| CVE-2026-44250 | 7.5 | 38.1 | netty | netty | CWE-400 | Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays |
| CVE-2026-44890 | 7.5 | 38.1 | netty | netty | CWE-400 | Netty has Unbounded Direct Memory Consumption in its RedisDecoder |
| CVE-2026-11561 | 9.8 | 37.3 | Soagen Informatics Technologies Software and Consulting Inc. | Apinizer | CWE-917 | SSTI in Soagen Informatics' Apinizer |
| CVE-2026-3329 | 8.7 | 37.3 | Sonatype | Nexus Repository Manager | CWE-307 | Nexus Repository Manager - Improper Restriction of Excessive Authentication A… |
| CVE-2026-41699 | 9.8 | 35.8 | Spring | Spring for GraphQL | CWE-502 | Unsafe Deserialization in Spring GraphQL |
| CVE-2026-53806 | 7.7 | 34.9 | OpenClaw | OpenClaw | CWE-367 | OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation |
| CVE-2026-53810 | 7.7 | 35.0 | OpenClaw | OpenClaw | CWE-829 | OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Run… |
| CVE-2026-39494 | 9.3 | 32.1 | WBW Plugins | Product Filter by WBW | CWE-89 | WordPress Product Filter by WBW plugin <= 3.1.2 - SQL Injection vulnerability |
| CVE-2026-40999 | 8.6 | 31.4 | Spring | Spring Web Services | CWE-918 | Spring WS SSRF via unvalidated WS-Addressing reply destinations |
| CVE-2026-53777 | 8.6 | 31.0 | PerryTS | perry | CWE-22 | Perry < 0.5.1159 Path Traversal via ArtifactReady WebSocket |
| CVE-2026-46519 | 8.8 | 30.7 | Flux159 | mcp-server-kubernetes | CWE-863 | mcp-server-kubernetes Affected By Tool Access Control Bypass: Presentation-La… |
| CVE-2026-7250 | 7.5 | 30.1 | GitLab | GitLab | CWE-770 | Allocation of Resources Without Limits or Throttling in GitLab |
| CVE-2026-40997 | 5.3 | 29.6 | Spring | Spring Web Services | CWE-209 | SOAP security faults leak Spring Security account state |
| CVE-2026-45060 | 9.8 | 29.5 | MacWarrior | clipbucket-v5 | CWE-89 | ClipBucket: Blind SQL Injection in progress_video.php |
| CVE-2026-45178 | 8.4 | 29.3 | CyberArk Software, a Palo Alto Networks Company | Conjur Enterprise | CWE-284 | Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluste… |
| CVE-2026-7852 | 9.8 | 28.9 | Limatek System Inc. | LimRAD NAC | CWE-434 | Unrestricted File Upload in Limatek's LimRAD NAC |
| CVE-2026-44705 | 7.7 | 28.5 | raszi | node-tmp | CWE-22 | tmp: Path Traversal via unsanitized prefix/postfix enables directory escape |
| CVE-2026-40998 | 8.2 | 28.3 | Spring | Spring Web Services | CWE-611 | Jaxp13 XPath XXE via StreamSource and SAXSource |
| CVE-2026-41856 | 7.5 | 28.2 | Spring | Spring for GraphQL | CWE-284 | Spring GraphQL Annotation Detection Vulnerability |
| CVE-2026-7870 | 8.8 | 27.3 | IBM | i | CWE-427 | IBM i is Affected by Privilege Escalation [] |
| CVE-2026-53816 | 8.6 | 27.3 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node |
| CVE-2026-11839 | 9.9 | 26.4 | Başarsoft Information Technologies Inc. | Rotaban | CWE-434 | Arbitrary File Upload in Basarsoft's Rotaban |
| CVE-2026-38581 | 9.8 | 25.8 | n/a | n/a | CWE-89 | SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0… |
| CVE-2026-53781 | 5.3 | 25.7 | steipete | summarize | CWE-770 | Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download |
| CVE-2026-47172 | 9.5 | 25.2 | duck-organization | quest-bot | CWE-829 | Quest Bot: Untrusted pull request code can be built and deployed by privilege… |
| CVE-2026-47171 | 8.8 | 25.2 | duck-organization | quest-bot | CWE-116 | Quest Bot: Reminder messages allow stored mass mentions through `@everyone` a… |
| CVE-2026-1500 | 6.5 | 24.9 | GitLab | GitLab | CWE-770 | Allocation of Resources Without Limits or Throttling in GitLab |
| CVE-2026-47174 | 9.5 | 23.9 | duck-organization | duck-site | CWE-829 | Duck Site: Untrusted pull request code can trigger privileged production depl… |
