| CVE-2025-71269 | 7.5 | medium | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallbac | 171d ago |
| CVE-2025-71268 | 7.5 | medium | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error path | 171d ago |
| CVE-2026-32041 | 6.9 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowi | 170d ago |
| CVE-2026-33308 | 6.8 | medium | mod gnutls project / mod gnutls | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. | 166d ago |
| CVE-2026-32279 | 6.8 | medium | opensource-workshop / connect-cms | Connect-CMS is a content management system. | 166d ago |
| CVE-2026-33194 | 6.8 | medium | b3log / siyuan | SiYuan is a personal knowledge management system. | 169d ago |
| CVE-2025-62843 | 6.8 | medium | qnap / qurouter | An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect Q | 169d ago |
| CVE-2026-32812 | 6.8 | medium | admidio / admidio | Admidio is an open-source user management solution. | 170d ago |
| CVE-2026-32750 | 6.8 | medium | b3log / siyuan | SiYuan is a personal knowledge management system. | 170d ago |
| CVE-2026-32007 | 6.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool t | 170d ago |
| CVE-2026-32005 | 6.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks includi | 170d ago |
| CVE-2026-32747 | 6.8 | medium | b3log / siyuan | SiYuan is a personal knowledge management system. | 170d ago |
| CVE-2026-29607 | 6.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persist | 171d ago |
| CVE-2026-22174 | 6.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loo | 172d ago |
| CVE-2026-32291 | 6.8 | medium | gl-inet / comet gl-rm1 firmware | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. | 172d ago |
| CVE-2026-3227 | 6.8 | medium | tp-link / tl-wr802n firmware | A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to im | 173d ago |
| CVE-2026-32705 | 6.8 | medium | dronecode / px4 drone autopilot | PX4 autopilot is a flight control solution for drones. | 173d ago |
| CVE-2026-31864 | 6.8 | medium | fit2cloud / jumpserver | JumpServer is an open source bastion host and an operation and maintenance security audit system. | 176d ago |
| CVE-2026-2808 | 6.8 | medium | — | HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when | 178d ago |
| CVE-2026-32112 | 6.8 | medium | homeassistant-ai / home assistant mcp server | ha-mcp is a Home Assistant MCP Server. | 178d ago |
| CVE-2026-32103 | 6.8 | medium | studiocms / studiocms | StudioCMS is a server-side-rendered, Astro native, headless content management system. | 178d ago |
| CVE-2026-20118 | 6.8 | medium | — | A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Sof | 178d ago |
| CVE-2026-34926exploited | 6.7 | medium | trendmicro / apex one | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local atta | 107d ago |
| CVE-2026-33549 | 6.7 | medium | spip / spip | SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) duri | 168d ago |
| CVE-2026-22902 | 6.7 | medium | qnap / qunetswitch | A command injection vulnerability has been reported to affect QuNetSwitch. | 169d ago |
| CVE-2025-62846 | 6.7 | medium | qnap / qurouter | An SQL injection vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2025-62845 | 6.7 | medium | qnap / qurouter | An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. | 169d ago |
| CVE-2026-29608 | 6.7 | medium | openclaw / openclaw | OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewrit | 171d ago |
| CVE-2026-22169 | 6.7 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that | 172d ago |
| CVE-2026-4105 | 6.7 | medium | — | A flaw was found in systemd. | 176d ago |
| CVE-2026-32259 | 6.7 | medium | imagemagick / imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. | 177d ago |
| CVE-2026-0940 | 6.7 | medium | — | A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a loc | 178d ago |
| CVE-2026-24510 | 6.7 | medium | dell / alienware command center | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulner | 178d ago |
| CVE-2026-32003 | 6.6 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run fun | 170d ago |
| CVE-2026-32694 | 6.6 | medium | canonical / juju | In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the se | 171d ago |
| CVE-2026-2462 | 6.6 | medium | mattermost / mattermost server | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on | 173d ago |
| CVE-2026-20262exploited | 6.5 | medium | cisco / catalyst sd-wan manager | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authentica | 82d ago |
| CVE-2026-48710exploited | 6.5 | medium | encode / starlette | Starlette is a lightweight ASGI framework/toolkit. | 102d ago |
| CVE-2026-33421 | 6.5 | medium | parseplatform / parse-server | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. | 165d ago |
| CVE-2026-33417 | 6.5 | medium | wallosapp / wallos | Wallos is an open-source, self-hostable personal subscription tracker. | 165d ago |
| CVE-2026-33401 | 6.5 | medium | wallosapp / wallos | Wallos is an open-source, self-hostable personal subscription tracker. | 165d ago |
| CVE-2026-33162 | 6.5 | medium | craftcms / craft cms | Craft CMS is a content management system (CMS). | 165d ago |
| CVE-2026-33159 | 6.5 | medium | craftcms / craft cms | Craft CMS is a content management system (CMS). | 165d ago |
| CVE-2026-33158 | 6.5 | medium | craftcms / craft cms | Craft CMS is a content management system (CMS). | 165d ago |
| CVE-2026-33677 | 6.5 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-33676 | 6.5 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-33474 | 6.5 | medium | vikunja / vikunja | Vikunja is an open-source self-hosted task management platform. | 165d ago |
| CVE-2026-30662 | 6.5 | medium | concretecms / concrete cms | ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. | 165d ago |
| CVE-2026-30655 | 6.5 | medium | esiclivre / esiclivre | SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remot | 165d ago |
| CVE-2026-4728 | 6.5 | medium | mozilla / firefox | Spoofing issue in the Privacy: Anti-Tracking component. | 165d ago |
| CVE-2026-4749 | 6.5 | medium | — | NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0. | 165d ago |
| CVE-2026-3138 | 6.5 | medium | — | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a mis | 165d ago |
| CVE-2026-3079 | 6.5 | medium | — | The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_ord | 166d ago |
| CVE-2026-33283 | 6.5 | medium | ellanetworks / ella core | Ella Core is a 5G core designed for private networks. | 166d ago |
| CVE-2026-33281 | 6.5 | medium | ellanetworks / ella core | Ella Core is a 5G core designed for private networks. | 166d ago |
| CVE-2026-2412 | 6.5 | medium | — | The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' para | 166d ago |
| CVE-2026-23487 | 6.5 | medium | blinko / blinko | Blinko is an AI-powered card note-taking project. | 166d ago |
| CVE-2026-23484 | 6.5 | medium | blinko / blinko | Blinko is an AI-powered card note-taking project. | 166d ago |
| CVE-2026-23481 | 6.5 | medium | blinko / blinko | Blinko is an AI-powered card note-taking project. | 166d ago |
| CVE-2026-30886 | 6.5 | medium | newapi / new api | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. | 166d ago |