| CVE-2026-74292 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: tegra: tegra210_ahub: Validate written e | 55d ago |
| CVE-2026-72471 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent potential lcn remains uninit | 55d ago |
| CVE-2026-72460 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: apparmor: check label build before no_new_priv | 55d ago |
| CVE-2026-72455 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix uninitialised pointer passed to | 55d ago |
| CVE-2026-72440 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: md/raid1: fix writes_pending and barrier refer | 55d ago |
| CVE-2026-72425 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ice: fix FDIR CTRL VSI resource leak in ice_re | 55d ago |
| CVE-2026-72415 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Validate written enum value in ge_ | 55d ago |
| CVE-2026-72397 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) honor vrm_version in pmbus | 55d ago |
| CVE-2026-72395 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing events to regulator | 55d ago |
| CVE-2026-72364 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix writeback error handling Fix the er | 55d ago |
| CVE-2026-72297 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: atm: reject out-of-range traffic classes | 55d ago |
| CVE-2026-72284 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ignore pending PV EOI if the vCPU ha | 55d ago |
| CVE-2026-72280 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Drop bogus WARN for write to Z | 55d ago |
| CVE-2026-72213 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb cgroup rsvd charge/unc | 55d ago |
| CVE-2026-72175 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix make_uffd_wp_huge_pte() | 55d ago |
| CVE-2026-72143 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Restore SST-PP control to | 55d ago |
| CVE-2026-72116 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops after device rem | 55d ago |
| CVE-2026-72099 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment hash_offset twic | 55d ago |
| CVE-2026-72089 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Reject firmware log with size smal | 55d ago |
| CVE-2026-72049 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ieee802154: admin-gate legacy LLSEC dump opera | 55d ago |
| CVE-2026-72043 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing dirty page tracking in | 55d ago |
| CVE-2026-19908 | 7.1 | — | — | — | — | PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. | 55d ago |
| CVE-2025-7639 | 7.1 | — | — | — | — | The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege t | 55d ago |
| CVE-2026-19680 | 7.1 | — | — | — | tenable / security center | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data f | 55d ago |
| CVE-2026-19483 | 7.1 | — | — | — | ibm / storage scale | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IB | 56d ago |
| CVE-2026-72675 | 7.1 | — | — | — | elastic / kibana | Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data mod | 56d ago |
| CVE-2026-72643 | 7.1 | — | — | — | elastic / kibana | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when o | 56d ago |
| CVE-2026-72632 | 7.1 | — | — | — | elastic / kibana | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). | 56d ago |
| CVE-2026-72630 | 7.1 | — | — | — | elastic / kibana | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122) | 56d ago |
| CVE-2026-72629 | 7.1 | — | — | — | elastic / kibana | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access v | 56d ago |
| CVE-2026-59714 | 7.1 | — | — | — | — | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. | 56d ago |
| CVE-2026-48099 | 7.1 | — | — | — | — | WsgiDAV is a generic and extendable WebDAV server based on WSGI. | 56d ago |
| CVE-2026-16896 | 7.1 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due | 56d ago |
| CVE-2026-13365 | 7.1 | — | — | — | ibm / planning analytics local | IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacke | 56d ago |
| CVE-2026-73266 | 7.1 | — | — | — | — | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). | 57d ago |
| CVE-2026-58437 | 7.1 | — | — | — | — | Repository Visibility Manipulation via Git Push Options | 57d ago |
| CVE-2026-58416 | 7.1 | — | — | — | — | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard | 57d ago |
| CVE-2026-68453 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_ciphe | 57d ago |
| CVE-2026-63426 | 7.1 | — | — | — | — | During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could | 57d ago |
| CVE-2026-53802 | 7.1 | — | — | — | samba / rsync | rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to | 57d ago |
| CVE-2026-53785 | 7.1 | — | — | — | — | rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside t | 57d ago |
| CVE-2026-53784 | 7.1 | — | — | — | samba / rsync | rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the | 57d ago |
| CVE-2026-28154 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Sam | 57d ago |
| CVE-2026-12036 | 7.1 | — | — | — | — | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commer | 57d ago |
| CVE-2026-66700 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | 57d ago |
| CVE-2026-66698 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. | 57d ago |
| CVE-2026-66697 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10. | 57d ago |
| CVE-2026-66655 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. | 57d ago |
| CVE-2026-66468 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | 57d ago |
| CVE-2026-66449 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions. | 57d ago |
| CVE-2026-66429 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | 57d ago |
| CVE-2026-66426 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. | 57d ago |
| CVE-2026-65580 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. | 57d ago |
| CVE-2026-61974 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. | 57d ago |
| CVE-2026-61965 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. | 57d ago |
| CVE-2026-61960 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions. | 57d ago |
| CVE-2026-28187 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211. | 57d ago |
| CVE-2026-28175 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | 57d ago |
| CVE-2026-28173 | 7.1 | — | — | — | — | Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. | 57d ago |
| CVE-2026-28170 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. | 57d ago |