| CVE-2026-53901 | 8.7 | 23.8 | cerebrate | cerebrate | CWE-20 | Cerebrate before v1.37 allows mass assignment of record identifiers during ob… |
| CVE-2026-53807 | 7.7 | 23.9 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks … |
| CVE-2026-46489 | 8.1 | 23.7 | SolidInvoice | SolidInvoice | CWE-79 | SolidInvoice: Unrestricted file upload with no MIME validation allows stored … |
| CVE-2026-53817 | 8.7 | 23.6 | OpenClaw | OpenClaw | CWE-290 | OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing |
| CVE-2026-53811 | 7.7 | 23.6 | OpenClaw | OpenClaw | CWE-290 | OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matri… |
| CVE-2026-45418 | 8.8 | 23.3 | MacWarrior | clipbucket-v5 | CWE-89 | ClipBucket: Blind SQL Injection in subtitle_edit.php |
| CVE-2026-47189 | 8.3 | 23.3 | duck-organization | quest-bot | CWE-639 | Quest Bot: AutoMod removal can delete rules from another guild by global rule ID |
| CVE-2026-52859 | 6.9 | 22.9 | vim | vim | CWE-125 | Vim: Out-of-bounds Read in Terminal Screen Snapshot |
| CVE-2026-11986 | 4.9 | 22.6 | Red Hat | Red Hat build of Keycloak 26.6 | CWE-425 | Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-u… |
| CVE-2026-53819 | 8.7 | 22.3 | OpenClaw | OpenClaw | CWE-426 | OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace … |
| CVE-2026-12007 | 8.8 | 21.2 | Google | Chrome | CWE-416 | Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 al… |
| CVE-2026-44490 | 8.2 | 21.2 | axios | axios | CWE-1321 | Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in ax… |
| CVE-2026-53814 | 8.7 | 20.6 | OpenClaw | OpenClaw | CWE-266 | OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool A… |
| CVE-2026-12010 | 8.3 | 19.5 | Google | Chrome | CWE-122 | Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.1… |
| CVE-2023-33999 | 7.1 | 19.6 | WPVibes | WP Mail Log | CWE-79 | WordPress WP Mail Log plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) … |
| CVE-2025-46315 | 7.5 | 19.2 | Apple | macOS | CWE-284 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-47250 | 6.1 | 18.9 | Flux159 | mcp-server-kubernetes | CWE-88 | mcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bear… |
| CVE-2026-53782 | 6.3 | 18.4 | steipete | summarize | CWE-918 | Summarize < 0.17.0 SSRF via podcast:transcript URL fetch |
| CVE-2026-47173 | 6.3 | 18.2 | duck-organization | quest-bot | CWE-116 | Quest Bot: Ticket reason allows mass-mention injection |
| CVE-2026-11850 | 5.0 | 18.0 | Red Hat | Red Hat Hardened Images | CWE-191 | Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds… |
| CVE-2026-53661 | 8.8 | 17.7 | malach-it | boruta-server | CWE-614 | boruta-server sent sensitive session cookies without the Secure attribute |
| CVE-2026-45802 | 6.0 | 17.8 | Setasign | FPDI | CWE-400 | FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service |
| CVE-2026-8589 | 8.7 | 17.3 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-12019 | 8.3 | 17.0 | Google | Chrome | CWE-787 | Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior t… |
| CVE-2026-49949 | 6.0 | 17.0 | steipete | CodexBar | CWE-522 | CodexBar < 0.33.0 Credential Leakage via HTTP Redirect |
| CVE-2026-6338 | 4.9 | 16.9 | Kong | Kong Enterprise Gateway | CWE-444 | HTTP request smuggling in Kong Enteprise Gateway |
| CVE-2026-47181 | 8.7 | 16.7 | PenguinMod | PenguinMod-BackendApi | CWE-20 | PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Acco… |
| CVE-2026-47176 | 5.7 | 16.8 | duck-organization | quest-bot | CWE-200 | Quest Bot: Logging module can disclose private-channel message contents to a … |
