| CVE-2026-4612 | 7.3 | — | — | — | — | A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. | 200d ago |
| CVE-2026-4594 | 7.3 | — | — | — | — | A vulnerability has been found in erupts erupt up to 1.13.3. | 200d ago |
| CVE-2025-15605 | 7.3 | — | — | — | tp-link / archer nx600 firmware | A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 e | 200d ago |
| CVE-2026-33492 | 7.3 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 200d ago |
| CVE-2026-4581 | 7.3 | — | — | — | code-projects / simple laundry system | A weakness has been identified in code-projects Simple Laundry System 1.0. | 200d ago |
| CVE-2026-4580 | 7.3 | — | — | — | code-projects / simple laundry system | A security flaw has been discovered in code-projects Simple Laundry System 1.0. | 200d ago |
| CVE-2026-4579 | 7.3 | — | — | — | code-projects / simple laundry system | A vulnerability was identified in code-projects Simple Laundry System 1.0. | 200d ago |
| CVE-2025-10679 | 7.3 | — | — | — | — | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plug | 200d ago |
| CVE-2026-4562 | 7.3 | — | — | — | — | A security flaw has been discovered in MacCMS 2025.1000.4052. | 201d ago |
| CVE-2026-4540 | 7.3 | — | — | — | — | A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. | 201d ago |
| CVE-2026-4536 | 7.3 | — | — | — | — | A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. | 201d ago |
| CVE-2026-4528 | 7.3 | — | — | — | — | A vulnerability was determined in trueleaf ApiFlow 0.9.7. | 202d ago |
| CVE-2026-4508 | 7.3 | — | — | — | — | A vulnerability was identified in PbootCMS up to 3.2.12. | 203d ago |
| CVE-2026-32663 | 7.3 | — | — | — | igl / eparking.fi | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoin | 203d ago |
| CVE-2026-27649 | 7.3 | — | — | — | ctek / charge portal | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoin | 203d ago |
| CVE-2026-33147 | 7.3 | — | — | — | generic-mapping-tools / gmt | GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. | 203d ago |
| CVE-2026-4504 | 7.3 | — | — | — | — | A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. | 203d ago |
| CVE-2026-4499 | 7.3 | — | — | — | dlink / dir-820lw firmware | A vulnerability was determined in D-Link DIR-820LW 2.03. | 203d ago |
| CVE-2026-4497 | 7.3 | — | — | — | totolink / wa300 firmware | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. | 203d ago |
| CVE-2026-33080 | 7.3 | — | — | — | filamentphp / filament | Filament is a collection of full-stack components for accelerated Laravel development. | 203d ago |
| CVE-2025-69720 | 7.3 | — | — | — | invisible-island / ncurses | The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string i | 204d ago |
| CVE-2025-71257exploited | 7.3 | 44.6% | 1/3 | +13d | bmc / footprints | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to i | 204d ago |
| CVE-2026-2991 | 7.3 | — | — | — | — | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass | 205d ago |
| CVE-2026-4319 | 7.3 | — | — | — | carmelo / simple food order system | A vulnerability was identified in code-projects Simple Food Order System 1.0. | 206d ago |
| CVE-2026-4289 | 7.3 | — | — | — | — | A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. | 207d ago |
| CVE-2026-4288 | 7.3 | — | — | — | — | A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. | 207d ago |
| CVE-2026-4287 | 7.3 | — | — | — | — | A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. | 207d ago |
| CVE-2026-4237 | 7.3 | — | — | — | — | A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. | 207d ago |
| CVE-2026-4236 | 7.3 | — | — | — | — | A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. | 207d ago |
| CVE-2026-4235 | 7.3 | — | — | — | — | A weakness has been identified in itsourcecode Online Enrollment System 1.0. | 207d ago |
| CVE-2026-4232 | 7.3 | — | — | — | — | A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. | 207d ago |
| CVE-2026-4231 | 7.3 | — | — | — | — | A vulnerability was found in vanna-ai vanna up to 2.0.2. | 207d ago |
| CVE-2026-4229 | 7.3 | — | — | — | — | A flaw has been found in vanna-ai vanna up to 2.0.2. | 207d ago |
| CVE-2026-4223 | 7.3 | — | — | — | angeljudesuarez / payroll management system | A vulnerability was identified in itsourcecode Payroll Management System 1.0. | 207d ago |
| CVE-2026-4221 | 7.3 | — | — | — | — | A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. | 207d ago |
| CVE-2026-4220 | 7.3 | — | — | — | — | A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. | 207d ago |
| CVE-2026-4201 | 7.3 | — | — | — | — | A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. | 207d ago |
| CVE-2026-4200 | 7.3 | — | — | — | — | A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. | 207d ago |
| CVE-2026-4194 | 7.3 | — | — | — | dlink / dnr-202l firmware | A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L | 207d ago |
| CVE-2026-4193 | 7.3 | — | — | — | dlink / dir-823g firmware | A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. | 207d ago |
| CVE-2026-4191 | 7.3 | — | — | — | — | A flaw has been found in JawherKl node-api-postgres up to 2.5. | 207d ago |
| CVE-2026-4190 | 7.3 | — | — | — | — | A vulnerability was detected in JawherKl node-api-postgres up to 2.5. | 207d ago |
| CVE-2026-4180 | 7.3 | — | — | — | dlink / dir-816 firmware | A vulnerability was identified in D-Link DIR-816 1.10CNB05. | 207d ago |
| CVE-2026-3839 | 7.3 | — | — | — | unraid / unraid | Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability. | 207d ago |
| CVE-2026-32594 | 7.3 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 207d ago |
| CVE-2026-25076 | 7.3 | — | — | — | — | Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. | 210d ago |
| CVE-2026-4014 | 7.3 | — | — | — | luffypirates / cafe reservation system | A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. | 211d ago |
| CVE-2026-3981 | 7.3 | — | — | — | unguardable / online doctor appointment system | A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. | 211d ago |
| CVE-2026-3980 | 7.3 | — | — | — | unguardable / online doctor appointment system | A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. | 211d ago |
| CVE-2026-3969 | 7.3 | — | — | — | — | A vulnerability was detected in FeMiner wms up to 1.0. | 212d ago |
| CVE-2026-86188 | 7.2 | — | — | — | — | AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attack | 34d ago |
| CVE-2026-83625 | 7.2 | — | — | — | — | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Hea | 34d ago |
| CVE-2026-78438 | 7.2 | — | — | — | — | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyL | 34d ago |
| CVE-2026-77830 | 7.2 | — | — | — | — | The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scri | 34d ago |
| CVE-2026-19769 | 7.2 | — | — | — | — | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross- | 34d ago |
| CVE-2026-18406 | 7.2 | — | — | — | — | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to | 34d ago |
| CVE-2026-16649 | 7.2 | — | — | — | — | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in a | 34d ago |
| CVE-2026-15984 | 7.2 | — | — | — | — | The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all | 34d ago |
| CVE-2026-77263 | 7.2 | — | — | — | — | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to St | 34d ago |
| CVE-2026-77233 | 7.2 | — | — | — | — | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to St | 34d ago |