| CVE-2026-41935 | 7.1 | — | — | — | — | Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where | 147d ago |
| CVE-2026-46446 | 7.1 | — | — | — | — | SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. | 148d ago |
| CVE-2026-46445 | 7.1 | — | — | — | — | SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection. | 148d ago |
| CVE-2026-32991 | 7.1 | — | — | — | — | Improper authorization checks of team members privileges allow a team member to escalate privileges to the team ow | 148d ago |
| CVE-2026-33377 | 7.1 | — | — | — | grafana / grafana | An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. | 148d ago |
| CVE-2020-37226 | 7.1 | — | — | — | — | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to | 148d ago |
| CVE-2020-37224 | 7.1 | — | — | — | — | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to | 148d ago |
| CVE-2026-4609 | 7.1 | — | — | — | — | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access d | 148d ago |
| CVE-2026-5371 | 7.1 | — | — | — | — | The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vu | 149d ago |
| CVE-2026-45226 | 7.1 | — | — | — | — | Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated | 149d ago |
| CVE-2026-41102 | 7.1 | — | — | — | microsoft / powerpoint | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. | 149d ago |
| CVE-2026-41101 | 7.1 | — | — | — | microsoft / word | Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. | 149d ago |
| CVE-2026-40401 | 7.1 | — | — | — | microsoft / windows 10 1607 | Windows TCP/IP Denial of Service Vulnerability | 149d ago |
| CVE-2026-25789 | 7.1 | — | — | — | — | Affected devices do not properly validate and sanitize filenames on the Firmware Update page. | 149d ago |
| CVE-2026-45430 | 7.1 | — | — | — | — | The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect | 150d ago |
| CVE-2026-28941 | 7.1 | — | — | — | apple / ipados | The issue was addressed with improved checks. | 150d ago |
| CVE-2026-45224 | 7.1 | — | — | — | — | Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that | 150d ago |
| CVE-2026-45001 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and confi | 150d ago |
| CVE-2026-2393 | 7.1 | — | — | — | lfprojects / mlflow | A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. | 150d ago |
| CVE-2019-25638 | 7.1 | — | — | — | — | Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to e | 198d ago |
| CVE-2026-33252 | 7.1 | — | — | — | lfprojects / mcp go sdk | The Go MCP SDK used Go's standard encoding/json. | 199d ago |
| CVE-2026-33723 | 7.1 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 199d ago |
| CVE-2026-33493 | 7.1 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 199d ago |
| CVE-2026-23555 | 7.1 | — | — | — | xen / xen | Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash x | 200d ago |
| CVE-2019-25573 | 7.1 | — | — | — | njtech / greencms | Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL | 201d ago |
| CVE-2026-32057 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control U | 202d ago |
| CVE-2026-33125 | 7.1 | — | — | — | frigate / frigate | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. | 202d ago |
| CVE-2024-32537 | 7.1 | — | — | — | — | Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forger | 202d ago |
| CVE-2026-32954 | 7.1 | — | — | — | frappe / erpnext | ERP is a free and open source Enterprise Resource Planning tool. | 203d ago |
| CVE-2026-29100 | 7.1 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 203d ago |
| CVE-2026-32023 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode | 203d ago |
| CVE-2026-32017 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that al | 203d ago |
| CVE-2026-27953 | 7.1 | — | — | — | collerek / ormar | ormar is a async mini ORM for Python. | 203d ago |
| CVE-2026-0819 | 7.1 | — | — | — | wolfssl / wolfssl | A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. | 203d ago |
| CVE-2026-27070 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Ev | 204d ago |
| CVE-2026-27068 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard | 204d ago |
| CVE-2026-25442 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes | 204d ago |
| CVE-2026-25438 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gu | 204d ago |
| CVE-2025-68836 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars | 204d ago |
| CVE-2025-67618 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWor | 204d ago |
| CVE-2025-53222 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 204d ago |
| CVE-2025-50001 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDi | 204d ago |
| CVE-2026-28073 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tri | 204d ago |
| CVE-2026-32000 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execu | 204d ago |
| CVE-2026-31994 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task scr | 204d ago |
| CVE-2026-31992 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allow | 204d ago |
| CVE-2026-28460 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers | 204d ago |
| CVE-2026-27566 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fa | 204d ago |
| CVE-2026-23269 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: apparmor: validate DFA start states are in bou | 204d ago |
| CVE-2025-55045 | 7.1 | — | — | — | murasoftware / mura cms | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address infor | 204d ago |
| CVE-2026-23244 | 7.1 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_ke | 204d ago |
| CVE-2026-22323 | 7.1 | — | — | — | — | A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to | 205d ago |
| CVE-2026-22322 | 7.1 | — | — | — | — | A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauth | 205d ago |
| CVE-2026-32254 | 7.1 | — | — | — | kube-router / kube-router | Kube-router is a turnkey solution for Kubernetes networking. | 205d ago |
| CVE-2026-22175 | 7.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-a | 205d ago |
| CVE-2026-26001 | 7.1 | — | — | — | glpi-project / glpi inventory | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI | 205d ago |
| CVE-2026-1264 | 7.1 | — | — | — | ibm / sterling b2b integrator | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2 | 205d ago |
| CVE-2026-25369 | 7.1 | — | — | — | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flex | 206d ago |
| CVE-2026-32706 | 7.1 | — | — | — | dronecode / px4 drone autopilot | PX4 autopilot is a flight control solution for drones. | 206d ago |
| CVE-2026-32617 | 7.1 | — | — | — | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 206d ago |