| CVE-2026-55651 | 7.1 | — | — | — | — | Easy!Appointments is a self hosted appointment scheduler. | 86d ago |
| CVE-2026-10671 | 7.1 | — | — | — | zephyrproject / zephyr | In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used | 86d ago |
| CVE-2026-62191 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handl | 87d ago |
| CVE-2026-62189 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows | 87d ago |
| CVE-2026-58410 | 7.1 | — | — | — | — | ChurchCRM is an open-source church management system. | 87d ago |
| CVE-2026-61956 | 7.1 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basala | 88d ago |
| CVE-2026-59516 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Crea | 88d ago |
| CVE-2026-57816 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Fu | 88d ago |
| CVE-2026-57814 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Y | 88d ago |
| CVE-2026-57745 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Th | 88d ago |
| CVE-2026-57741 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing N | 88d ago |
| CVE-2026-57740 | 7.1 | — | — | — | — | Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exp | 88d ago |
| CVE-2026-57734 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 88d ago |
| CVE-2026-57733 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 88d ago |
| CVE-2026-57732 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 88d ago |
| CVE-2026-57728 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Fl | 88d ago |
| CVE-2026-57725 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirk | 88d ago |
| CVE-2026-57718 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited El | 88d ago |
| CVE-2026-57715 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinj | 88d ago |
| CVE-2026-57712 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOO | 88d ago |
| CVE-2026-57708 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Co | 88d ago |
| CVE-2026-57706 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. | 88d ago |
| CVE-2026-57695 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter | 88d ago |
| CVE-2026-57668 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Fo | 88d ago |
| CVE-2026-57423 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome | 88d ago |
| CVE-2026-57422 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme B | 88d ago |
| CVE-2026-57421 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CR | 88d ago |
| CVE-2026-57417 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme Car | 88d ago |
| CVE-2026-57416 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround S | 88d ago |
| CVE-2026-57415 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen | 88d ago |
| CVE-2026-57411 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Vie | 88d ago |
| CVE-2026-57409 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 A | 88d ago |
| CVE-2026-57405 | 7.1 | — | — | — | — | Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Acce | 88d ago |
| CVE-2026-57403 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrov | 88d ago |
| CVE-2026-57399 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy & | 88d ago |
| CVE-2026-57398 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPla | 88d ago |
| CVE-2026-57396 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free | 88d ago |
| CVE-2026-57394 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant So | 88d ago |
| CVE-2026-57388 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hyd | 88d ago |
| CVE-2026-57387 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu pi | 88d ago |
| CVE-2026-57383 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSe | 88d ago |
| CVE-2026-57382 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Ben | 88d ago |
| CVE-2026-57381 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hiv | 88d ago |
| CVE-2026-57380 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Exten | 88d ago |
| CVE-2026-57379 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Formy | 88d ago |
| CVE-2026-57376 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Inva | 88d ago |
| CVE-2026-57369 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Th | 88d ago |
| CVE-2026-57368 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Job | 88d ago |
| CVE-2026-57363 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud | 88d ago |
| CVE-2026-12275 | 7.1 | — | — | — | — | The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform th | 88d ago |
| CVE-2026-61442 | 7.1 | — | — | — | — | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH route | 89d ago |
| CVE-2026-55880 | 7.1 | — | — | — | — | OpenReplay is a self-hosted session replay suite. | 90d ago |
| CVE-2026-55460 | 7.1 | — | — | — | snipeitapp / snipe-it | Snipe-IT is an IT asset/license management system. | 90d ago |
| CVE-2026-39903 | 7.1 | — | — | — | — | Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass | 90d ago |
| CVE-2026-50181 | 7.1 | — | — | — | — | Langroid is a framework for building large-language-model-powered applications. | 91d ago |
| CVE-2026-55212 | 7.1 | — | — | — | — | Pimcore is an Open Source Data & Experience Management Platform. | 91d ago |
| CVE-2026-0281 | 7.1 | — | — | — | paloaltonetworks / pan-os | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker | 91d ago |
| CVE-2026-59219 | 7.1 | — | — | — | openwebui / open webui | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. | 91d ago |
| CVE-2026-59206 | 7.1 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 91d ago |
| CVE-2026-59691 | 7.1 | — | — | — | — | A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. | 92d ago |