| CVE-2026-27091 | 6.3 | medium | — | Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured | 170d ago |
| CVE-2026-31999 | 6.3 | medium | openclaw / openclaw | OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerabili | 171d ago |
| CVE-2026-33265 | 6.3 | medium | librechat / librechat | In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API. | 171d ago |
| CVE-2026-4308 | 6.3 | medium | — | A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. | 173d ago |
| CVE-2026-4241 | 6.3 | medium | — | A vulnerability was identified in itsourcecode College Management System 1.0. | 173d ago |
| CVE-2026-4234 | 6.3 | medium | — | A security flaw has been discovered in SSCMS 7.4.0. | 173d ago |
| CVE-2026-4230 | 6.3 | medium | — | A vulnerability has been found in vanna-ai vanna up to 2.0.2. | 173d ago |
| CVE-2026-4228 | 6.3 | medium | lb-link / bl-wr9000 firmware | A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. | 173d ago |
| CVE-2026-4215 | 6.3 | medium | — | A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. | 173d ago |
| CVE-2026-4210 | 6.3 | medium | dlink / dnr-202l firmware | A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, D | 173d ago |
| CVE-2026-4209 | 6.3 | medium | dlink / dnr-202l firmware | A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-32 | 173d ago |
| CVE-2026-4207 | 6.3 | medium | dlink / dnr-202l firmware | A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-32 | 173d ago |
| CVE-2026-4206 | 6.3 | medium | dlink / dnr-202l firmware | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D | 173d ago |
| CVE-2026-4205 | 6.3 | medium | dlink / dnr-202l firmware | A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-32 | 173d ago |
| CVE-2026-4204 | 6.3 | medium | dlink / dnr-202l firmware | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-3 | 173d ago |
| CVE-2026-4203 | 6.3 | medium | dlink / dnr-202l firmware | A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L | 173d ago |
| CVE-2026-4197 | 6.3 | medium | dlink / dnr-202l firmware | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D | 173d ago |
| CVE-2026-4196 | 6.3 | medium | dlink / dns-1550-04 firmware | A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-32 | 173d ago |
| CVE-2026-4195 | 6.3 | medium | dlink / dnr-202l firmware | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-3 | 173d ago |
| CVE-2026-4192 | 6.3 | medium | — | A vulnerability has been found in AvinashBole quip-mcp-server 1.0.0. | 173d ago |
| CVE-2026-4185 | 6.3 | medium | — | A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. | 173d ago |
| CVE-2026-4173 | 6.3 | medium | — | A flaw has been found in CodePhiliaX Chat2DB up to 0.3.7. | 173d ago |
| CVE-2026-4171 | 6.3 | medium | — | A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. | 173d ago |
| CVE-2026-2491 | 6.3 | medium | — | Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. | 173d ago |
| CVE-2025-25277 | 6.3 | medium | openatom / openharmony | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps thr | 173d ago |
| CVE-2026-32745 | 6.3 | medium | jetbrains / datalore | In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie sett | 176d ago |
| CVE-2025-66249 | 6.3 | medium | apache / livy | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. | 176d ago |
| CVE-2025-60012 | 6.3 | medium | apache / livy | Malicious configuration can lead to unauthorized file access in Apache Livy. | 176d ago |
| CVE-2025-13913 | 6.3 | medium | inductiveautomation / ignition | A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, | 177d ago |
| CVE-2026-24125 | 6.3 | medium | ssw / tinacms\/graphql | Tina is a headless content management system. | 177d ago |
| CVE-2026-4039 | 6.3 | medium | openclaw / openclaw | A vulnerability was determined in OpenClaw 2026.2.19-2. | 177d ago |
| CVE-2026-4013 | 6.3 | medium | — | A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. | 177d ago |
| CVE-2026-3992 | 6.3 | medium | — | A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. | 177d ago |
| CVE-2026-3977 | 6.3 | medium | — | A security vulnerability has been detected in projectsend up to r1945. | 178d ago |
| CVE-2026-3968 | 6.3 | medium | — | A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. | 178d ago |
| CVE-2026-3967 | 6.3 | medium | — | A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. | 178d ago |
| CVE-2026-3966 | 6.3 | medium | — | A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. | 178d ago |
| CVE-2026-3965 | 6.3 | medium | — | A security vulnerability has been detected in whyour qinglong up to 2.20.1. | 178d ago |
| CVE-2026-3961 | 6.3 | medium | — | A vulnerability was determined in zyddnys manga-image-translator up to beta-0.3. | 178d ago |
| CVE-2026-3958 | 6.3 | medium | — | A vulnerability has been found in Woahai321 ListSync up to 0.6.6. | 178d ago |
| CVE-2026-32128 | 6.3 | medium | fastgpt / fastgpt | FastGPT is an AI Agent building platform. | 178d ago |
| CVE-2026-3955 | 6.3 | medium | — | A security vulnerability has been detected in elecV2P up to 3.8.3. | 178d ago |
| CVE-2026-30868 | 6.3 | medium | opnsense / opnsense | OPNsense is a FreeBSD based firewall and routing platform. | 178d ago |
| CVE-2026-20165 | 6.3 | medium | splunk / splunk | In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10 | 178d ago |
| CVE-2026-20162 | 6.3 | medium | splunk / splunk | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10. | 178d ago |
| CVE-2019-25645 | 6.2 | medium | — | WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to | 165d ago |
| CVE-2019-25644 | 6.2 | medium | direct-soft / winmpg video convert | WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog t | 165d ago |
| CVE-2019-25632 | 6.2 | medium | dulldusk / phpfilemanager | phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read a | 165d ago |
| CVE-2026-33320 | 6.2 | medium | tomwright / dasel | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. | 166d ago |
| CVE-2026-30007 | 6.2 | medium | xnview / nconvert | XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file | 166d ago |
| CVE-2026-30006 | 6.2 | medium | xnview / nconvert | XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file. | 166d ago |
| CVE-2019-25625 | 6.2 | medium | pixarra / blob studio | Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application b | 166d ago |
| CVE-2019-25624 | 6.2 | medium | pixarra / liquid studio | Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application | 166d ago |
| CVE-2019-25623 | 6.2 | medium | pixarra / luminance studio | Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the applicat | 166d ago |
| CVE-2019-25622 | 6.2 | medium | pixarra / paint studio | Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application | 166d ago |
| CVE-2019-25621 | 6.2 | medium | pixarra / pixel studio | Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application | 166d ago |
| CVE-2019-25620 | 6.2 | medium | pixarra / tree studio | Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application b | 166d ago |
| CVE-2019-25618 | 6.2 | medium | — | AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application | 167d ago |
| CVE-2019-25617 | 6.2 | medium | — | Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows loca | 167d ago |
| CVE-2019-25616 | 6.2 | medium | — | AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the applica | 167d ago |