| CVE-2026-32611 | 7 | — | — | — | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 204d ago |
| CVE-2026-32608 | 7 | — | — | — | nicolargo / glances | Glances is an open-source system cross-platform monitoring tool. | 204d ago |
| CVE-2026-32041 | 6.9 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowi | 203d ago |
| CVE-2026-33308 | 6.8 | — | — | — | mod gnutls project / mod gnutls | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. | 199d ago |
| CVE-2026-32279 | 6.8 | — | — | — | opensource-workshop / connect-cms | Connect-CMS is a content management system. | 199d ago |
| CVE-2026-33194 | 6.8 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 202d ago |
| CVE-2025-62843 | 6.8 | — | — | — | qnap / qurouter | An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect Q | 202d ago |
| CVE-2026-32812 | 6.8 | — | — | — | admidio / admidio | Admidio is an open-source user management solution. | 203d ago |
| CVE-2026-32750 | 6.8 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 203d ago |
| CVE-2026-32007 | 6.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool t | 203d ago |
| CVE-2026-32005 | 6.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks includi | 203d ago |
| CVE-2026-32747 | 6.8 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 203d ago |
| CVE-2026-29607 | 6.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persist | 204d ago |
| CVE-2026-22174 | 6.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loo | 205d ago |
| CVE-2026-32291 | 6.8 | — | — | — | gl-inet / comet gl-rm1 firmware | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. | 205d ago |
| CVE-2026-3227 | 6.8 | — | — | — | tp-link / tl-wr802n firmware | A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to im | 206d ago |
| CVE-2026-32705 | 6.8 | — | — | — | dronecode / px4 drone autopilot | PX4 autopilot is a flight control solution for drones. | 206d ago |
| CVE-2026-31864 | 6.8 | — | — | — | fit2cloud / jumpserver | JumpServer is an open source bastion host and an operation and maintenance security audit system. | 209d ago |
| CVE-2026-2808 | 6.8 | — | — | — | — | HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when | 211d ago |
| CVE-2026-32112 | 6.8 | — | — | — | homeassistant-ai / home assistant mcp server | ha-mcp is a Home Assistant MCP Server. | 211d ago |
| CVE-2026-32103 | 6.8 | — | — | — | studiocms / studiocms | StudioCMS is a server-side-rendered, Astro native, headless content management system. | 211d ago |
| CVE-2026-20118 | 6.8 | — | — | — | — | A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Sof | 211d ago |
| CVE-2026-34926zero day | 6.7 | 0.54% | 3/3 | same day | trendmicro / apex one | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local atta | 140d ago |
| CVE-2026-33549 | 6.7 | — | — | — | spip / spip | SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) duri | 201d ago |
| CVE-2026-22902 | 6.7 | — | — | — | qnap / qunetswitch | A command injection vulnerability has been reported to affect QuNetSwitch. | 202d ago |
| CVE-2025-62846 | 6.7 | — | — | — | qnap / qurouter | An SQL injection vulnerability has been reported to affect QHora. | 202d ago |
| CVE-2025-62845 | 6.7 | — | — | — | qnap / qurouter | An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. | 202d ago |
| CVE-2026-29608 | 6.7 | — | — | — | openclaw / openclaw | OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewrit | 204d ago |
| CVE-2026-22169 | 6.7 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that | 205d ago |
| CVE-2026-4105 | 6.7 | — | — | — | — | A flaw was found in systemd. | 209d ago |
| CVE-2026-32259 | 6.7 | — | — | — | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 210d ago |
| CVE-2026-0940 | 6.7 | — | — | — | — | A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a loc | 211d ago |
| CVE-2026-24510 | 6.7 | — | — | — | dell / alienware command center | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulner | 211d ago |
| CVE-2026-32003 | 6.6 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run fun | 203d ago |
| CVE-2026-32694 | 6.6 | — | — | — | canonical / juju | In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the se | 204d ago |
| CVE-2026-2462 | 6.6 | — | — | — | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on | 206d ago |
| CVE-2026-20262zero day | 6.5 | 28.2% | 3/3 | same day | cisco / catalyst sd-wan manager | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authentica | 115d ago |
| CVE-2026-48710zero day | 6.5 | 7.1% | 3/3 | same day | encode / starlette | Starlette is a lightweight ASGI framework/toolkit. | 135d ago |
| CVE-2026-33421 | 6.5 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 198d ago |
| CVE-2026-33417 | 6.5 | — | — | — | wallosapp / wallos | Wallos is an open-source, self-hostable personal subscription tracker. | 198d ago |
| CVE-2026-33401 | 6.5 | — | — | — | wallosapp / wallos | Wallos is an open-source, self-hostable personal subscription tracker. | 198d ago |
| CVE-2026-33162 | 6.5 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 198d ago |
| CVE-2026-33159 | 6.5 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 198d ago |
| CVE-2026-33158 | 6.5 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 198d ago |
| CVE-2026-33677 | 6.5 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 198d ago |
| CVE-2026-33676 | 6.5 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 198d ago |
| CVE-2026-33474 | 6.5 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 198d ago |
| CVE-2026-30662 | 6.5 | — | — | — | concretecms / concrete cms | ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. | 198d ago |
| CVE-2026-30655 | 6.5 | — | — | — | esiclivre / esiclivre | SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remot | 198d ago |
| CVE-2026-4728 | 6.5 | — | — | — | mozilla / firefox | Spoofing issue in the Privacy: Anti-Tracking component. | 198d ago |
| CVE-2026-4749 | 6.5 | — | — | — | — | NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0. | 199d ago |
| CVE-2026-3138 | 6.5 | — | — | — | — | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a mis | 199d ago |
| CVE-2026-3079 | 6.5 | — | — | — | — | The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_ord | 199d ago |
| CVE-2026-33283 | 6.5 | — | — | — | ellanetworks / ella core | Ella Core is a 5G core designed for private networks. | 199d ago |
| CVE-2026-33281 | 6.5 | — | — | — | ellanetworks / ella core | Ella Core is a 5G core designed for private networks. | 199d ago |
| CVE-2026-2412 | 6.5 | — | — | — | — | The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' para | 199d ago |
| CVE-2026-23487 | 6.5 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 199d ago |
| CVE-2026-23484 | 6.5 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 199d ago |
| CVE-2026-23481 | 6.5 | — | — | — | blinko / blinko | Blinko is an AI-powered card note-taking project. | 199d ago |
| CVE-2026-30886 | 6.5 | — | — | — | newapi / new api | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. | 199d ago |