| CVE-2026-8771 | 7.3 | — | — | — | — | A security flaw has been discovered in linlinjava litemall up to 1.8.0. | 145d ago |
| CVE-2026-8768 | 7.3 | — | — | — | vercel / ai | A vulnerability was found in vercel ai up to 3.0.97. | 145d ago |
| CVE-2026-8759 | 7.3 | — | — | — | — | A vulnerability was identified in xiandafu beetl up to 3.20.2. | 145d ago |
| CVE-2026-8758 | 7.3 | — | — | — | — | A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. | 145d ago |
| CVE-2026-8757 | 7.3 | — | — | — | adenhq / hive | A vulnerability was found in adenhq hive up to 0.11.0. | 145d ago |
| CVE-2026-8756 | 7.3 | — | — | — | — | A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. | 145d ago |
| CVE-2026-8755 | 7.3 | — | — | — | — | A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. | 145d ago |
| CVE-2026-8751 | 7.3 | — | — | — | h2o / h2o | A security flaw has been discovered in h2oai h2o-3 up to 7402. | 145d ago |
| CVE-2026-8734 | 7.3 | — | — | — | — | A vulnerability was determined in Oinone Pamirs up to 7.2.0. | 145d ago |
| CVE-2026-8725 | 7.3 | — | — | — | — | A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. | 145d ago |
| CVE-2026-8700 | 7.3 | — | — | — | — | Crypt::DSA versions before 1.20 for Perl generate seeds using rand. | 147d ago |
| CVE-2026-44567 | 7.3 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 147d ago |
| CVE-2026-44566 | 7.3 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 147d ago |
| CVE-2026-44549 | 7.3 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 147d ago |
| CVE-2026-44721 | 7.3 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 147d ago |
| CVE-2026-39054 | 7.3 | — | — | — | — | Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. | 147d ago |
| CVE-2026-24712 | 7.3 | — | — | — | northern.tech / cfengine | Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. | 148d ago |
| CVE-2025-27853 | 7.3 | — | — | — | garmin / empirbus wireless display unit firmware | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. | 149d ago |
| CVE-2026-42584 | 7.3 | — | — | — | netty / netty | Netty is an asynchronous, event-driven network application framework. | 149d ago |
| CVE-2024-55045 | 7.3 | — | — | — | — | Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_ent | 149d ago |
| CVE-2026-37430 | 7.3 | — | — | — | — | An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a | 149d ago |
| CVE-2026-35433 | 7.3 | — | — | — | microsoft / .net framework | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | 150d ago |
| CVE-2026-32177 | 7.3 | — | — | — | microsoft / visual studio 2022 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | 150d ago |
| CVE-2026-5089 | 7.3 | — | — | — | — | YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. | 150d ago |
| CVE-2026-42498 | 7.3 | — | — | — | apache / tomcat | Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache | 150d ago |
| CVE-2026-43939 | 7.3 | — | — | — | — | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. | 150d ago |
| CVE-2026-8390 | 7.3 | — | — | — | mozilla / firefox | Use-after-free in the JavaScript: WebAssembly component. | 150d ago |
| CVE-2026-33862 | 7.3 | — | — | — | siemens / teamcenter | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All version | 150d ago |
| CVE-2026-43914 | 7.3 | — | — | — | dani-garcia / vaultwarden | Vaultwarden is a Bitwarden-compatible server written in Rust. | 151d ago |
| CVE-2026-43887 | 7.3 | — | — | — | — | Outline is a service that allows for collaborative documentation. | 151d ago |
| CVE-2026-43656 | 7.3 | — | — | — | apple / ipados | An out-of-bounds write issue was addressed with improved input validation. | 151d ago |
| CVE-2026-43655 | 7.3 | — | — | — | apple / ipados | An out-of-bounds read was addressed with improved bounds checking. | 151d ago |
| CVE-2026-37630 | 7.3 | — | — | — | — | An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark func | 151d ago |
| CVE-2026-8321 | 7.3 | — | — | — | — | A vulnerability was detected in inkeep agents 0.58.14. | 151d ago |
| CVE-2022-4988 | 7.3 | — | — | — | — | Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. | 151d ago |
| CVE-2026-8305 | 7.3 | — | — | — | openclaw / openclaw | A vulnerability was detected in OpenClaw up to 2026.1.24. | 151d ago |
| CVE-2026-5172 | 7.3 | — | — | — | — | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read | 151d ago |
| CVE-2026-44995 | 7.3 | — | — | — | openclaw / openclaw | OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server c | 151d ago |
| CVE-2026-36983 | 7.3 | — | — | — | dlink / dcs-932l firmware | D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. | 151d ago |
| CVE-2026-36962 | 7.3 | — | — | — | — | SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, a | 151d ago |
| CVE-2026-2291 | 7.3 | — | — | — | — | dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject fals | 151d ago |
| CVE-2026-31254 | 7.3 | — | — | — | — | The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code inje | 151d ago |
| CVE-2026-31253 | 7.3 | — | — | — | — | The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains | 151d ago |
| CVE-2026-31251 | 7.3 | — | — | — | — | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization v | 151d ago |
| CVE-2026-31250 | 7.3 | — | — | — | — | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization v | 151d ago |
| CVE-2026-31249 | 7.3 | — | — | — | — | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization v | 151d ago |
| CVE-2025-61314 | 7.3 | — | — | — | — | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed | 151d ago |
| CVE-2025-61313 | 7.3 | — | — | — | — | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Mana | 151d ago |
| CVE-2025-61312 | 7.3 | — | — | — | — | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed P | 151d ago |
| CVE-2025-61311 | 7.3 | — | — | — | — | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Pr | 151d ago |
| CVE-2025-10908 | 7.3 | — | — | — | wso2 / identity server | Due to a lack of user account state validation during authentication, locked user accounts can be successfully aut | 151d ago |
| CVE-2026-6433exploited | 7.3 | 0.81% | 1/3 | +43d | — | The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL | 151d ago |
| CVE-2026-8216 | 7.3 | — | — | — | — | A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. | 153d ago |
| CVE-2026-4632 | 7.3 | — | — | — | — | A weakness has been identified in itsourcecode Online Enrollment System 1.0. | 199d ago |
| CVE-2026-4625 | 7.3 | — | — | — | — | A flaw has been found in SourceCodester Online Admission System 1.0. | 199d ago |
| CVE-2026-4624 | 7.3 | — | — | — | — | A vulnerability was detected in SourceCodester Online Library Management System 1.0. | 199d ago |
| CVE-2026-4623 | 7.3 | — | — | — | — | A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b | 199d ago |
| CVE-2026-4617 | 7.3 | — | — | — | — | A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. | 200d ago |
| CVE-2026-4615 | 7.3 | — | — | — | — | A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. | 200d ago |
| CVE-2026-4613 | 7.3 | — | — | — | — | A vulnerability was found in SourceCodester E-Commerce Site 1.0. | 200d ago |