| CVE-2026-3957 | 4.7 | — | — | — | — | A flaw has been found in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. | 211d ago |
| CVE-2026-3956 | 4.7 | — | — | — | — | A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. | 211d ago |
| CVE-2026-32106 | 4.7 | — | — | — | studiocms / studiocms | StudioCMS is a server-side-rendered, Astro native, headless content management system. | 211d ago |
| CVE-2026-32234 | 4.7 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 211d ago |
| CVE-2025-60948 | 4.6 | — | — | — | csprousers / csweb | Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. | 199d ago |
| CVE-2026-32953 | 4.6 | — | — | — | tillitis / tkey client | Tillitis TKey Client package is a Go package for a TKey client. | 202d ago |
| CVE-2026-32040 | 4.6 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that all | 203d ago |
| CVE-2026-1527 | 4.6 | — | — | — | nodejs / undici | ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can i | 210d ago |
| CVE-2025-52637 | 4.5 | — | — | — | hcl / aion | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially | 206d ago |
| CVE-2026-4161 | 4.4 | — | — | — | — | The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin set | 201d ago |
| CVE-2026-3354 | 4.4 | — | — | — | — | The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in a | 201d ago |
| CVE-2026-3353 | 4.4 | — | — | — | — | The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting | 201d ago |
| CVE-2026-2837 | 4.4 | — | — | — | — | The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settin | 201d ago |
| CVE-2026-2424 | 4.4 | — | — | — | — | The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setti | 201d ago |
| CVE-2026-2121 | 4.4 | — | — | — | — | The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' paramet | 201d ago |
| CVE-2026-1278 | 4.4 | — | — | — | — | The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver | 201d ago |
| CVE-2026-1247 | 4.4 | — | — | — | — | The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up | 201d ago |
| CVE-2026-3577 | 4.4 | — | — | — | — | The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias | 201d ago |
| CVE-2026-2432 | 4.4 | — | — | — | — | The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored | 202d ago |
| CVE-2026-33395 | 4.4 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 203d ago |
| CVE-2026-32119 | 4.4 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 203d ago |
| CVE-2026-31996 | 4.4 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that al | 203d ago |
| CVE-2026-20991 | 4.4 | — | — | — | samsung / android | Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to | 206d ago |
| CVE-2026-22210 | 4.4 | — | — | — | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious cod | 209d ago |
| CVE-2026-32237 | 4.4 | — | — | — | linuxfoundation / backstage\/plugin-scaffolder-backend | Backstage is an open framework for building developer portals. | 210d ago |
| CVE-2026-33527 | 4.3 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 198d ago |
| CVE-2026-33161 | 4.3 | — | — | — | craftcms / craft cms | Craft CMS is a content management system (CMS). | 198d ago |
| CVE-2026-33315 | 4.3 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 198d ago |
| CVE-2026-33313 | 4.3 | — | — | — | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 198d ago |
| CVE-2026-32642 | 4.3 | — | — | — | apache / artemis | Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an applicat | 198d ago |
| CVE-2026-33290 | 4.3 | — | — | — | — | WPGraphQL provides a GraphQL API for WordPress sites. | 198d ago |
| CVE-2026-4066 | 4.3 | — | — | — | — | The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili | 199d ago |
| CVE-2026-3225 | 4.3 | — | — | — | — | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question | 199d ago |
| CVE-2026-4628 | 4.3 | — | — | — | redhat / build of keycloak | A flaw was found in Keycloak. | 199d ago |
| CVE-2026-4563 | 4.3 | — | — | — | — | A weakness has been identified in MacCMS up to 2025.1000.4052. | 199d ago |
| CVE-2026-4557 | 4.3 | — | — | — | — | A vulnerability was detected in code-projects Exam Form Submission 1.0. | 200d ago |
| CVE-2026-4547 | 4.3 | — | — | — | — | A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. | 200d ago |
| CVE-2026-4510 | 4.3 | — | — | — | — | A weakness has been identified in PbootCMS up to 3.2.12. | 201d ago |
| CVE-2026-4143 | 4.3 | — | — | — | — | The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u | 201d ago |
| CVE-2026-4127 | 4.3 | — | — | — | — | The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and incl | 201d ago |
| CVE-2026-3332 | 4.3 | — | — | — | — | The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions | 201d ago |
| CVE-2026-3331 | 4.3 | — | — | — | — | The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, | 201d ago |
| CVE-2026-2294 | 4.3 | — | — | — | — | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unaut | 201d ago |
| CVE-2026-1935 | 4.3 | — | — | — | — | The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, a | 201d ago |
| CVE-2026-1503 | 4.3 | — | — | — | — | The login_register plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting | 201d ago |
| CVE-2026-1393 | 4.3 | — | — | — | — | The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forg | 201d ago |
| CVE-2026-1392 | 4.3 | — | — | — | — | The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i | 201d ago |
| CVE-2026-1390 | 4.3 | — | — | — | — | The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and | 201d ago |
| CVE-2026-1378 | 4.3 | — | — | — | — | The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i | 201d ago |
| CVE-2026-1253 | 4.3 | — | — | — | — | The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due | 201d ago |
| CVE-2026-32899 | 4.3 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-m | 201d ago |
| CVE-2026-33238 | 4.3 | — | — | — | wwbn / avideo | WWBN AVideo is an open source video platform. | 201d ago |
| CVE-2026-33423 | 4.3 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 202d ago |
| CVE-2026-33177 | 4.3 | — | — | — | statamic / statamic | Statamic is a Laravel and Git powered content management system (CMS). | 202d ago |
| CVE-2026-33171 | 4.3 | — | — | — | statamic / statamic | Statamic is a Laravel and Git powered content management system (CMS). | 202d ago |
| CVE-2026-30580 | 4.3 | — | — | — | leefish / file thingie | File Thingie 2.5.7 is vulnerable to Directory Traversal. | 202d ago |
| CVE-2026-33371 | 4.3 | — | — | — | synacor / zimbra collaboration suite | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. | 202d ago |
| CVE-2026-33369 | 4.3 | — | — | — | synacor / zimbra collaboration suite | Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service with | 202d ago |
| CVE-2026-33071 | 4.3 | — | — | — | filerise / filerise | FileRise is a self-hosted web file manager / WebDAV server. | 202d ago |
| CVE-2026-4136 | 4.3 | — | — | — | — | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions | 202d ago |