CVE-2026-22168 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allow | 172d ago |
| CVE-2026-29057 | 6.5 | medium | vercel / next.js | Next.js is a React framework for building full-stack web applications. | 172d ago |
| CVE-2026-26004 | 6.5 | medium | sentry / sentry | Sentry is a developer-first error tracking and performance monitoring tool. | 172d ago |
| CVE-2026-25937 | 6.5 | medium | teclib-edition / glpi | GLPI is a free Asset and IT management software package. | 172d ago |
| CVE-2026-32842 | 6.5 | medium | edimax / gs-5008pl firmware | Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allo | 172d ago |
| CVE-2026-1267 | 6.5 | medium | ibm / planning analytics local | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data | 172d ago |
| CVE-2026-25936 | 6.5 | medium | teclib-edition / glpi | GLPI is a free Asset and IT management software package. | 172d ago |
| CVE-2026-4147 | 6.5 | medium | mongodb / mongodb | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-craft | 172d ago |
| CVE-2026-21886 | 6.5 | medium | citeum / opencti | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. | 172d ago |
| CVE-2026-26929 | 6.5 | medium | apache / airflow | Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization fi | 172d ago |
| CVE-2025-68971 | 6.5 | medium | — | In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file | 173d ago |
| CVE-2025-69196 | 6.5 | medium | jlowin / fastmcp | FastMCP is the standard framework for building MCP applications. | 173d ago |
| CVE-2026-28490 | 6.5 | medium | authlib / authlib | Authlib is a Python library which builds OAuth and OpenID Connect servers. | 173d ago |
| CVE-2026-3022 | 6.5 | medium | wakyma / wakyma | Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 've | 173d ago |
| CVE-2026-3021 | 6.5 | medium | wakyma / wakyma | Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 've | 173d ago |
| CVE-2026-32704 | 6.5 | medium | b3log / siyuan | SiYuan is a personal knowledge management system. | 173d ago |
| CVE-2026-28522 | 6.5 | medium | tuya / arduino-tuyaopen | arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. | 173d ago |
| CVE-2026-21005 | 6.5 | medium | samsung / smart switch | Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files w | 173d ago |
| CVE-2026-21004 | 6.5 | medium | samsung / smart switch | Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial o | 173d ago |
| CVE-2025-12736 | 6.5 | medium | openatom / openharmony | in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uni | 173d ago |
| CVE-2026-32598 | 6.5 | medium | hackerbay / oneuptime | OneUptime is a solution for monitoring and managing online services. | 176d ago |
| CVE-2026-32460 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ult | 176d ago |
| CVE-2026-32455 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 M | 176d ago |
| CVE-2026-32454 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion | 176d ago |
| CVE-2026-32451 | 6.5 | medium | — | Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Con | 176d ago |
| CVE-2026-32450 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 A | 176d ago |
| CVE-2026-32449 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Th | 176d ago |
| CVE-2026-32448 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Teubert | 176d ago |
| CVE-2026-32443 | 6.5 | medium | — | Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed | 176d ago |
| CVE-2026-32431 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm F | 176d ago |
| CVE-2026-32430 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Crea | 176d ago |
| CVE-2026-32429 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Ma | 176d ago |
| CVE-2026-32424 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Spr | 176d ago |
| CVE-2026-32411 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simpma Embed | 176d ago |
| CVE-2026-32403 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Too | 176d ago |
| CVE-2026-32398 | 6.5 | medium | — | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Subra | 176d ago |
| CVE-2026-32361 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fi | 176d ago |
| CVE-2026-32359 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Ico | 176d ago |
| CVE-2026-32356 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Rob | 176d ago |
| CVE-2026-32352 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor El | 176d ago |
| CVE-2026-32320 | 6.5 | medium | ellanetworks / ella core | Ella Core is a 5G core designed for private networks. | 176d ago |
| CVE-2026-31949 | 6.5 | medium | librechat / librechat | LibreChat is a ChatGPT clone with additional features. | 176d ago |
| CVE-2026-31918 | 6.5 | medium | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in immonex immo | 176d ago |
| CVE-2026-31885 | 6.5 | medium | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 176d ago |
| CVE-2026-31884 | 6.5 | medium | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 176d ago |