| CVE-2026-3634 | 3.9 | low | gnome / libsoup | A flaw was found in libsoup. | 172d ago |
| CVE-2026-3633 | 3.9 | low | gnome / libsoup | A flaw was found in libsoup. | 172d ago |
| CVE-2026-3632 | 3.9 | low | gnome / libsoup | A flaw was found in libsoup, a library used by applications to send network requests. | 172d ago |
| CVE-2026-2290 | 3.8 | low | — | The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and | 168d ago |
| CVE-2026-26230 | 3.8 | low | mattermost / mattermost server | Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles | 173d ago |
| CVE-2026-4222 | 3.8 | low | — | A vulnerability was determined in SSCMS up to 7.4.0. | 173d ago |
| CVE-2026-32715 | 3.8 | low | mintplexlabs / anythingllm | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during | 173d ago |
| CVE-2026-0849 | 3.8 | low | zephyrproject / zephyr | Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto d | 173d ago |
| CVE-2026-4044 | 3.8 | low | — | A vulnerability was detected in projectsend up to r1945. | 177d ago |
| CVE-2026-28753 | 3.7 | low | f5 / nginx plus | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handl | 165d ago |
| CVE-2026-4588 | 3.7 | low | — | A vulnerability was determined in kalcaddle kodbox 1.64. | 166d ago |
| CVE-2026-4587 | 3.7 | low | — | A vulnerability was found in HybridAuth up to 3.12.2. | 166d ago |
| CVE-2026-4633 | 3.7 | low | redhat / build of keycloak | A flaw was found in Keycloak. | 166d ago |
| CVE-2026-4115 | 3.7 | low | putty / putty | A vulnerability was detected in PuTTY 0.83. | 167d ago |
| CVE-2026-32897 | 3.7 | low | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfusc | 169d ago |
| CVE-2026-32067 | 3.7 | low | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access con | 169d ago |
| CVE-2026-32050 | 3.7 | low | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handl | 169d ago |
| CVE-2026-32595 | 3.7 | low | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 169d ago |
| CVE-2026-33070 | 3.7 | low | filerise / filerise | FileRise is a self-hosted web file manager / WebDAV server. | 169d ago |
| CVE-2026-31991 | 3.7 | low | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist po | 171d ago |
| CVE-2026-32293 | 3.7 | low | gl-inet / comet gl-rm1 firmware | The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. | 172d ago |
| CVE-2025-71264 | 3.7 | low | mumble / mumble | Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client cra | 173d ago |
| CVE-2026-22204 | 3.7 | low | gvectors / wpdiscuz | wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail r | 176d ago |
| CVE-2025-13718 | 3.7 | low | ibm / sterling partner engagement manager | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote a | 176d ago |
| CVE-2026-4045 | 3.7 | low | — | A flaw has been found in projectsend up to r1945. | 177d ago |
| CVE-2026-3963 | 3.7 | low | — | A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. | 178d ago |
| CVE-2025-62328 | 3.7 | low | — | HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header b | 178d ago |
| CVE-2026-32109 | 3.7 | low | 9001 / copyparty | Copyparty is a portable file server. | 178d ago |
| CVE-2026-32018 | 3.6 | low | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and remov | 170d ago |
| CVE-2026-32722 | 3.6 | low | bloomberg / memray | Memray is a memory profiler for Python. | 171d ago |
| CVE-2026-24509 | 3.6 | low | dell / alienware command center | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerabilit | 178d ago |
| CVE-2026-31863 | 3.6 | low | anytype / anytype cli | Anytype Heart is the middleware library for Anytype. | 178d ago |
| CVE-2026-4626 | 3.5 | low | projectworlds / online lawyer management system | A vulnerability has been found in projectworlds Lawyer Management System 1.0. | 165d ago |
| CVE-2026-4596 | 3.5 | low | projectworlds / online lawyer management system | A vulnerability was identified in projectworlds Lawyer Management System 1.0. | 166d ago |
| CVE-2026-33426 | 3.5 | low | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-33422 | 3.5 | low | discourse / discourse | Discourse is an open-source discussion platform. | 169d ago |
| CVE-2026-4495 | 3.5 | low | — | A security flaw has been discovered in atjiu pybbs 6.0.0. | 169d ago |
| CVE-2026-4494 | 3.5 | low | — | A vulnerability was identified in atjiu pybbs 6.0.0. | 169d ago |
| CVE-2026-4355 | 3.5 | low | — | A vulnerability was detected in Portabilis i-Educar 2.11. | 172d ago |
| CVE-2026-4354 | 3.5 | low | — | A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. | 172d ago |
| CVE-2026-4239 | 3.5 | low | — | A vulnerability was found in Lagom WHMCS Template up to 2.3.7. | 173d ago |
| CVE-2026-4186 | 3.5 | low | — | A vulnerability was determined in UEditor up to 1.4.3.2. | 173d ago |
| CVE-2026-4175 | 3.5 | low | — | A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. | 173d ago |
| CVE-2026-4166 | 3.5 | low | — | A vulnerability was found in Wavlink WL-NU516U1 240425. | 173d ago |
| CVE-2026-3984 | 3.5 | low | — | A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. | 177d ago |
| CVE-2026-3983 | 3.5 | low | — | A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. | 177d ago |
| CVE-2025-12704 | 3.5 | low | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, an | 178d ago |
| CVE-2026-32772 | 3.4 | low | gnu / inetutils | telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_EN | 173d ago |
| CVE-2026-4539 | 3.3 | low | — | A security flaw has been discovered in pygments up to 2.19.2. | 167d ago |
| CVE-2026-4519 | 3.3 | low | python / python | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for | 169d ago |
| CVE-2026-4159 | 3.3 | low | wolfssl / wolfssl | 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. | 170d ago |
| CVE-2026-32020 | 3.3 | low | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follow | 170d ago |
| CVE-2025-52642 | 3.3 | low | hcltech / aion | HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application respons | 173d ago |
| CVE-2026-4219 | 3.3 | low | — | A flaw has been found in INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App up to 1.0.2 on Android. | 173d ago |
| CVE-2026-4174 | 3.3 | low | — | A vulnerability has been found in Radare2 5.9.9. | 173d ago |
| CVE-2026-20992 | 3.3 | low | samsung / android | Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring th | 173d ago |
| CVE-2026-0639 | 3.3 | low | openatom / openharmony | in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory. | 173d ago |
| CVE-2025-26474 | 3.3 | low | openatom / openharmony | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. | 173d ago |
| CVE-2025-13462 | 3.3 | low | python / python | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a | 177d ago |
| CVE-2026-4040 | 3.3 | low | openclaw / openclaw | A vulnerability was identified in OpenClaw up to 2026.2.17. | 177d ago |