| CVE-2026-28158 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. | 57d ago |
| CVE-2026-28004 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | 57d ago |
| CVE-2026-28003 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | 57d ago |
| CVE-2026-27539 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions. | 57d ago |
| CVE-2026-27536 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. | 57d ago |
| CVE-2026-27535 | 7.1 | — | — | — | — | Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. | 57d ago |
| CVE-2026-73617 | 7.1 | — | — | — | — | Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-s | 57d ago |
| CVE-2026-73331 | 7.1 | — | — | — | — | CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with p | 57d ago |
| CVE-2026-16494 | 7.1 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 | 57d ago |
| CVE-2026-17248 | 7.1 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to impro | 57d ago |
| CVE-2026-73291 | 7.1 | — | — | — | — | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. | 58d ago |
| CVE-2026-16294 | 7.1 | — | — | — | — | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast E | 58d ago |
| CVE-2026-68447 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkp | 58d ago |
| CVE-2026-63177 | 7.1 | — | — | — | — | Malcolm is a network traffic analysis tool suite. | 58d ago |
| CVE-2026-71474 | 7.1 | — | — | — | redhat / advanced cluster management for kubernetes | A flaw was found in insights-client. | 58d ago |
| CVE-2026-18711 | 7.1 | — | — | — | — | An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileg | 58d ago |
| CVE-2026-18694 | 7.1 | — | — | — | — | An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges t | 58d ago |
| CVE-2026-18688 | 7.1 | — | — | — | — | An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds m | 58d ago |
| CVE-2026-18687 | 7.1 | — | — | — | — | MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain reques | 58d ago |
| CVE-2026-65675 | 7.1 | — | — | — | microsoft / github copilot chat | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a sec | 58d ago |
| CVE-2026-48442 | 7.1 | — | — | — | adobe / c2pa | CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trave | 58d ago |
| CVE-2026-53416 | 7.1 | — | — | — | — | Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure vi | 59d ago |
| CVE-2026-48495 | 7.1 | — | — | — | — | TypeBot is a chatbot builder tool. | 59d ago |
| CVE-2026-42142 | 7.1 | — | — | — | — | TypeBot is a chatbot builder tool. | 59d ago |
| CVE-2026-18640 | 7.1 | — | — | — | — | The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDI | 59d ago |
| CVE-2026-72609 | 7.1 | — | — | — | — | An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta | 59d ago |
| CVE-2026-72607 | 7.1 | — | — | — | — | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticat | 59d ago |
| CVE-2026-72547 | 7.1 | — | — | — | — | An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated eve | 59d ago |
| CVE-2026-72546 | 7.1 | — | — | — | — | An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated eve | 59d ago |
| CVE-2026-72694 | 7.1 | — | — | — | — | A flaw was found in MRTG. | 59d ago |
| CVE-2026-72910 | 7.1 | — | — | — | — | ERPNext is a free and open source Enterprise Resource Planning tool. | 59d ago |
| CVE-2026-18620 | 7.1 | — | — | — | — | A flaw was found in Data Science Pipelines. | 59d ago |
| CVE-2026-69112 | 7.1 | — | — | — | — | Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and loa | 59d ago |
| CVE-2026-72731 | 7.1 | — | — | — | — | Discourse is an open-source discussion platform. | 59d ago |
| CVE-2026-72690 | 7.1 | — | — | — | — | An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacke | 60d ago |
| CVE-2026-68425 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before r | 60d ago |
| CVE-2026-68420 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: reject optional IPTFS templates in outbo | 60d ago |
| CVE-2026-68402 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when che | 60d ago |
| CVE-2026-68348 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description stri | 60d ago |
| CVE-2026-68293 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on | 60d ago |
| CVE-2026-68262 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix user array stride in pvr_ | 60d ago |
| CVE-2026-68258 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue | 60d ago |
| CVE-2026-68229 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference li | 60d ago |
| CVE-2026-68173 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready() instead of ub-> | 60d ago |
| CVE-2026-68172 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handled unaligned ad | 60d ago |
| CVE-2026-68103 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject mapping a reserved doorbell | 60d ago |
| CVE-2026-21059 | 7.1 | — | — | — | samsung / android | Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local | 60d ago |
| CVE-2026-21058 | 7.1 | — | — | — | samsung / android | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete fil | 60d ago |
| CVE-2026-19389 | 7.1 | — | — | — | — | Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer ( | 60d ago |
| CVE-2026-66061 | 7.1 | — | — | — | — | Home Assistant is open source home automation software focused on local control and privacy. | 62d ago |
| CVE-2026-66060 | 7.1 | — | — | — | — | Home Assistant is open source home automation software focused on local control and privacy. | 62d ago |
| CVE-2025-71412 | 7.1 | — | — | — | — | Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational con | 62d ago |
| CVE-2025-71409 | 7.1 | — | — | — | — | Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC mes | 62d ago |
| CVE-2026-71556 | 7.1 | — | — | — | — | go-git is an extensible git implementation library written in pure Go. | 62d ago |
| CVE-2026-18497 | 7.1 | — | — | — | — | A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used | 63d ago |
| CVE-2026-49746 | 7.1 | — | — | — | — | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel | 63d ago |
| CVE-2026-70635 | 7.1 | — | — | — | timescale / timescaledb | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows auth | 63d ago |
| CVE-2026-5856 | 7.1 | — | — | — | — | Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no | 63d ago |
| CVE-2026-18277 | 7.1 | — | — | — | escriptorium / escriptorium | Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows | 64d ago |
| CVE-2026-66711 | 7.1 | — | — | — | — | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. | 64d ago |