| CVE-2026-55153 | 7.1 | — | — | — | — | mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection | 99d ago |
| CVE-2026-53346 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for | 99d ago |
| CVE-2026-53330 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_ | 99d ago |
| CVE-2026-53905 | 7.1 | — | — | — | mycomplianceoffice / mycomplianceoffice | MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-ac | 99d ago |
| CVE-2026-53904 | 7.1 | — | — | — | mycomplianceoffice / mco | MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. | 99d ago |
| CVE-2026-56320 | 7.1 | — | — | — | — | Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied | 100d ago |
| CVE-2026-11546 | 7.1 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery | 100d ago |
| CVE-2026-10546 | 7.1 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL compon | 100d ago |
| CVE-2026-43725 | 7.1 | — | — | — | apple / safari | The issue was addressed with improved input validation. | 101d ago |
| CVE-2026-43701 | 7.1 | — | — | — | apple / safari | The issue was addressed with improved checks. | 101d ago |
| CVE-2026-57338 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | 101d ago |
| CVE-2026-57337 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | 101d ago |
| CVE-2026-57336 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions. | 101d ago |
| CVE-2026-57333 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions. | 101d ago |
| CVE-2026-57332 | 7.1 | — | — | — | — | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | 101d ago |
| CVE-2026-57320 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions. | 101d ago |
| CVE-2026-54371 | 7.1 | — | — | — | — | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that a | 101d ago |
| CVE-2026-54369 | 7.1 | — | — | — | — | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get | 101d ago |
| CVE-2026-40522 | 7.1 | — | — | — | — | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that all | 101d ago |
| CVE-2026-57346 | 7.1 | — | — | — | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Priv | 102d ago |
| CVE-2026-13601 | 7.1 | — | — | — | redhat / enterprise linux | A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp | 102d ago |
| CVE-2026-49413 | 7.1 | — | — | — | freebsd / freebsd | The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. | 104d ago |
| CVE-2026-33560 | 7.1 | — | — | — | daktronics / dmp-5000 firmware | The DMP-5000 file service exposes authenticated arbitrary file upload functionality. | 104d ago |
| CVE-2026-53303 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: f2fs: protect extension_list reading with sb_l | 104d ago |
| CVE-2026-47214 | 7.1 | — | — | — | docling / docling | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative A | 104d ago |
| CVE-2026-57325 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions. | 104d ago |
| CVE-2026-57322 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions. | 104d ago |
| CVE-2026-57321 | 7.1 | — | — | — | — | Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions. | 104d ago |
| CVE-2026-57319 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions. | 104d ago |
| CVE-2026-57317 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. | 104d ago |
| CVE-2026-57314 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. | 104d ago |
| CVE-2026-57312 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. | 104d ago |
| CVE-2026-56072 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions. | 104d ago |
| CVE-2026-56047 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions. | 104d ago |
| CVE-2026-56045 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. | 104d ago |
| CVE-2026-56044 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. | 104d ago |
| CVE-2026-56043 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | 104d ago |
| CVE-2026-56041 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions. | 104d ago |
| CVE-2026-56040 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions. | 104d ago |
| CVE-2026-56039 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. | 104d ago |
| CVE-2026-56011zero day | 7.1 | 0.25% | 1/3 | 7d before | — | Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. | 104d ago |
| CVE-2026-57918 | 7.1 | — | — | — | — | libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/sock | 105d ago |
| CVE-2026-57520 | 7.1 | — | — | — | bitwarden / server | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom us | 105d ago |
| CVE-2026-55700 | 7.1 | — | — | — | pnpm / pnpm | pnpm is a package manager. | 105d ago |
| CVE-2026-49839 | 7.1 | — | — | — | jqlang / jq | jq is a command-line JSON processor. | 105d ago |
| CVE-2026-56071 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. | 105d ago |
| CVE-2026-56051 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. | 105d ago |
| CVE-2026-56042 | 7.1 | — | — | — | — | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | 105d ago |
| CVE-2026-56014 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. | 105d ago |
| CVE-2026-56006 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions. | 105d ago |
| CVE-2026-56005exploited | 7.1 | 0.25% | 1/3 | +99d | — | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. | 105d ago |
| CVE-2026-47151 | 7.1 | — | — | — | silabs / emberznet | In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Doo | 105d ago |
| CVE-2026-47150 | 7.1 | — | — | — | silabs / emberznet | In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table w | 105d ago |
| CVE-2026-47147 | 7.1 | — | — | — | silabs / emberznet | In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. | 105d ago |
| CVE-2026-53255 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV befo | 106d ago |
| CVE-2026-53253 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before pa | 106d ago |
| CVE-2026-53223 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue | 106d ago |
| CVE-2026-53205 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log | 106d ago |
| CVE-2026-53203 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add buffer overflow check in MS ge | 106d ago |
| CVE-2026-53187 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate cpu_id against nr_cpu_ids | 106d ago |