| CVE-2026-47177 | 5.7 | 16.8 | duck-organization | quest-bot | CWE-200 | Quest Bot: Ticket transcripts can disclose private ticket contents to a lower… |
| CVE-2026-47162 | 7.3 | 16.7 | vim | vim | CWE-74 | Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted direct… |
| CVE-2026-10087 | 8.7 | 16.5 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-7787 | 8.1 | 16.4 | IBM | Langflow OSS | CWE-639 | Unauthenticated Session History Access via Public Flow Execution |
| CVE-2026-11945 | 7.5 | 16.2 | DALIBO | PostgreSQL Anonymizer | CWE-89 | PostgreSQL Anonymizer: SQL injection in the rules import functions |
| CVE-2026-9204 | 6.5 | 16.2 | GitLab | GitLab | CWE-918 | Server-Side Request Forgery (SSRF) in GitLab |
| CVE-2026-53812 | 4.9 | 16.2 | OpenClaw | OpenClaw | CWE-918 | OpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act Inte… |
| CVE-2026-12008 | 8.3 | 16.1 | Google | Chrome | CWE-416 | Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115… |
| CVE-2026-12009 | 8.3 | 16.1 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Accessibility in Google Chrome … |
| CVE-2026-12011 | 8.3 | 16.1 | Google | Chrome | CWE-416 | Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115… |
| CVE-2026-53912 | 5.1 | 15.6 | cerebrate | cerebrate | CWE-200 | Cerebrate self-registration password hash exposure via inbox and audit log views |
| CVE-2026-47169 | 7.5 | 15.1 | duck-organization | quest-bot | CWE-266 | Quest Bot: Manage Server users can configure AutoRole to grant Administrator … |
| CVE-2026-8406 | 7.1 | 15.1 | OS4ED | openSIS-Classic | CWE-639 | openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail |
| CVE-2026-12026 | 6.5 | 14.9 | Google | Chrome | CWE-125 | Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.… |
| CVE-2026-3553 | 3.1 | 14.8 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-47175 | 2.3 | 14.6 | duck-organization | quest-bot | CWE-116 | Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` p… |
| CVE-2026-47188 | 2.3 | 14.6 | duck-organization | quest-bot | CWE-116 | Quest Bot: Unban and unwarn reason fields still allow bot-powered mass mentions. |
| CVE-2026-46697 | 7.5 | 14.6 | stefanbohacek | fediverse-embeds-wordpress-plugin | CWE-918 | Fediverse Embeds: Unauthenticated SSRF / open proxy via REST media-proxy endp… |
| CVE-2022-45813 | 5.4 | 14.0 | BeRocket | Advanced AJAX Product Filters | CWE-862 | WordPress Advanced AJAX Product Filters plugin <= 1.6.3.3 - Broken Access Con… |
| CVE-2025-46308 | 5.3 | 14.1 | Apple | iOS and iPadOS | CWE-284 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-12016 | 8.3 | 13.9 | Google | Chrome | CWE-20 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827… |
| CVE-2026-12023 | 8.3 | 13.9 | Google | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed… |
| CVE-2026-12028 | 8.3 | 13.9 | Google | Chrome | CWE-416 | Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 all… |
| CVE-2026-40994 | 8.2 | 14.0 | Spring | Spring Web Services | CWE-1188 | Wss4jSecurityInterceptor disables WS-I BSP validation by default |
| CVE-2026-46698 | 5.3 | 13.9 | stefanbohacek | fediverse-embeds-wordpress-plugin | CWE-918 | Fediverse Embeds: Public-nonce SSRF via ftf_get_site_info AJAX action |
| CVE-2026-53702 | 6.5 | 13.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Gstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffer… |
| CVE-2026-44489 | 5.3 | 13.8 | axios | axios | CWE-113 | Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incompl… |
| CVE-2026-12015 | 5.3 | 13.6 | Google | Chrome | CWE-416 | Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a… |
| CVE-2026-12025 | 5.3 | 13.6 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … |
