| CVE-2026-42759 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affilia | 134d ago |
| CVE-2026-42754 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Fa | 134d ago |
| CVE-2026-42749 | 7.1 | — | — | — | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post | 134d ago |
| CVE-2026-42739 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Adva | 134d ago |
| CVE-2026-42738 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smar | 134d ago |
| CVE-2026-42734 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn G | 134d ago |
| CVE-2026-42733 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 W | 134d ago |
| CVE-2026-42729 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hiv | 134d ago |
| CVE-2026-42728 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins H | 134d ago |
| CVE-2026-40836 | 7.1 | — | — | — | — | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage mode | 135d ago |
| CVE-2026-40834 | 7.1 | — | — | — | — | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.ph | 135d ago |
| CVE-2026-40833 | 7.1 | — | — | — | — | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files | 135d ago |
| CVE-2025-52747 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Them | 135d ago |
| CVE-2025-22741 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Fe | 135d ago |
| CVE-2026-6268 | 7.1 | — | — | — | — | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customi | 135d ago |
| CVE-2026-42012 | 7.1 | — | — | — | — | A flaw was found in gnutls. | 135d ago |
| CVE-2025-14361 | 7.1 | — | — | — | — | Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Pr | 135d ago |
| CVE-2026-3603 | 7.1 | — | — | — | ibm / engineering lifecycle management | IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through I | 135d ago |
| CVE-2026-24196 | 7.1 | — | — | — | nvidia / gpu display driver | NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. | 135d ago |
| CVE-2026-24195 | 7.1 | — | — | — | nvidia / gpu display driver | NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validatio | 135d ago |
| CVE-2026-48690 | 7.1 | — | — | — | pavel-odintsov / fastnetmon | FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer | 135d ago |
| CVE-2026-39436 | 7.1 | — | — | — | — | Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. | 136d ago |
| CVE-2018-25381 | 7.1 | — | — | — | — | Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to e | 136d ago |
| CVE-2018-25380 | 7.1 | — | — | — | — | Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to e | 136d ago |
| CVE-2018-25352 | 7.1 | — | — | — | — | WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that a | 138d ago |
| CVE-2018-25347 | 7.1 | — | — | — | — | WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attack | 138d ago |
| CVE-2018-25346 | 7.1 | — | — | — | — | WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated atta | 138d ago |
| CVE-2026-41074 | 7.1 | — | — | — | — | RT is an open source, enterprise-grade issue and ticket tracking system. | 139d ago |
| CVE-2026-9291 | 7.1 | — | — | — | — | Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a | 139d ago |
| CVE-2026-39968 | 7.1 | — | — | — | — | TypeBot is a chatbot builder tool. | 139d ago |
| CVE-2026-7325 | 7.1 | — | — | — | devolutions / devolutions server | Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authe | 139d ago |
| CVE-2026-48240 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id an | 140d ago |
| CVE-2026-48239 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST | 140d ago |
| CVE-2026-48238 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET pa | 140d ago |
| CVE-2026-48237 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and | 140d ago |
| CVE-2026-48236 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST pa | 140d ago |
| CVE-2026-48234 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the | 140d ago |
| CVE-2026-48233 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset | 140d ago |
| CVE-2026-48232 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the off | 140d ago |
| CVE-2026-48231 | 7.1 | — | — | — | — | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST param | 140d ago |
| CVE-2025-13477 | 7.1 | — | — | — | — | Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerabil | 140d ago |
| CVE-2026-44066 | 7.1 | — | — | — | — | Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a | 141d ago |
| CVE-2026-44064 | 7.1 | — | — | — | — | An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker | 141d ago |
| CVE-2026-32882exploited | 7.1 | 0.71% | 0/3 | — | — | libheif is a HEIF and AVIF file format decoder and encoder. | 142d ago |
| CVE-2026-32741 | 7.1 | — | — | — | — | libheif is a HEIF and AVIF file format decoder and encoder. | 142d ago |
| CVE-2026-7571 | 7.1 | — | — | — | redhat / build of keycloak | A flaw was found in Keycloak. | 142d ago |
| CVE-2026-30950 | 7.1 | — | — | — | — | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence | 143d ago |
| CVE-2026-45242 | 7.1 | — | — | — | steipete / summarize | Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows | 143d ago |
| CVE-2026-6495 | 7.1 | — | — | — | — | The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back | 144d ago |
| CVE-2018-25319 | 7.1 | — | — | — | — | Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to man | 144d ago |
| CVE-2021-47980 | 7.1 | — | — | — | — | Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate dat | 145d ago |
| CVE-2026-45350 | 7.1 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 146d ago |
| CVE-2026-44569 | 7.1 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 146d ago |
| CVE-2026-45399 | 7.1 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 146d ago |
| CVE-2026-45349 | 7.1 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 146d ago |
| CVE-2026-44556 | 7.1 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 146d ago |
| CVE-2026-45037 | 7.1 | — | — | — | tabby / tabby | Tabby (formerly Terminus) is a highly configurable terminal emulator. | 146d ago |
| CVE-2026-44641 | 7.1 | — | — | — | — | Microsoft APM is an open-source, community-driven dependency manager for AI agents. | 146d ago |
| CVE-2026-46333 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic | 146d ago |
| CVE-2026-44637 | 7.1 | — | — | — | saitoha / libsixel | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. | 147d ago |