| CVE-2026-23970 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions. | 115d ago |
| CVE-2025-68872 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 vers | 115d ago |
| CVE-2025-68851 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions. | 115d ago |
| CVE-2025-68840 | 7.1 | — | — | — | — | Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions. | 115d ago |
| CVE-2026-53704 | 7.1 | — | — | — | — | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. | 115d ago |
| CVE-2026-53703 | 7.1 | — | — | — | — | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). | 115d ago |
| CVE-2026-52722 | 7.1 | — | — | — | — | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. | 115d ago |
| CVE-2026-52719 | 7.1 | — | — | — | — | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. | 115d ago |
| CVE-2026-5233 | 7.1 | — | — | — | — | Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. | 115d ago |
| CVE-2026-5230 | 7.1 | — | — | — | — | Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. | 115d ago |
| CVE-2019-25746 | 7.1 | — | — | — | — | WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated at | 115d ago |
| CVE-2026-49396 | 7.1 | — | — | — | — | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. | 118d ago |
| CVE-2026-48119 | 7.1 | — | — | — | — | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. | 118d ago |
| CVE-2026-47120 | 7.1 | — | — | — | — | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. | 118d ago |
| CVE-2026-3840 | 7.1 | — | — | — | linuxfoundation / kedro | A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version | 118d ago |
| CVE-2026-42653zero day | 7.1 | 0.25% | 1/3 | same day | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai S | 119d ago |
| CVE-2023-33999zero day | 7.1 | 0.27% | 1/3 | 1059d before | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP M | 120d ago |
| CVE-2026-40987 | 7.1 | — | — | — | vmware / spring integration | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outsid | 120d ago |
| CVE-2022-26758 | 7.1 | — | — | — | apple / macos | A malicious application may cause unexpected changes in memory shared between processes. | 120d ago |
| CVE-2026-20258 | 7.1 | — | — | — | splunk / splunk | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 1 | 120d ago |
| CVE-2026-53689 | 7.1 | — | — | — | — | libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a conne | 120d ago |
| CVE-2026-49069 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portf | 120d ago |
| CVE-2026-45542 | 7.1 | — | — | — | espressif / esp-idf | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. | 121d ago |
| CVE-2026-45329 | 7.1 | — | — | — | espressif / esp-idf | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. | 121d ago |
| CVE-2026-53674 | 7.1 | — | — | — | — | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, whe | 121d ago |
| CVE-2026-48569 | 7.1 | — | — | — | microsoft / visual studio code | Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature local | 121d ago |
| CVE-2026-47288 | 7.1 | — | — | — | microsoft / windows server 2012 | Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent | 121d ago |
| CVE-2026-45649 | 7.1 | — | — | — | microsoft / excel | Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. | 121d ago |
| CVE-2026-46322 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp | 121d ago |
| CVE-2026-46321 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun | 121d ago |
| CVE-2016-20063 | 7.1 | — | — | — | — | Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute a | 121d ago |
| CVE-2026-24349 | 7.1 | — | — | — | siemens / simatic wincc unified pc runtime | A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified | 122d ago |
| CVE-2026-41845 | 7.1 | — | — | — | vmware / spring framework | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in | 122d ago |
| CVE-2026-44751 | 7.1 | — | — | — | — | Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an atta | 122d ago |
| CVE-2026-49141 | 7.1 | — | — | — | — | WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows a | 122d ago |
| CVE-2026-48507 | 7.1 | — | — | — | snipeitapp / snipe-it | Snipe-IT is an IT asset/license management system. | 122d ago |
| CVE-2026-46293 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds ac | 122d ago |
| CVE-2026-46657 | 7.1 | — | — | — | — | Bludit is a content management system. | 122d ago |
| CVE-2026-34194 | 7.1 | — | — | — | — | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement o | 122d ago |
| CVE-2026-11422 | 7.1 | — | — | — | — | Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDr | 125d ago |
| CVE-2026-21037 | 7.1 | — | — | — | samsung / members | Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary | 125d ago |
| CVE-2026-21033 | 7.1 | — | — | — | samsung / assistant | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to versi | 125d ago |
| CVE-2026-21032 | 7.1 | — | — | — | samsung / assistant | Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version | 125d ago |
| CVE-2026-11269 | 7.1 | — | — | — | google / chrome | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privil | 126d ago |
| CVE-2025-67448 | 7.1 | — | — | — | — | The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. | 126d ago |
| CVE-2026-36176 | 7.1 | — | — | — | — | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the se | 126d ago |
| CVE-2026-10840 | 7.1 | — | — | — | — | A flaw was found in the OpenShift Pipelines operator. | 126d ago |
| CVE-2025-52612 | 7.1 | — | — | — | hcltech / icontrol | HCL iControl was affected by Export CSV - CSV Injection vulnerability. | 126d ago |
| CVE-2026-8874 | 7.1 | — | — | — | securly / securly | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering r | 127d ago |
| CVE-2026-36606 | 7.1 | — | — | — | — | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DE | 127d ago |
| CVE-2025-15654 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes P | 128d ago |
| CVE-2026-31942 | 7.1 | — | — | — | librechat / librechat | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. | 128d ago |
| CVE-2026-8036 | 7.1 | — | — | — | ni / ni-pal | Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potenti | 128d ago |
| CVE-2026-8035 | 7.1 | — | — | — | ni / ni-pal | Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of ser | 128d ago |
| CVE-2026-42654 | 7.1 | — | — | — | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce | 128d ago |
| CVE-2026-42685 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job | 128d ago |
| CVE-2025-52759 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudi | 129d ago |
| CVE-2026-24090 | 7.1 | — | — | — | qualcomm / snapdragon 460 mobile platform firmware | Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. | 129d ago |
| CVE-2018-25431 | 7.1 | — | — | — | — | No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoi | 129d ago |
| CVE-2018-25430 | 7.1 | — | — | — | — | Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary S | 129d ago |