| CVE-2026-12012 | 8.1 | 13.4 | Google | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an… |
| CVE-2026-40985 | 6.4 | 13.4 | Spring | Spring Web Flow | CWE-917 | Data Binding Vulnerability in Spring Web Flow with Unified EL Parser |
| CVE-2026-12027 | 9.6 | 13.3 | Google | Chrome | CWE-250 | Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827… |
| CVE-2026-12020 | 8.8 | 13.3 | Google | Chrome | CWE-416 | Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 al… |
| CVE-2026-52860 | 7.5 | 13.2 | vim | vim | CWE-94 | Vim: Arbitrary Code Execution via Python Omni-Completion |
| CVE-2026-9648 | 9.1 | 13.1 | Haskell Programming Language | crypton-certificate | — | CVE-2026-9648 |
| CVE-2026-41000 | 3.7 | 13.1 | Spring | Spring Web Services | CWE-294 | WSS4J validation does not use configured replay cache |
| CVE-2026-10733 | 4.3 | 12.8 | GitLab | GitLab | CWE-1021 | Improper Restriction of Rendered UI Layers or Frames in GitLab |
| CVE-2026-53723 | 5.8 | 12.7 | guzzle | guzzle-services | CWE-20 | guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injec… |
| CVE-2026-47163 | 7.2 | 12.2 | duck-organization | quest-bot | CWE-862 | Quest Bot: Unprivileged users can create and remove AutoMod rules. |
| CVE-2026-53815 | 7.1 | 12.1 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions |
| CVE-2026-9694 | 4.3 | 11.6 | GitLab | GitLab | CWE-153 | Improper Neutralization of Substitution Characters in GitLab |
| CVE-2026-40987 | 7.1 | 11.5 | Spring | Spring Integration | CWE-22 | Remote-file synchronizer in Spring Integration writes server-supplied filenam… |
| CVE-2026-47170 | 7.7 | 11.3 | garlic-signage | garlic-hub | CWE-918 | Garlic-Hub: SSRF vulnerability in uploadFromUrl endpoint |
| CVE-2026-12017 | 3.1 | 11.3 | Google | Chrome | CWE-20 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… |
| CVE-2026-4764 | 9.4 | 11.1 | Google Cloud | Dialogflow CX | CWE-862 | Privilege Escalation in Dialogflow CX via Playbook Import |
| CVE-2026-53911 | 6.3 | 11.1 | cerebrate | cerebrate | CWE-639 | Cerebrate primary key mass assignment in CRUD edit operations allows authenti… |
| CVE-2026-53701 | 6.5 | 11.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps … |
| CVE-2026-8464 | 8.3 | 10.7 | Neuron Soft | Golem OEE MES | CWE-22 | Path traversal in Neuron Soft Golem OEE MES |
| CVE-2026-52858 | 7.3 | 10.3 | vim | vim | CWE-94 | Vim: Arbitrary Code Execution via Python Omni-Completion |
| CVE-2026-40986 | 4.8 | 10.4 | Spring | Spring Web Flow | CWE-79 | Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML |
| CVE-2026-47238 | 6.5 | 10.2 | MacWarrior | clipbucket-v5 | CWE-639 | ClipBucket: IDOR in videos subtitle editor |
| CVE-2026-48998 | 5.3 | 9.9 | guzzle | psr7 | CWE-918 | guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation |
| CVE-2026-50005 | 8.3 | 9.8 | Brickcom | Cube | CWE-1392 | Brickcom Cameras Use of Default Credentials |
| CVE-2026-46622 | 8.1 | 9.7 | SolidInvoice | SolidInvoice | CWE-312 | SolidInvoice: API tokens stored as plaintext in the database allowing full cr… |
| CVE-2026-47157 | 6.5 | 9.5 | subzeroid | aiograpi | CWE-918 | aiograpi: Unsafe signup challenge path handling |
| CVE-2026-53808 | 6.0 | 9.5 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.5.6 - Approval Policy Bypass in Skill Workshop Apply Flow |
| CVE-2026-12029 | 8.3 | 9.1 | Google | Chrome | CWE-416 | Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 a… |
| CVE-2026-12030 | 8.3 | 9.1 | Google | Chrome | CWE-122 | Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.11… |
| CVE-2026-12031 | 8.3 | 9.1 | Google | Chrome | CWE-693 | Inappropriate implementation in Views in Google Chrome on Windows prior to 14… |
