| CVE-2026-82883 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login | 37d ago |
| CVE-2026-19723 | 7.1 | — | — | — | — | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a val | 37d ago |
| CVE-2026-19453 | 7.1 | — | — | — | — | The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserve | 37d ago |
| CVE-2026-12865 | 7.1 | — | — | — | — | The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting | 37d ago |
| CVE-2026-73764 | 7.1 | — | — | — | hpe / arubaos-cx | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an un | 37d ago |
| CVE-2026-73763 | 7.1 | — | — | — | — | A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute | 37d ago |
| CVE-2026-73724 | 7.1 | — | — | — | arubanetworks / fabric composer | Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. | 38d ago |
| CVE-2026-73723 | 7.1 | — | — | — | arubanetworks / fabric composer | A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Compose | 38d ago |
| CVE-2026-84201 | 7.1 | — | — | — | — | appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch | 38d ago |
| CVE-2026-18780 | 7.1 | — | — | — | — | Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. | 38d ago |
| CVE-2026-84192 | 7.1 | — | — | — | — | LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SN | 38d ago |
| CVE-2026-82392 | 7.1 | — | — | — | — | pnpm is a package manager. | 38d ago |
| CVE-2026-82229 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | 38d ago |
| CVE-2026-82224 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. | 38d ago |
| CVE-2026-82221 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. | 38d ago |
| CVE-2026-81768 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | 38d ago |
| CVE-2026-81765 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | 38d ago |
| CVE-2026-81764 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | 38d ago |
| CVE-2026-81298 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | 38d ago |
| CVE-2026-81291 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. | 38d ago |
| CVE-2026-81290 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | 38d ago |
| CVE-2026-79747 | 7.1 | — | — | — | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separa | 39d ago |
| CVE-2026-79745 | 7.1 | — | — | — | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separa | 39d ago |
| CVE-2026-82659 | 7.1 | — | — | — | — | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, a | 39d ago |
| CVE-2026-82648 | 7.1 | — | — | — | — | WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that | 40d ago |
| CVE-2026-14307 | 7.1 | — | — | — | — | The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflectin | 40d ago |
| CVE-2026-82455 | 7.1 | — | — | — | — | RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. | 41d ago |
| CVE-2026-81533 | 7.1 | — | — | — | — | An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL | 41d ago |
| CVE-2026-82280 | 7.1 | — | — | — | — | Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any | 42d ago |
| CVE-2026-55066 | 7.1 | — | — | — | — | Vikunja is an open-source self-hosted task management platform. | 42d ago |
| CVE-2026-81760 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock J | 42d ago |
| CVE-2026-82246 | 7.1 | — | — | — | — | Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint th | 42d ago |
| CVE-2026-82241 | 7.1 | — | — | — | — | Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 1 | 42d ago |
| CVE-2026-80685 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mm/util: don't read __page_2 for order-1 folio | 42d ago |
| CVE-2026-80675 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libbpf: Reject non-exclusive metadata maps in | 42d ago |
| CVE-2026-80665 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if kvm_translate_vn | 42d ago |
| CVE-2026-80663 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tools/power/x86/intel-speed-select: Harden dae | 42d ago |
| CVE-2026-80662 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capab | 42d ago |
| CVE-2026-38821 | 7.1 | — | — | — | — | A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker | 42d ago |
| CVE-2026-54085 | 7.1 | — | — | — | — | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud worklo | 42d ago |
| CVE-2026-81934 | 7.1 | — | — | — | — | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pen | 43d ago |
| CVE-2026-81838 | 7.1 | — | — | — | amazon / diagram-as-code | A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0. | 43d ago |
| CVE-2026-81529 | 7.1 | — | — | — | — | Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the Mon | 43d ago |
| CVE-2026-81727 | 7.1 | — | — | — | nltk / nltk | NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and D | 43d ago |
| CVE-2026-78293 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | 43d ago |
| CVE-2026-78289 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions. | 43d ago |
| CVE-2026-78283 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | 43d ago |
| CVE-2026-78281 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | 43d ago |
| CVE-2026-78261 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | 43d ago |
| CVE-2026-47849 | 7.1 | — | — | — | vmware / spring data rest | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 J | 43d ago |
| CVE-2026-77611 | 7.1 | — | — | — | — | SeaweedFS is a distributed storage system for files and blobs. | 43d ago |
| CVE-2025-29419 | 7.1 | — | — | — | — | CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. | 44d ago |
| CVE-2026-80426 | 7.1 | — | — | — | — | FiftyOne renders a dataset field's description as markup. | 44d ago |
| CVE-2026-80555 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Free all memory if cp_init() fa | 44d ago |
| CVE-2026-80538 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfs: propagate errors from xfs_rtginode_load x | 44d ago |
| CVE-2026-80530 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing | 44d ago |
| CVE-2026-80523 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: clk: spacemit: k3: set hdma clock as critical | 44d ago |
| CVE-2026-80350 | 7.1 | — | — | — | — | OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 | 44d ago |
| CVE-2026-80346 | 7.1 | — | — | — | — | StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. | 44d ago |
| CVE-2026-78892 | 7.1 | — | — | — | google / chrome | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attack | 44d ago |