| CVE-2026-31883 | 6.5 | medium | freerdp / freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. | 176d ago |
| CVE-2026-30955 | 6.5 | medium | forceu / gokapi | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. | 176d ago |
| CVE-2026-2673 | 6.5 | medium | openssl / openssl | Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its k | 176d ago |
| CVE-2026-23940 | 6.5 | medium | hex / hexpm | Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. | 176d ago |
| CVE-2026-22216 | 6.5 | medium | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to sub | 176d ago |
| CVE-2025-36368 | 6.5 | medium | ibm / sterling b2b integrator | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, an | 176d ago |
| CVE-2025-13778 | 6.5 | medium | — | Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affe | 176d ago |
| CVE-2026-32269 | 6.5 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 177d ago |
| CVE-2026-32251 | 6.5 | medium | tolgee / tolgee | Tolgee is an open-source localization platform. | 177d ago |
| CVE-2026-32240 | 6.5 | medium | capnproto / capnproto | Cap'n Proto is a data interchange format and capability-based RPC system. | 177d ago |
| CVE-2026-32239 | 6.5 | medium | capnproto / capnproto | Cap'n Proto is a data interchange format and capability-based RPC system. | 177d ago |
| CVE-2026-1525 | 6.5 | medium | nodejs / undici | Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g | 177d ago |
| CVE-2026-32245 | 6.5 | medium | tinyauth / tinyauth | Tinyauth is an authentication and authorization server. | 177d ago |
| CVE-2025-66955 | 6.5 | medium | asseco / live | Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenti | 177d ago |
| CVE-2025-61154 | 6.5 | medium | gnu / libredwg | Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file | 177d ago |
| CVE-2026-31841 | 6.5 | medium | hyperterse / hyperterse | Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. | 177d ago |
| CVE-2026-3937 | 6.5 | medium | google / chrome | Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to | 178d ago |
| CVE-2026-3935 | 6.5 | medium | google / chrome | Incorrect security UI in WebAppInstalls in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perfor | 178d ago |
| CVE-2026-3934 | 6.5 | medium | google / chrome | Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker t | 178d ago |
| CVE-2026-32108 | 6.5 | medium | 9001 / copyparty | Copyparty is a portable file server. | 178d ago |
| CVE-2026-32102 | 6.5 | medium | olivetin / olivetin | OliveTin gives access to predefined shell commands from a web interface. | 178d ago |
| CVE-2026-3954 | 6.5 | medium | — | A weakness has been identified in OpenBMB XAgent 1.0.0. | 178d ago |
| CVE-2026-32094 | 6.5 | medium | shescape project / shescape | Shescape is a simple shell escape library for JavaScript. | 178d ago |
| CVE-2026-30239 | 6.5 | medium | openproject / openproject | OpenProject is an open-source, web-based project management software. | 178d ago |
| CVE-2026-30235 | 6.5 | medium | openproject / openproject | OpenProject is an open-source, web-based project management software. | 178d ago |
| CVE-2026-20164 | 6.5 | medium | splunk / splunk | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10 | 178d ago |
| CVE-2026-1471 | 6.5 | medium | neo4j / neo4j | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authen | 178d ago |
| CVE-2026-30234 | 6.5 | medium | openproject / openproject | OpenProject is an open-source, web-based project management software. | 178d ago |
| CVE-2026-29777 | 6.5 | medium | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 178d ago |
| CVE-2026-28803 | 6.5 | medium | maykinmedia / open forms | Open Forms allows users create and publish smart forms. | 178d ago |
| CVE-2025-13690 | 6.5 | medium | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6 | 178d ago |
| CVE-2025-12576 | 6.5 | medium | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, | 178d ago |
| CVE-2026-33679 | 6.4 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-33675 | 6.4 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-4752 | 6.4 | medium | — | Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329. | 165d ago |
| CVE-2025-6229 | 6.4 | medium | — | The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data | 166d ago |
| CVE-2026-3427 | 6.4 | medium | — | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored C | 168d ago |
| CVE-2025-71276 | 6.4 | medium | alinto / sogo | SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories. | 168d ago |
| CVE-2026-4086 | 6.4 | medium | — | The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and | 169d ago |
| CVE-2026-4084 | 6.4 | medium | — | The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast | 169d ago |
| CVE-2026-4077 | 6.4 | medium | — | The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' param | 169d ago |
| CVE-2026-4072 | 6.4 | medium | — | The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' sh | 169d ago |
| CVE-2026-4067 | 6.4 | medium | — | The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' at | 169d ago |
| CVE-2026-4022 | 6.4 | medium | — | The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Script | 169d ago |
| CVE-2026-3997 | 6.4 | medium | — | The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribu | 169d ago |
| CVE-2026-3996 | 6.4 | medium | — | The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in al | 169d ago |
| CVE-2026-3619 | 6.4 | medium | — | The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attri | 169d ago |
| CVE-2026-3617 | 6.4 | medium | — | The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' | 169d ago |
| CVE-2026-3554 | 6.4 | medium | — | The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titl | 169d ago |
| CVE-2026-3333 | 6.4 | medium | — | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkg | 169d ago |
| CVE-2026-2501 | 6.4 | medium | — | The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_sh | 169d ago |
| CVE-2026-2496 | 6.4 | medium | — | The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_ | 169d ago |
| CVE-2026-1914 | 6.4 | medium | — | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusedesk_newcase sh | 169d ago |
| CVE-2026-1911 | 6.4 | medium | — | The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter | 169d ago |
| CVE-2026-1908 | 6.4 | medium | — | The Integration with Hubspot Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hubsp | 169d ago |
| CVE-2026-1899 | 6.4 | medium | — | The Any Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aps_slider s | 169d ago |
| CVE-2026-1891 | 6.4 | medium | — | The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_s | 169d ago |
| CVE-2026-1889 | 6.4 | medium | — | The Outgrow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the 'outgro | 169d ago |
| CVE-2026-1886 | 6.4 | medium | — | The Go Night Pro | WordPress Dark Mode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl | 169d ago |
| CVE-2026-1854 | 6.4 | medium | — | The Post Flagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flag' shortcod | 169d ago |