| CVE-2026-22179 | 7.2 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that | 205d ago |
| CVE-2026-28674 | 7.2 | — | — | — | danvei233 / xiaoheifs | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. | 205d ago |
| CVE-2026-28673 | 7.2 | — | — | — | danvei233 / xiaoheifs | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. | 205d ago |
| CVE-2026-23759 | 7.2 | — | — | — | — | Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command inje | 206d ago |
| CVE-2026-32264 | 7.2 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 206d ago |
| CVE-2026-32263 | 7.2 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 206d ago |
| CVE-2026-4172 | 7.2 | — | — | — | — | A vulnerability was detected in TRENDnet TEW-632BRP 1.010B32. | 207d ago |
| CVE-2026-31386 | 7.2 | — | — | — | litespeedtech / litespeed web server | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability | 207d ago |
| CVE-2016-20032 | 7.2 | — | — | — | — | ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers t | 207d ago |
| CVE-2015-20118 | 7.2 | — | — | — | nextclickventures / realtyscript | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name p | 207d ago |
| CVE-2015-20115 | 7.2 | — | — | — | nextclickventures / realtyscript | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malici | 207d ago |
| CVE-2026-3873 | 7.2 | — | — | — | — | Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by A | 210d ago |
| CVE-2026-32414 | 7.2 | — | — | — | — | Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo- | 210d ago |
| CVE-2026-32401 | 7.2 | — | — | — | — | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerabil | 210d ago |
| CVE-2026-20163 | 7.2 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10 | 212d ago |
| CVE-2025-67041 | 7.2 | — | — | — | lantronix / eds3016ps1ns firmware | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. | 212d ago |
| CVE-2025-67037 | 7.2 | — | — | — | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 212d ago |
| CVE-2025-67036 | 7.2 | — | — | — | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 212d ago |
| CVE-2025-67035 | 7.2 | — | — | — | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 212d ago |
| CVE-2025-67034 | 7.2 | — | — | — | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 212d ago |
| CVE-2026-1497 | 7.2 | — | — | — | neo4j / neo4j | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and | 212d ago |
| CVE-2026-86091 | 7.1 | — | — | — | — | ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated | 34d ago |
| CVE-2026-86090 | 7.1 | — | — | — | — | ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 hand | 34d ago |
| CVE-2026-80118 | 7.1 | — | — | — | — | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 bu | 35d ago |
| CVE-2026-80117 | 7.1 | — | — | — | — | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 bu | 35d ago |
| CVE-2026-80113 | 7.1 | — | — | — | — | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 bu | 35d ago |
| CVE-2022-35499 | 7.1 | — | — | — | — | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via | 35d ago |
| CVE-2026-19051 | 7.1 | — | — | — | — | Plaintext storage of a password vulnerability in Menulux Software Inc. | 35d ago |
| CVE-2026-16281 | 7.1 | — | — | — | — | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target l | 35d ago |
| CVE-2026-85451 | 7.1 | — | — | — | — | MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component | 35d ago |
| CVE-2026-53728 | 7.1 | — | — | — | — | Medplum is a developer platform that enables development of healthcare apps. | 35d ago |
| CVE-2026-85395 | 7.1 | — | — | — | — | UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing | 36d ago |
| CVE-2026-85390 | 7.1 | — | — | — | — | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check- | 36d ago |
| CVE-2026-84848 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | 36d ago |
| CVE-2026-84836 | 7.1 | — | — | — | — | Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions. | 36d ago |
| CVE-2026-84812 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | 36d ago |
| CVE-2026-84765 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. | 36d ago |
| CVE-2026-84763 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions. | 36d ago |
| CVE-2026-84756 | 7.1 | — | — | — | — | Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions. | 36d ago |
| CVE-2026-81776 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | 36d ago |
| CVE-2026-81773 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | 36d ago |
| CVE-2026-81300 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | 36d ago |
| CVE-2026-81295 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. | 36d ago |
| CVE-2026-81292 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. | 36d ago |
| CVE-2026-83961 | 7.1 | — | — | — | — | ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. | 36d ago |
| CVE-2026-84989 | 7.1 | — | — | — | — | ntopng is a web-based network traffic monitoring application. | 36d ago |
| CVE-2026-85164 | 7.1 | — | — | — | — | WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImage | 36d ago |
| CVE-2026-80749 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/connector/hdmi: Fix out of bounds memory r | 36d ago |
| CVE-2026-80741 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read on empty messa | 36d ago |
| CVE-2026-84667 | 7.1 | — | — | — | — | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler d | 37d ago |
| CVE-2026-14199 | 7.1 | — | — | — | — | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater | 37d ago |
| CVE-2026-84800 | 7.1 | — | — | — | — | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::a | 37d ago |
| CVE-2026-84798 | 7.1 | — | — | — | — | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsContro | 37d ago |
| CVE-2026-84794 | 7.1 | — | — | — | — | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supp | 37d ago |
| CVE-2026-84759 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions. | 37d ago |
| CVE-2026-81775 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. | 37d ago |
| CVE-2026-81771 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | 37d ago |
| CVE-2026-81770 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | 37d ago |
| CVE-2026-81289 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 vers | 37d ago |
| CVE-2026-81288 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | 37d ago |