| CVE-2026-68515 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 44d ago |
| CVE-2026-68513 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 44d ago |
| CVE-2026-59981 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion | 44d ago |
| CVE-2026-79788 | 7.1 | — | — | — | — | In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action | 44d ago |
| CVE-2026-79786 | 7.1 | — | — | — | — | Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect U | 44d ago |
| CVE-2026-55609 | 7.1 | — | — | — | — | sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in subl | 44d ago |
| CVE-2026-59982 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 45d ago |
| CVE-2026-59189 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 45d ago |
| CVE-2026-59187 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 45d ago |
| CVE-2026-59186 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 45d ago |
| CVE-2026-59184 | 7.1 | — | — | — | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion pict | 45d ago |
| CVE-2026-55540 | 7.1 | — | — | — | — | PraisonAI is a multi-agent teams system. | 45d ago |
| CVE-2026-55537 | 7.1 | — | — | — | — | PraisonAI is a multi-agent teams system. | 45d ago |
| CVE-2026-55527 | 7.1 | — | — | — | — | PraisonAI is a multi-agent teams system. | 45d ago |
| CVE-2026-78282 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | 45d ago |
| CVE-2026-78264 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | 45d ago |
| CVE-2026-78263 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | 45d ago |
| CVE-2026-32556 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | 45d ago |
| CVE-2026-75369 | 7.1 | — | — | — | — | An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot Acu | 45d ago |
| CVE-2026-71505 | 7.1 | — | — | — | — | Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site | 45d ago |
| CVE-2026-19685 | 7.1 | — | — | — | — | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-value | 46d ago |
| CVE-2026-66623 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | 46d ago |
| CVE-2026-66610 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. | 46d ago |
| CVE-2026-66599 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | 46d ago |
| CVE-2026-66584 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | 46d ago |
| CVE-2026-32476 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | 46d ago |
| CVE-2026-28190 | 7.1 | — | — | — | — | Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. | 46d ago |
| CVE-2026-28166 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions. | 46d ago |
| CVE-2026-28162 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | 46d ago |
| CVE-2026-78203 | 7.1 | — | — | — | — | Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attac | 46d ago |
| CVE-2026-77115 | 7.1 | — | — | — | — | Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML w | 47d ago |
| CVE-2026-74713 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vhost_iotlb: bound map allocation in add_range | 48d ago |
| CVE-2026-74703 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Validate T10 PI scatterlist counts | 48d ago |
| CVE-2026-74689 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/atm: fix slab-out-of-bounds read in vcc_se | 48d ago |
| CVE-2026-74684 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: tap: set skb->dev before parsing virtio n | 48d ago |
| CVE-2026-74603 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix board ID over-read The EEPROM bo | 48d ago |
| CVE-2026-74584 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing | 48d ago |
| CVE-2026-63310 | 7.1 | — | — | — | nltk / nltk | NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloade | 48d ago |
| CVE-2026-58003 | 7.1 | — | — | — | — | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.jso | 48d ago |
| CVE-2026-77219 | 7.1 | — | — | — | — | GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to l | 48d ago |
| CVE-2026-30865 | 7.1 | — | — | — | — | Combodo iTop is a web based IT service management tool. | 48d ago |
| CVE-2026-62676 | 7.1 | — | — | — | — | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. | 49d ago |
| CVE-2026-49114 | 7.1 | — | — | — | — | In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's exter | 49d ago |
| CVE-2026-55013 | 7.1 | — | — | — | microsoft / remote help | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing | 49d ago |
| CVE-2026-46355 | 7.1 | — | — | — | — | BigBlueButton is an open-source virtual classroom. | 49d ago |
| CVE-2026-16989 | 7.1 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to impr | 49d ago |
| CVE-2026-54623 | 7.1 | — | — | — | — | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. | 50d ago |
| CVE-2026-54616 | 7.1 | — | — | — | — | NanaZip is the 7-Zip derivative intended for the modern Windows experience. | 50d ago |
| CVE-2026-16925 | 7.1 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to | 50d ago |
| CVE-2026-77081 | 7.1 | — | — | — | n8n / n8n | n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL nod | 50d ago |
| CVE-2026-74019 | 7.1 | — | — | — | — | Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. | 50d ago |
| CVE-2026-68564 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | 50d ago |
| CVE-2026-66673 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. | 50d ago |
| CVE-2026-66616 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. | 50d ago |
| CVE-2026-66615 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. | 50d ago |
| CVE-2026-66614 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. | 50d ago |
| CVE-2026-66612 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions. | 50d ago |
| CVE-2026-66611 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | 50d ago |
| CVE-2026-66607 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | 50d ago |
| CVE-2026-66606 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | 50d ago |