| CVE-2026-11956 | 6.3 | 9.1 | TwiN | gatus | CWE-614 | TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute |
| CVE-2026-49214 | 5.3 | 8.9 | guzzle | psr7 | CWE-20 | guzzlehttp/psr7 has CRLF Injection via URI Host Component |
| CVE-2026-41700 | 8.1 | 8.8 | Spring | Spring for GraphQL | CWE-346 | Cross-Site WebSocket Hijacking in Spring for GraphQL |
| CVE-2026-12033 | 5.3 | 8.8 | Google | Chrome | CWE-125 | Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 a… |
| CVE-2023-40200 | 5.3 | 8.8 | Essential Plugin | WP Logo Showcase Responsive Slider and Carousel | CWE-639 | WordPress WP Logo Showcase Responsive Slider and Carousel plugin <= 3.6 - Bro… |
| CVE-2026-2827 | 4.7 | 8.8 | 100plugins | Open User Map PRO | CWE-79 | Open User Map PRO <= 1.4.31 - Unauthenticated Stored Cross-Site Scripting via… |
| CVE-2026-12035 | 8.8 | 8.6 | Google | Chrome | CWE-416 | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 a… |
| CVE-2026-6269 | 5.4 | 8.6 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2023-32959 | 4.3 | 8.3 | Sparkle WP | MetroStore | CWE-862 | WordPress MetroStore theme <= 1.3.2 - Broken Access Control |
| CVE-2026-6277 | 4.3 | 8.0 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-12034 | 8.3 | 7.9 | Google | Chrome | CWE-20 | Insufficient validation of untrusted input in Linux Toolkit Theming in Google… |
| CVE-2022-42479 | 5.4 | 7.5 | TemplateHouse | Soledad | CWE-862 | WordPress Soledad premium theme <= 8.2.5 - Broken Access Control vulnerability |
| CVE-2023-25969 | 5.4 | 7.4 | ThemeHunk | Contact Form & Lead Form Elementor Builder | CWE-862 | WordPress Contact Form & Lead Form Elementor Builder plugin <= 1.8.4 - Broken… |
| CVE-2026-12014 | 8.3 | 7.2 | Google | Chrome | CWE-416 | Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an at… |
| CVE-2026-49482 | 4.3 | 6.7 | MacWarrior | clipbucket-v5 | CWE-155 | ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subt… |
| CVE-2026-12022 | 8.3 | 6.3 | Google | Chrome | CWE-362 | Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed… |
| CVE-2026-45173 | 8.4 | 5.8 | CyberArk Software, a Palo Alto Networks Company | Identity Browser Extensions | CWE-346 | Idira Identity Browser Extension: Unauthorized Application Interaction via Or… |
| CVE-2026-12018 | 8.8 | 5.7 | Google | Chrome | CWE-269 | Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149… |
| CVE-2026-12024 | 6.5 | 5.4 | Google | Chrome | CWE-346 | Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7… |
| CVE-2026-6976 | 3.7 | 5.5 | GitLab | GitLab | CWE-639 | Authorization Bypass Through User-Controlled Key in GitLab |
| CVE-2026-50245 | 8.3 | 5.3 | Brickcom | Cube | CWE-306 | Brickcom Cameras Missing Authentication for Critical Function |
| CVE-2026-12032 | 3.1 | 5.2 | Google | Chrome | CWE-346 | Inappropriate implementation in Passwords in Google Chrome on Android prior t… |
| CVE-2025-43278 | 5.5 | 4.8 | Apple | macOS | CWE-61 | This issue was addressed with improved handling of symlinks. This issue is fi… |
| CVE-2026-4096 | 6.1 | 4.6 | IBM | DevOps Plan | CWE-644 | A vulnerability has been identified in IBM DevOps Plan that allows a Host Hea… |
| CVE-2026-40995 | 5.4 | 4.5 | Spring | Spring Web Services | CWE-287 | X.509 authentication bypasses Spring Security account checks |
| CVE-2022-44630 | 4.6 | 4.2 | YITH | YITH WooCommerce Product Slider Carousel | CWE-352 | WordPress YITH WooCommerce Product Slider Carousel plugin <= 1.16.0 - Cross-S… |
| CVE-2026-42653 | 7.1 | 4.0 | iova.mihai | SliceWP | CWE-79 | WordPress SliceWP plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2025-24268 | 5.5 | 3.9 | Apple | macOS | CWE-22 | A parsing issue in the handling of directory paths was addressed with improve… |
