| CVE-2026-53179 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix buffer over-read in rt | 106d ago |
| CVE-2026-53149 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to b | 106d ago |
| CVE-2026-53146 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to ac | 106d ago |
| CVE-2026-53138 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk | 106d ago |
| CVE-2026-53132 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queu | 106d ago |
| CVE-2026-9154 | 7.1 | — | — | — | gnu / sed | Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to w | 106d ago |
| CVE-2026-54070 | 7.1 | — | — | — | — | SiYuan is an open-source personal knowledge management system. | 106d ago |
| CVE-2026-52808 | 7.1 | — | — | — | — | Gogs is an open source self-hosted Git service. | 106d ago |
| CVE-2026-53076 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix OOB in pcpu_init_value An out-of-boun | 106d ago |
| CVE-2026-53068 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: drm/komeda: fix integer overflow in AFBC frame | 106d ago |
| CVE-2026-53044 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fa | 106d ago |
| CVE-2026-53041 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix listxattr handling when the buffer | 106d ago |
| CVE-2026-53040 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate bg_bits during freefrag scan [ | 106d ago |
| CVE-2026-52988 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: join hook list via splic | 106d ago |
| CVE-2026-52953 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix oops due to out of scope acces | 106d ago |
| CVE-2026-57303 | 7.1 | — | — | — | jenkins / assembla | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) att | 106d ago |
| CVE-2026-56257 | 7.1 | — | — | — | — | Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_ap | 106d ago |
| CVE-2026-56256 | 7.1 | — | — | — | — | Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. | 106d ago |
| CVE-2026-56244 | 7.1 | — | — | — | — | Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insuffici | 106d ago |
| CVE-2026-52942 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set | 107d ago |
| CVE-2026-52917 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_ | 107d ago |
| CVE-2026-52915 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option l | 107d ago |
| CVE-2026-54761 | 7.1 | — | — | — | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 107d ago |
| CVE-2026-54318 | 7.1 | — | — | — | home-assistant / home assistant companion | Home Assistant is open source home automation software that puts local control and privacy first. | 107d ago |
| CVE-2026-54012 | 7.1 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 107d ago |
| CVE-2026-56275 | 7.1 | — | — | — | flowiseai / flowise | Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows att | 107d ago |
| CVE-2026-8172 | 7.1 | — | — | — | — | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecti | 108d ago |
| CVE-2026-10658 | 7.1 | — | — | — | zephyrproject / zephyr | bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is se | 108d ago |
| CVE-2026-10651 | 7.1 | — | — | — | zephyrproject / zephyr | bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the | 108d ago |
| CVE-2026-56314 | 7.1 | — | — | — | — | Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allo | 108d ago |
| CVE-2026-56280 | 7.1 | — | — | — | — | Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-onl | 108d ago |
| CVE-2026-50146 | 7.1 | — | — | — | astro / astro | Astro is a web framework. | 108d ago |
| CVE-2026-54290 | 7.1 | — | — | — | — | Hono is a Web application framework that provides support for any JavaScript runtime. | 108d ago |
| CVE-2026-41049 | 7.1 | — | — | — | presire / qsnapper | Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allo | 108d ago |
| CVE-2026-41048 | 7.1 | — | — | — | presire / qsnapper | Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a lo | 108d ago |
| CVE-2026-6858 | 7.1 | — | — | — | — | The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing una | 109d ago |
| CVE-2026-4259 | 7.1 | — | — | — | — | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before | 109d ago |
| CVE-2026-49346 | 7.1 | — | — | — | struktur / libde265 | libde265 is an open source implementation of the h.265 video codec. | 111d ago |
| CVE-2026-49295 | 7.1 | — | — | — | struktur / libde265 | libde265 is an open source implementation of the h.265 video codec. | 111d ago |
| CVE-2026-49339 | 7.1 | — | — | — | — | gonic is a music streaming server / free-software subsonic server API implementation. | 111d ago |
| CVE-2026-49338 | 7.1 | — | — | — | — | gonic is a music streaming server / free-software subsonic server API implementation. | 111d ago |
| CVE-2019-25761 | 7.1 | — | — | — | joomboost / joomcrm | Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to exe | 111d ago |
| CVE-2019-25759 | 7.1 | — | — | — | wdmtech / vbizz | Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execu | 111d ago |
| CVE-2019-25757 | 7.1 | — | — | — | wdmtech / vwishlist | Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbi | 111d ago |
| CVE-2019-25749 | 7.1 | — | — | — | cmsjunkie / j-cruiseportal | Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute | 111d ago |
| CVE-2026-56211 | 7.1 | — | — | — | — | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. | 111d ago |
| CVE-2026-56210 | 7.1 | — | — | — | — | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. | 111d ago |
| CVE-2026-56209 | 7.1 | — | — | — | — | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. | 111d ago |
| CVE-2017-20265 | 7.1 | — | — | — | pulseextensions / flip wall | Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to e | 111d ago |
| CVE-2017-20264 | 7.1 | — | — | — | pulseextensions / sponsor wall | Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers t | 111d ago |
| CVE-2026-53915 | 7.1 | — | — | — | jetbrains / goland | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | 111d ago |
| CVE-2026-48759 | 7.1 | — | — | — | — | TypeBot is a chatbot builder tool. | 113d ago |
| CVE-2026-48997 | 7.1 | — | — | — | — | e107 is a content management system (CMS). | 113d ago |
| CVE-2026-35066 | 7.1 | — | — | — | dell / powerflex manager | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. | 113d ago |
| CVE-2026-40720 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | 113d ago |
| CVE-2026-10641 | 7.1 | — | — | — | zephyrproject / zephyr | Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c | 113d ago |
| CVE-2025-69140 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions. | 113d ago |
| CVE-2025-68524 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions. | 113d ago |
| CVE-2026-9570 | 7.1 | — | — | — | — | The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inl | 113d ago |
| CVE-2026-8089 | 7.1 | — | — | — | — | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress pl | 113d ago |