| CVE-2026-31919 | 4.3 | — | — | — | — | Missing Authorization vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for | 209d ago |
| CVE-2026-30961 | 4.3 | — | — | — | forceu / gokapi | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. | 209d ago |
| CVE-2026-30915 | 4.3 | — | — | — | sftpgo project / sftpgo | SFTPGo is an open source, event-driven file transfer solution. | 209d ago |
| CVE-2026-2859 | 4.3 | — | — | — | checkmk / checkmk | Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) a | 209d ago |
| CVE-2026-24097 | 4.3 | — | — | — | checkmk / checkmk | Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) | 209d ago |
| CVE-2026-22215 | 4.3 | — | — | — | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that a | 209d ago |
| CVE-2026-1704 | 4.3 | — | — | — | — | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable t | 209d ago |
| CVE-2025-14483 | 4.3 | — | — | — | ibm / sterling b2b integrator | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6. | 209d ago |
| CVE-2026-3234 | 4.3 | — | — | — | — | A flaw was found in mod_proxy_cluster. | 210d ago |
| CVE-2026-3993 | 4.3 | — | — | — | — | A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. | 210d ago |
| CVE-2026-3990 | 4.3 | — | — | — | — | A security flaw has been discovered in CesiumGS CesiumJS up to 1.137.0. | 210d ago |
| CVE-2026-2687 | 4.3 | — | — | — | — | The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which coul | 210d ago |
| CVE-2025-15473 | 4.3 | — | — | — | — | The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticat | 210d ago |
| CVE-2026-3982 | 4.3 | — | — | — | — | A vulnerability was determined in itsourcecode University Management System 1.0. | 210d ago |
| CVE-2026-3226 | 4.3 | — | — | — | — | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification trigger | 210d ago |
| CVE-2026-1182 | 4.3 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, | 210d ago |
| CVE-2026-3962 | 4.3 | — | — | — | — | A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. | 210d ago |
| CVE-2026-3942 | 4.3 | — | — | — | google / chrome | Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perf | 210d ago |
| CVE-2026-3941 | 4.3 | — | — | — | google / chrome | Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to by | 210d ago |
| CVE-2026-3938 | 4.3 | — | — | — | google / chrome | Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who | 210d ago |
| CVE-2026-3928 | 4.3 | — | — | — | google / chrome | Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convi | 210d ago |
| CVE-2026-3927 | 4.3 | — | — | — | google / chrome | Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perf | 210d ago |
| CVE-2026-3925 | 4.3 | — | — | — | google / chrome | Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attack | 210d ago |
| CVE-2026-32122 | 4.3 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 211d ago |
| CVE-2026-3951 | 4.3 | — | — | — | — | A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. | 211d ago |
| CVE-2026-30236 | 4.3 | — | — | — | openproject / openproject | OpenProject is an open-source, web-based project management software. | 211d ago |
| CVE-2025-12555 | 4.3 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, | 211d ago |
| CVE-2026-1732 | 4.3 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, | 211d ago |
| CVE-2026-1663 | 4.3 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, | 211d ago |
| CVE-2026-0602 | 4.3 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, | 211d ago |
| CVE-2026-32719 | 4.2 | — | — | — | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 206d ago |
| CVE-2026-3429 | 4.2 | — | — | — | redhat / build of keycloak | A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security leve | 211d ago |
| CVE-2026-32310 | 4.1 | — | — | — | cryptomator / cryptomator | Cryptomator encrypts data being stored on cloud infrastructure. | 202d ago |
| CVE-2026-27166 | 4.1 | — | — | — | discourse / discourse | Discourse is an open source discussion platform. | 203d ago |
| CVE-2026-30943 | 4.1 | — | — | — | forceu / gokapi | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. | 209d ago |
| CVE-2026-1230 | 4.1 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, a | 211d ago |
| CVE-2026-45498zero day | 4 | 1.3% | 3/3 | 1d before | microsoft / defender antimalware platform | Microsoft Defender Denial of Service Vulnerability | 141d ago |
| CVE-2026-32837 | 4 | — | — | — | mackron / miniaudio | miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vul | 205d ago |
| CVE-2026-32777 | 4 | — | — | — | libexpat project / libexpat | libexpat before 2.7.5 allows an infinite loop while parsing DTD content. | 206d ago |
| CVE-2026-32776 | 4 | — | — | — | libexpat project / libexpat | libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. | 206d ago |
| CVE-2026-3634 | 3.9 | — | — | — | gnome / libsoup | A flaw was found in libsoup. | 205d ago |
| CVE-2026-3633 | 3.9 | — | — | — | gnome / libsoup | A flaw was found in libsoup. | 205d ago |
| CVE-2026-3632 | 3.9 | — | — | — | gnome / libsoup | A flaw was found in libsoup, a library used by applications to send network requests. | 205d ago |
| CVE-2026-2290 | 3.8 | — | — | — | — | The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and | 201d ago |
| CVE-2026-26230 | 3.8 | — | — | — | mattermost / mattermost server | Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles | 206d ago |
| CVE-2026-4222 | 3.8 | — | — | — | — | A vulnerability was determined in SSCMS up to 7.4.0. | 206d ago |
| CVE-2026-32715 | 3.8 | — | — | — | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 206d ago |
| CVE-2026-0849 | 3.8 | — | — | — | zephyrproject / zephyr | Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto d | 206d ago |
| CVE-2026-4044 | 3.8 | — | — | — | — | A vulnerability was detected in projectsend up to r1945. | 210d ago |
| CVE-2026-28753 | 3.7 | — | — | — | f5 / nginx plus | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handl | 198d ago |
| CVE-2026-4588 | 3.7 | — | — | — | — | A vulnerability was determined in kalcaddle kodbox 1.64. | 199d ago |
| CVE-2026-4587 | 3.7 | — | — | — | — | A vulnerability was found in HybridAuth up to 3.12.2. | 199d ago |
| CVE-2026-4633 | 3.7 | — | — | — | redhat / build of keycloak | A flaw was found in Keycloak. | 199d ago |
| CVE-2026-4115 | 3.7 | — | — | — | putty / putty | A vulnerability was detected in PuTTY 0.83. | 200d ago |
| CVE-2026-32897 | 3.7 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfusc | 201d ago |
| CVE-2026-32067 | 3.7 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access con | 201d ago |
| CVE-2026-32050 | 3.7 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handl | 201d ago |
| CVE-2026-32595 | 3.7 | — | — | — | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 202d ago |
| CVE-2026-33070 | 3.7 | — | — | — | filerise / filerise | FileRise is a self-hosted web file manager / WebDAV server. | 202d ago |
| CVE-2026-31991 | 3.7 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist po | 203d ago |