| CVE-2026-54545 | 7.1 | — | — | — | — | wakaru is a JavaScript decompiler and unminifier toolkit. | 72d ago |
| CVE-2026-14870 | 7.1 | — | — | — | — | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise | 73d ago |
| CVE-2026-65447 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | 73d ago |
| CVE-2026-65446 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | 73d ago |
| CVE-2026-65443 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. | 73d ago |
| CVE-2026-65441 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | 73d ago |
| CVE-2026-65440 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | 73d ago |
| CVE-2026-65439 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | 73d ago |
| CVE-2026-65438 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | 73d ago |
| CVE-2026-65437 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | 73d ago |
| CVE-2026-61957 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | 73d ago |
| CVE-2026-64725 | 7.1 | — | — | — | apple / ipados | An out-of-bounds write issue was addressed with improved bounds checking. | 73d ago |
| CVE-2026-64692 | 7.1 | — | — | — | apple / ipados | An out-of-bounds read was addressed with improved bounds checking. | 73d ago |
| CVE-2026-64546 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drm/edid: fix OOB read in drm_parse_tiled_bloc | 73d ago |
| CVE-2026-43813 | 7.1 | — | — | — | apple / ipados | A validation issue was addressed with improved input sanitization. | 73d ago |
| CVE-2026-43771 | 7.1 | — | — | — | apple / macos | A stack overflow was addressed with improved input validation. | 73d ago |
| CVE-2026-43747 | 7.1 | — | — | — | apple / macos | An out-of-bounds read was addressed with improved bounds checking. | 73d ago |
| CVE-2026-43681 | 7.1 | — | — | — | apple / macos | A buffer overflow was addressed with improved bounds checking. | 73d ago |
| CVE-2026-43672 | 7.1 | — | — | — | apple / macos | An authorization issue was addressed with improved state management. | 73d ago |
| CVE-2026-28945 | 7.1 | — | — | — | apple / macos | A permissions issue was addressed with additional sandbox restrictions. | 73d ago |
| CVE-2026-65922 | 7.1 | — | — | — | jfrog / artifactory | An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited reposito | 73d ago |
| CVE-2026-66759 | 7.1 | — | — | — | gimp / gimp | A flaw was found in the file-icns plugin in GIMP. | 73d ago |
| CVE-2026-59558 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | 73d ago |
| CVE-2026-59556 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versio | 73d ago |
| CVE-2026-59553zero day | 7.1 | 0.25% | 1/3 | 3d before | — | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | 73d ago |
| CVE-2026-13726 | 7.1 | — | — | — | — | The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the re | 74d ago |
| CVE-2026-64501 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted | 76d ago |
| CVE-2026-64496 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: iio: event: Fix event FIFO reset race `iio_eve | 76d ago |
| CVE-2026-64452 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix NHC entry use-after-free on error | 76d ago |
| CVE-2026-64436 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp | 76d ago |
| CVE-2026-64422 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes | 76d ago |
| CVE-2026-64412 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null | 76d ago |
| CVE-2026-64411 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name befo | 76d ago |
| CVE-2026-64407 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix out-of-bounds firmwa | 76d ago |
| CVE-2026-64403 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length befor | 76d ago |
| CVE-2026-64379 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 0777 | 76d ago |
| CVE-2026-64339 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: bound bulk IN response lengt | 76d ago |
| CVE-2026-64323 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VA | 76d ago |
| CVE-2026-64318 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: partitions: aix: bound the pp_count scan to th | 76d ago |
| CVE-2026-64317 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink components to | 76d ago |
| CVE-2026-64299 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent out-of-bounds read in glob ma | 76d ago |
| CVE-2026-64298 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: NFSv4: include MAY_WRITE in open permission ma | 76d ago |
| CVE-2026-64284 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure vendor's exit handler runs be | 76d ago |
| CVE-2026-65710 | 7.1 | — | — | — | — | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with | 76d ago |
| CVE-2026-64243 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bou | 76d ago |
| CVE-2026-64237 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size befor | 76d ago |
| CVE-2026-64209 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array a | 76d ago |
| CVE-2026-9765 | 7.1 | — | — | — | — | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. | 77d ago |
| CVE-2026-15968 | 7.1 | — | — | — | progress / moveit transfer | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOV | 77d ago |
| CVE-2026-65918 | 7.1 | — | — | — | linuxfoundation / torchvision | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in | 77d ago |
| CVE-2026-65896 | 7.1 | — | — | — | — | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field | 78d ago |
| CVE-2026-65540 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | 78d ago |
| CVE-2026-65539 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | 78d ago |
| CVE-2026-65511 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme < | 78d ago |
| CVE-2026-65510 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | 78d ago |
| CVE-2026-65494 | 7.1 | — | — | — | — | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | 78d ago |
| CVE-2026-65492 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions. | 78d ago |
| CVE-2026-65488 | 7.1 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | 78d ago |
| CVE-2026-61947 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | 78d ago |
| CVE-2026-61944 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | 78d ago |