| CVE-2026-32946 | 2.7 | — | — | — | stepsecurity / harden-runner | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. | 202d ago |
| CVE-2026-29104 | 2.7 | — | — | — | suitecrm / suitecrm | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. | 202d ago |
| CVE-2026-33394 | 2.7 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 202d ago |
| CVE-2026-3230 | 2.7 | — | — | — | wolfssl / wolfssl | Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead t | 202d ago |
| CVE-2026-32638 | 2.7 | — | — | — | studiocms / studiocms | StudioCMS is a server-side-rendered, Astro native, headless content management system. | 203d ago |
| CVE-2025-31966 | 2.7 | — | — | — | hcltech / sametime | HCL Sametime is vulnerable to broken server-side validation. | 205d ago |
| CVE-2026-4285 | 2.7 | — | — | — | — | A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. | 205d ago |
| CVE-2026-32717 | 2.7 | — | — | — | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 206d ago |
| CVE-2025-69239 | 2.7 | — | — | — | raytha / raytha | Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. | 206d ago |
| CVE-2025-13459 | 2.7 | — | — | — | ibm / aspera console | IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper | 206d ago |
| CVE-2026-32445 | 2.7 | — | — | — | — | Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly | 209d ago |
| CVE-2025-70082 | 2.7 | — | — | — | lantronix / eds3016ps1ns firmware | An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive info | 211d ago |
| CVE-2026-32058 | 2.6 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows wi | 201d ago |
| CVE-2026-22735 | 2.6 | — | — | — | vmware / spring framework | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). | 202d ago |
| CVE-2026-4541 | 2.5 | — | — | — | — | A flaw has been found in janmojzis tinyssh up to 20250501. | 200d ago |
| CVE-2026-4251 | 2.5 | — | — | — | — | A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. | 206d ago |
| CVE-2026-4250 | 2.5 | — | — | — | — | A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. | 206d ago |
| CVE-2026-4243 | 2.5 | — | — | — | — | A weakness has been identified in La Nacion App 10.2.25 on Android. | 206d ago |
| CVE-2026-4242 | 2.5 | — | — | — | — | A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. | 206d ago |
| CVE-2026-4218 | 2.5 | — | — | — | — | A vulnerability was detected in myAEDES App up to 1.18.4 on Android. | 206d ago |
| CVE-2026-4217 | 2.5 | — | — | — | — | A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. | 206d ago |
| CVE-2026-24508 | 2.5 | — | — | — | dell / alienware command center | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vuln | 210d ago |
| CVE-2026-4616 | 2.4 | — | — | — | — | A security flaw has been discovered in bolo-blog up to 2.6.4. | 198d ago |
| CVE-2026-4595 | 2.4 | — | — | — | — | A vulnerability was determined in code-projects Exam Form Submission 1.0. | 199d ago |
| CVE-2026-4578 | 2.4 | — | — | — | — | A vulnerability was determined in code-projects Exam Form Submission 1.0. | 199d ago |
| CVE-2026-4577 | 2.4 | — | — | — | — | A vulnerability was found in code-projects Exam Form Submission 1.0. | 199d ago |
| CVE-2026-4576 | 2.4 | — | — | — | — | A vulnerability has been found in code-projects Exam Form Submission 1.0. | 199d ago |
| CVE-2026-4575 | 2.4 | — | — | — | — | A flaw has been found in code-projects Exam Form Submission 1.0. | 199d ago |
| CVE-2026-4544 | 2.4 | — | — | — | wavlink / wl-wn578w2 firmware | A vulnerability was determined in Wavlink WL-WN578W2 221110. | 200d ago |
| CVE-2026-4474 | 2.4 | — | — | — | angeljudesuarez / university management system | A flaw has been found in itsourcecode University Management System 1.0. | 202d ago |
| CVE-2026-4356 | 2.4 | — | — | — | — | A flaw has been found in itsourcecode University Management System 1.0. | 204d ago |
| CVE-2026-4225 | 2.4 | — | — | — | — | A security flaw has been discovered in CMS Made Simple up to 2.2.21. | 206d ago |
| CVE-2026-4169 | 2.4 | — | — | — | — | A security flaw has been discovered in Tecnick TCExam up to 16.6.0. | 206d ago |
| CVE-2026-4168 | 2.4 | — | — | — | — | A vulnerability was identified in Tecnick TCExam 16.5.0. | 206d ago |
| CVE-2026-4165 | 2.4 | — | — | — | — | A vulnerability has been found in Worksuite HR, CRM and Project Management up to 5.5.25. | 206d ago |
| CVE-2026-20989 | 2.4 | — | — | — | samsung / android | Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical | 206d ago |
| CVE-2026-30888 | 2.2 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 202d ago |
| CVE-2026-33408 | 2.2 | — | — | — | discourse / discourse | Discourse is an open-source discussion platform. | 202d ago |
| CVE-2025-52646 | 2.2 | — | — | — | hcltech / aion | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially | 206d ago |
| CVE-2025-12697 | 2.2 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, | 211d ago |
| CVE-2026-33550 | 2 | — | — | — | alinto / sogo | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digit | 200d ago |
| CVE-2026-4359 | 2 | — | — | — | mongodb / c driver | A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause | 204d ago |
| CVE-2025-52645 | 1.9 | — | — | — | hcltech / aion | HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficie | 206d ago |
| CVE-2025-52649 | 1.8 | — | — | — | hcltech / aion | HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. | 206d ago |
| CVE-2025-52636 | 1.8 | — | — | — | hcltech / aion | HCL AION is affected by a vulnerability related to the handling of upload size limits. | 206d ago |
| CVE-2026-32752 | 0 | — | — | — | freescout / freescout | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. | 202d ago |
| CVE-2026-31897 | 0 | — | — | — | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 209d ago |
| CVE-2026-31873 | 0 | — | — | — | unjs / unhead | Unhead is a document head and template manager. | 210d ago |
| CVE-2026-31954 | 0 | — | — | — | emlog / emlog | Emlog is an open source website building system. | 210d ago |
| CVE-2026-2417 | — | — | — | — | — | A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware ver | 198d ago |
| CVE-2026-23924 | — | — | — | — | — | Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding the | 198d ago |
| CVE-2026-23923 | — | — | — | — | — | An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classe | 198d ago |
| CVE-2026-23921 | — | — | — | — | — | A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api | 198d ago |
| CVE-2026-23920 | — | — | — | — | — | Host and event action script input is validated with a regex (set by the administrator), but the validation runs i | 198d ago |
| CVE-2026-23919 | — | — | — | — | — | For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript | 198d ago |
| CVE-2026-26809 | — | — | — | — | — | Rejected reason: DO NOT USE THIS CVE RECORD. | 198d ago |
| CVE-2025-11571 | — | — | — | — | — | Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. | 198d ago |
| CVE-2025-71275 | — | — | — | — | — | Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519. | 198d ago |
| CVE-2026-4649 | — | — | — | — | — | Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages | 198d ago |
| CVE-2026-4746 | — | — | — | — | — | Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). | 198d ago |