| CVE-2025-6969 | 5 | — | — | — | openatom / openharmony | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. | 206d ago |
| CVE-2026-32442 | 5 | — | — | — | — | Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control S | 209d ago |
| CVE-2026-32415 | 5 | — | — | — | — | Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue af | 209d ago |
| CVE-2026-31798 | 5 | — | — | — | fit2cloud / jumpserver | JumpServer is an open source bastion host and an operation and maintenance security audit system. | 209d ago |
| CVE-2026-30853 | 5 | — | — | — | calibre-ebook / calibre | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. | 209d ago |
| CVE-2026-31878 | 5 | — | — | — | frappe / frappe | Frappe is a full-stack web application framework. | 211d ago |
| CVE-2026-3848 | 5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, | 211d ago |
| CVE-2026-33700 | 4.9 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 198d ago |
| CVE-2026-32879 | 4.9 | — | — | — | newapi / new api | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. | 199d ago |
| CVE-2026-31850 | 4.9 | — | — | — | nexxtsolutions / nebula300plus firmware | Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administr | 199d ago |
| CVE-2026-3474 | 4.9 | — | — | — | — | The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via | 202d ago |
| CVE-2026-32947 | 4.9 | — | — | — | stepsecurity / harden-runner | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. | 202d ago |
| CVE-2026-30889 | 4.9 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 202d ago |
| CVE-2026-32828 | 4.9 | — | — | — | akuity / kargo | Kargo manages and automates the promotion of software artifacts. | 202d ago |
| CVE-2026-29101 | 4.9 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 203d ago |
| CVE-2026-29098 | 4.9 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 203d ago |
| CVE-2026-30873 | 4.9 | — | — | — | openwrt / openwrt | OpenWrt Project is a Linux operating system targeting embedded devices. | 203d ago |
| CVE-2026-26948 | 4.9 | — | — | — | — | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to | 204d ago |
| CVE-2026-22319 | 4.9 | — | — | — | — | A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send | 204d ago |
| CVE-2026-22318 | 4.9 | — | — | — | — | A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privile | 204d ago |
| CVE-2026-25790 | 4.9 | — | — | — | wazuh / wazuh | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 205d ago |
| CVE-2026-25772 | 4.9 | — | — | — | wazuh / wazuh | Wazuh is a free and open source platform used for threat prevention, detection, and response. | 205d ago |
| CVE-2026-29516 | 4.9 | — | — | — | buffaloamericas / terastation nas ts5400r firmware | Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnera | 206d ago |
| CVE-2026-32349 | 4.9 | — | — | — | — | Server-Side Request Forgery (SSRF) vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer allows Server Si | 209d ago |
| CVE-2026-22203 | 4.9 | — | — | — | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertentl | 209d ago |
| CVE-2026-2376 | 4.9 | — | — | — | redhat / quay | A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended inte | 210d ago |
| CVE-2024-51225 | 4.8 | — | — | — | phpgurukul / vehicle record management system | A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Reco | 199d ago |
| CVE-2024-51224 | 4.8 | — | — | — | phpgurukul / vehicle record management system | Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle | 199d ago |
| CVE-2024-51223 | 4.8 | — | — | — | phpgurukul / vehicle record management system | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record | 199d ago |
| CVE-2024-51222 | 4.8 | — | — | — | phpgurukul / vehicle record management system | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record | 199d ago |
| CVE-2026-32896 | 4.8 | — | — | — | openclaw / openclaw | The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentic | 201d ago |
| CVE-2026-32065 | 4.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where render | 201d ago |
| CVE-2026-22895 | 4.8 | — | — | — | qnap / quftp | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. | 202d ago |
| CVE-2026-32031 | 4.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authen | 203d ago |
| CVE-2026-31993 | 4.8 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion ap | 203d ago |
| CVE-2025-52648 | 4.8 | — | — | — | hcl / aion | HCL AION is affected by a vulnerability where offering images are not digitally signed. | 206d ago |
| CVE-2026-31867 | 4.8 | — | — | — | craftcms / craft commerce | Craft Commerce is an ecommerce platform for Craft CMS. | 211d ago |
| CVE-2026-31813 | 4.8 | — | — | — | supabase / auth | Supabase Auth is a JWT based API for managing users and issuing JWT tokens. | 211d ago |
| CVE-2026-33311 | 4.7 | — | — | — | dicebear / dicebear | DiceBear is an avatar library for designers and developers. | 198d ago |
| CVE-2026-4591 | 4.7 | — | — | — | — | A weakness has been identified in kalcaddle kodbox 1.64. | 199d ago |
| CVE-2026-4564 | 4.7 | — | — | — | — | A security vulnerability has been detected in yangzongzhuan RuoYi up to 4.8.2. | 200d ago |
| CVE-2026-4550 | 4.7 | — | — | — | — | A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. | 200d ago |
| CVE-2026-4537 | 4.7 | — | — | — | — | A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. | 200d ago |
| CVE-2026-4473 | 4.7 | — | — | — | unguardable / online doctor appointment system | A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. | 202d ago |
| CVE-2026-4471 | 4.7 | — | — | — | adonesevangelista / online frozen foods ordering system | A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. | 202d ago |
| CVE-2026-4470 | 4.7 | — | — | — | adonesevangelista / online frozen foods ordering system | A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. | 202d ago |
| CVE-2026-4469 | 4.7 | — | — | — | adonesevangelista / online frozen foods ordering system | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. | 202d ago |
| CVE-2026-4468 | 4.7 | — | — | — | — | A vulnerability was determined in Comfast CF-AC100 2.6.0.8. | 202d ago |
| CVE-2026-4467 | 4.7 | — | — | — | — | A vulnerability was found in Comfast CF-AC100 2.6.0.8. | 202d ago |
| CVE-2026-4466 | 4.7 | — | — | — | — | A vulnerability has been found in Comfast CF-AC100 2.6.0.8. | 202d ago |
| CVE-2026-3580 | 4.7 | — | — | — | wolfssl / wolfssl | In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bne | 203d ago |
| CVE-2026-32723 | 4.7 | — | — | — | nyariv / sandboxjs | SandboxJS is a JavaScript sandboxing library. | 204d ago |
| CVE-2026-32294 | 4.7 | — | — | — | jetkvm / kvm | JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. | 205d ago |
| CVE-2026-32290 | 4.7 | — | — | — | gl-inet / comet gl-rm1 firmware | The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firm | 205d ago |
| CVE-2025-62320 | 4.7 | — | — | — | hcltech / unica | HTML Injection can be carried out in Product when a web application does not properly check or clean user input be | 205d ago |
| CVE-2026-4284 | 4.7 | — | — | — | — | A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. | 206d ago |
| CVE-2026-4253 | 4.7 | — | — | — | tenda / ac8 firmware | A security flaw has been discovered in Tenda AC8 16.03.50.11. | 206d ago |
| CVE-2025-52643 | 4.7 | — | — | — | hcltech / aion | HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly | 206d ago |
| CVE-2026-4238 | 4.7 | — | — | — | — | A vulnerability has been found in itsourcecode College Management System 1.0. | 206d ago |
| CVE-2026-4189 | 4.7 | — | — | — | — | A weakness has been identified in phpipam up to 1.7.4. | 206d ago |