| CVE-2025-46293 | 5.5 | 3.9 | Apple | macOS | CWE-59 | This issue was addressed with improved handling of symlinks. This issue is fi… |
| CVE-2026-3341 | 5.4 | 3.6 | IBM | Langflow Desktop | CWE-918 | IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection All… |
| CVE-2026-47167 | 5.1 | 3.4 | vim | vim | CWE-94 | Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-de… |
| CVE-2026-41005 | 9.0 | 3.1 | Cloud Foundry | UAA | CWE-347 | UAA accepts SAML Encrypted Assertions authentication bypass |
| CVE-2025-46313 | 5.5 | 3.1 | Apple | macOS | CWE-532 | A logging issue was addressed with improved data redaction. This issue is fix… |
| CVE-2026-40996 | 4.8 | 2.9 | Spring | Spring Web Services | CWE-327 | Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default |
| CVE-2026-45175 | 8.5 | 2.9 | CyberArk Software, a Palo Alto Networks Company | Idira Endpoint Privilege Manager | CWE-295 | Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Va… |
| CVE-2025-24284 | 8.8 | 2.8 | Apple | macOS | CWE-693 | This issue was addressed with improved checks to prevent unauthorized actions… |
| CVE-2025-30431 | 5.5 | 2.7 | Apple | macOS | CWE-693 | The issue was addressed with improved checks. This issue is fixed in macOS Se… |
| CVE-2026-45174 | 8.5 | 2.7 | CyberArk Software, a Palo Alto Networks Company | Idira Endpoint Privilege Manager | CWE-404 | Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemo… |
| CVE-2026-53423 | 5.9 | 2.7 | membraneframework | membrane_mp4_plugin | CWE-770 | Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_… |
| CVE-2026-45176 | 8.9 | 2.6 | CyberArk Software, a Palo Alto Networks Company | Idira Endpoint Privilege Manager | CWE-269 | Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Intern… |
| CVE-2026-10847 | 7.8 | 2.5 | checkpoint | Identity Agent | CWE-427 | Local Privilege Escalation vulnerability in Check Point Identity Agent Full f… |
| CVE-2026-40992 | 5.0 | 2.5 | Spring | Spring Boot | CWE-295 | Mail Auto-Configuration Does Not Enable SSL Hostname Verification |
| CVE-2025-30459 | 5.5 | 2.4 | Apple | macOS | CWE-359 | A privacy issue was addressed by removing the vulnerable code. This issue is … |
| CVE-2025-24165 | 5.5 | 2.3 | Apple | macOS | CWE-284 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2025-7064 | 5.6 | 1.9 | ABB | Freelance | CWE-305 | Freelance Security Lock – Access to Windows OS |
| CVE-2025-31272 | 7.8 | 1.8 | Apple | macOS | CWE-269 | The issue was addressed with improved checks. This issue is fixed in macOS Se… |
| CVE-2026-53813 | 7.3 | 1.8 | OpenClaw | OpenClaw | CWE-427 | OpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root Resol… |
| CVE-2022-47150 | 4.3 | 1.7 | weDevs | WooCommerce Conversion Tracking | CWE-352 | WordPress WooCommerce Conversion Tracking plugin <= 2.0.10 - Cross-Site Reque… |
| CVE-2025-43339 | 5.5 | 1.6 | Apple | macOS | CWE-284 | An access issue was addressed with additional sandbox restrictions. This issu… |
| CVE-2024-32110 | 4.3 | 1.0 | Magepeople inc. | WpEvently | CWE-352 | WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= … |
| CVE-2026-53818 | 6.9 | 0.8 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback |
| CVE-2026-41001 | 5.3 | 0.7 | Spring | Spring Boot | CWE-377 | Predictable Temp Directory in Artemis Auto-configuration |
| CVE-2024-45636 | 4.4 | 0.7 | IBM | Security QRadar EDR | CWE-522 | IBM Security QRadar EDR Software has a vulnerability where user credentials m… |
| CVE-2026-53809 | 4.8 | 0.6 | OpenClaw | OpenClaw | CWE-863 | OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy |