| CVE-2026-46996 | 7.1 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Meta | 79d ago |
| CVE-2026-56147 | 7.1 | — | — | — | elastic / kibana | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosu | 79d ago |
| CVE-2026-47697 | 7.1 | — | — | — | — | Shelf is a platform for tracking physical assets. | 79d ago |
| CVE-2026-64880 | 7.1 | — | — | — | tenable / security center | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without p | 79d ago |
| CVE-2026-3183 | 7.1 | — | — | — | — | Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. | 80d ago |
| CVE-2026-55550 | 7.1 | — | — | — | — | NextCRM is open-source customer relationship management (CRM) software. | 80d ago |
| CVE-2026-56623 | 7.1 | — | — | — | apache / mina sshd | Path traversal on Windows in Apache MINA SSHD component sshd-git. | 80d ago |
| CVE-2026-47130 | 7.1 | — | — | — | — | NextCRM is open-source customer relationship management (CRM) software. | 80d ago |
| CVE-2026-63771 | 7.1 | — | — | — | — | Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attribut | 80d ago |
| CVE-2026-58484 | 7.1 | — | — | — | network-ai / network-ai | Network-AI is a TypeScript/Node.js multi-agent orchestrator. | 80d ago |
| CVE-2026-39879 | 7.1 | — | — | — | — | Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e | 80d ago |
| CVE-2026-9833 | 7.1 | — | — | — | — | The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly e | 81d ago |
| CVE-2026-12970 | 7.1 | — | — | — | — | The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML | 81d ago |
| CVE-2026-64186 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Remove latent out-of-bounds access | 81d ago |
| CVE-2026-64172 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Disable AVIC IPI virtualization on H | 81d ago |
| CVE-2026-64121 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: ifb: report ethtool stats over num_tx_que | 81d ago |
| CVE-2026-64111 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_at | 81d ago |
| CVE-2026-64095 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid double decrement of bla | 81d ago |
| CVE-2026-63920 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: validate extension header length before | 81d ago |
| CVE-2026-63833 | 7.1 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ntfs3: reject direct userspace writes to reser | 82d ago |
| CVE-2026-63806 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: KVM: Replace guest-triggerable BUG_ON() in ioe | 82d ago |
| CVE-2026-53402 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: fbdev: fbcon: fix out-of-bounds read in err_ou | 82d ago |
| CVE-2026-53396 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak and ignored error in | 82d ago |
| CVE-2026-53387 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6075: add bounds check to veml | 82d ago |
| CVE-2026-53368 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency caused by incorre | 82d ago |
| CVE-2026-47870 | 7.1 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a privilege escalation vulnerability. | 83d ago |
| CVE-2026-56171 | 7.1 | — | — | — | microsoft / remote desktop web client | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker t | 83d ago |
| CVE-2026-52584 | 7.1 | — | — | — | — | Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive informatio | 83d ago |
| CVE-2026-45784 | 7.1 | — | — | — | sfackler / openssl | rust-openssl provides OpenSSL bindings for the Rust programming language. | 83d ago |
| CVE-2026-50163 | 7.1 | — | — | — | — | oras-go is a Go library for managing OCI artifacts. | 83d ago |
| CVE-2026-49284 | 7.1 | — | — | — | simplesamlphp / simplesamlphp | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. | 83d ago |
| CVE-2026-16118 | 7.1 | — | — | — | — | A flaw was found in xdgmime. | 83d ago |
| CVE-2026-62387 | 7.1 | — | — | — | — | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its def | 84d ago |
| CVE-2026-62219 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds val | 84d ago |
| CVE-2026-62212 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. | 84d ago |
| CVE-2026-62206 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. | 84d ago |
| CVE-2026-62205 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams m | 84d ago |
| CVE-2024-34268 | 7.1 | — | — | — | — | EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to | 84d ago |
| CVE-2026-46336 | 7.1 | — | — | — | — | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focus | 84d ago |
| CVE-2026-59867 | 7.1 | — | — | — | — | Kiota is an OpenAPI based HTTP Client code generator. | 84d ago |
| CVE-2026-12978 | 7.1 | — | — | — | — | The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into | 85d ago |
| CVE-2026-52890 | 7.1 | — | — | — | — | Wekan is open source kanban built with Meteor. | 85d ago |
| CVE-2026-52869 | 7.1 | — | — | — | lfprojects / mcp python sdk | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). | 85d ago |
| CVE-2026-50144 | 7.1 | — | — | — | — | ncnn is a high-performance neural network inference framework optimized for the mobile platform. | 85d ago |
| CVE-2026-59255 | 7.1 | — | — | — | — | BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-no | 85d ago |
| CVE-2026-53515 | 7.1 | — | — | — | better-auth / better-auth\/sso | Better Auth is an authentication and authorization library for TypeScript. | 85d ago |
| CVE-2026-54563 | 7.1 | — | — | — | — | Cloudreve is a self-hosted file management and sharing system. | 85d ago |
| CVE-2026-15641 | 7.1 | — | — | — | devolutions / devolutions server | Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an | 86d ago |
| CVE-2026-58529 | 7.1 | — | — | — | microsoft / windows 11 26h1 | Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose infor | 86d ago |
| CVE-2026-57101 | 7.1 | — | — | — | microsoft / visual studio code | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows | 86d ago |
| CVE-2026-55122 | 7.1 | — | — | — | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 86d ago |
| CVE-2026-50682 | 7.1 | — | — | — | microsoft / windows 10 21h2 | Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. | 86d ago |
| CVE-2026-50465 | 7.1 | — | — | — | microsoft / windows 11 24h2 | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | 86d ago |
| CVE-2026-50451 | 7.1 | — | — | — | microsoft / windows 10 1607 | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authori | 86d ago |
| CVE-2026-50428 | 7.1 | — | — | — | microsoft / windows 11 26h1 | Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to | 86d ago |
| CVE-2026-56193 | 7.1 | — | — | — | microsoft / 365 apps | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 86d ago |
| CVE-2026-55144 | 7.1 | — | — | — | microsoft / windows 11 24h2 | Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. | 86d ago |
| CVE-2026-50354 | 7.1 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 86d ago |
| CVE-2026-49791 | 7.1 | — | — | — | microsoft / windows 10 1607 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) | 86d ago |
| CVE-2026-49165 | 7.1 | — | — | — | microsoft / windows 10 1607 | Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information | 86d ago |