| CVE-2026-32293 | 3.7 | — | — | — | gl-inet / comet gl-rm1 firmware | The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. | 205d ago |
| CVE-2025-71264 | 3.7 | — | — | — | mumble / mumble | Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client cra | 206d ago |
| CVE-2026-22204 | 3.7 | — | — | — | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail r | 209d ago |
| CVE-2025-13718 | 3.7 | — | — | — | ibm / sterling partner engagement manager | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote a | 209d ago |
| CVE-2026-4045 | 3.7 | — | — | — | — | A flaw has been found in projectsend up to r1945. | 210d ago |
| CVE-2026-3963 | 3.7 | — | — | — | — | A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. | 210d ago |
| CVE-2025-62328 | 3.7 | — | — | — | — | HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header b | 210d ago |
| CVE-2026-32109 | 3.7 | — | — | — | 9001 / copyparty | Copyparty is a portable file server. | 211d ago |
| CVE-2026-32018 | 3.6 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and remov | 202d ago |
| CVE-2026-32722 | 3.6 | — | — | — | bloomberg / memray | Memray is a memory profiler for Python. | 203d ago |
| CVE-2026-24509 | 3.6 | — | — | — | dell / alienware command center | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerabilit | 211d ago |
| CVE-2026-31863 | 3.6 | — | — | — | anytype / anytype cli | Anytype Heart is the middleware library for Anytype. | 211d ago |
| CVE-2026-4626 | 3.5 | — | — | — | projectworlds / online lawyer management system | A vulnerability has been found in projectworlds Lawyer Management System 1.0. | 198d ago |
| CVE-2026-4596 | 3.5 | — | — | — | projectworlds / online lawyer management system | A vulnerability was identified in projectworlds Lawyer Management System 1.0. | 199d ago |
| CVE-2026-33426 | 3.5 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 201d ago |
| CVE-2026-33422 | 3.5 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 201d ago |
| CVE-2026-4495 | 3.5 | — | — | — | — | A security flaw has been discovered in atjiu pybbs 6.0.0. | 202d ago |
| CVE-2026-4494 | 3.5 | — | — | — | — | A vulnerability was identified in atjiu pybbs 6.0.0. | 202d ago |
| CVE-2026-4355 | 3.5 | — | — | — | — | A vulnerability was detected in Portabilis i-Educar 2.11. | 204d ago |
| CVE-2026-4354 | 3.5 | — | — | — | — | A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. | 204d ago |
| CVE-2026-4239 | 3.5 | — | — | — | — | A vulnerability was found in Lagom WHMCS Template up to 2.3.7. | 206d ago |
| CVE-2026-4186 | 3.5 | — | — | — | — | A vulnerability was determined in UEditor up to 1.4.3.2. | 206d ago |
| CVE-2026-4175 | 3.5 | — | — | — | — | A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. | 206d ago |
| CVE-2026-4166 | 3.5 | — | — | — | — | A vulnerability was found in Wavlink WL-NU516U1 240425. | 206d ago |
| CVE-2026-3984 | 3.5 | — | — | — | — | A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. | 210d ago |
| CVE-2026-3983 | 3.5 | — | — | — | — | A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. | 210d ago |
| CVE-2025-12704 | 3.5 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, an | 211d ago |
| CVE-2026-32772 | 3.4 | — | — | — | gnu / inetutils | telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_EN | 206d ago |
| CVE-2026-4539 | 3.3 | — | — | — | — | A security flaw has been discovered in pygments up to 2.19.2. | 200d ago |
| CVE-2026-4519 | 3.3 | — | — | — | python / python | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for | 202d ago |
| CVE-2026-4159 | 3.3 | — | — | — | wolfssl / wolfssl | 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. | 202d ago |
| CVE-2026-32020 | 3.3 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follow | 202d ago |
| CVE-2025-52642 | 3.3 | — | — | — | hcltech / aion | HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application respons | 206d ago |
| CVE-2026-4219 | 3.3 | — | — | — | — | A flaw has been found in INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App up to 1.0.2 on Android. | 206d ago |
| CVE-2026-4174 | 3.3 | — | — | — | — | A vulnerability has been found in Radare2 5.9.9. | 206d ago |
| CVE-2026-20992 | 3.3 | — | — | — | samsung / android | Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring th | 206d ago |
| CVE-2026-0639 | 3.3 | — | — | — | openatom / openharmony | in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory. | 206d ago |
| CVE-2025-26474 | 3.3 | — | — | — | openatom / openharmony | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. | 206d ago |
| CVE-2025-13462 | 3.3 | — | — | — | python / python | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a | 210d ago |
| CVE-2026-4040 | 3.3 | — | — | — | openclaw / openclaw | A vulnerability was identified in OpenClaw up to 2026.2.17. | 210d ago |
| CVE-2026-4012 | 3.3 | — | — | — | — | A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. | 210d ago |
| CVE-2026-4010 | 3.3 | — | — | — | — | A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. | 210d ago |
| CVE-2026-4009 | 3.3 | — | — | — | — | A vulnerability has been found in jarikomppa soloud up to 20200207. | 210d ago |
| CVE-2026-3950 | 3.3 | — | — | — | — | A vulnerability was identified in strukturag libheif up to 1.21.2. | 211d ago |
| CVE-2026-3949 | 3.3 | — | — | — | — | A vulnerability was determined in strukturag libheif up to 1.21.2. | 211d ago |
| CVE-2026-4590 | 3.1 | — | — | — | — | A security flaw has been discovered in kalcaddle kodbox 1.64. | 199d ago |
| CVE-2026-4584 | 3.1 | — | — | — | — | A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. | 199d ago |
| CVE-2026-4549 | 3.1 | — | — | — | — | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. | 200d ago |
| CVE-2026-4477 | 3.1 | — | — | — | — | A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. | 202d ago |
| CVE-2026-32006 | 3.1 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identiti | 202d ago |
| CVE-2026-32943 | 3.1 | — | — | — | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 203d ago |
| CVE-2026-22545 | 3.1 | — | — | — | mattermost / mattermost server | Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth | 206d ago |
| CVE-2026-29776 | 3.1 | — | — | — | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 209d ago |
| CVE-2025-14811 | 3.1 | — | — | — | ibm / sterling partner engagement manager | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacke | 209d ago |
| CVE-2026-2366 | 3.1 | — | — | — | redhat / build of keycloak | A flaw was found in Keycloak. | 210d ago |
| CVE-2026-3929 | 3.1 | — | — | — | google / chrome | Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacke | 210d ago |
| CVE-2026-31974 | 3 | — | — | — | openproject / openproject | OpenProject is an open-source, web-based project management software. | 211d ago |
| CVE-2026-32778 | 2.9 | — | — | — | libexpat project / libexpat | libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-o | 206d ago |
| CVE-2026-0520 | 2.8 | — | — | — | lenovo / filez | A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, coul | 211d ago |
| CVE-2026-3339 | 2.7 | — | — | — | — | The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and inclu | 201d ago |