| CVE-2026-43720 | 6.5 | 43.8 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-55607 | 7.7 | 43.5 | anthropics | claude-code | CWE-22 | Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxe… |
| CVE-2026-55276 | 9.1 | 43.1 | Apache Software Foundation | Apache Tomcat | CWE-670 | Apache Tomcat: Logged effective web.xml is incomplete |
| CVE-2026-34597 | 8.8 | 42.1 | coollabsio | coolify | CWE-78 | Coolify: Authenticated Host RCE |
| CVE-2026-53434 | 9.1 | 42.1 | Apache Software Foundation | Apache Tomcat | CWE-390 | Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Conn… |
| CVE-2026-43701 | 7.1 | 40.6 | Apple | Safari | CWE-284 | The issue was addressed with improved checks. This issue is fixed in Safari 2… |
| CVE-2026-43713 | 6.5 | 39.4 | Apple | Safari | CWE-284 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-51219 | 7.5 | 39.1 | n/a | n/a | CWE-122 | A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages f… |
| CVE-2026-13763 | 7.9 | 38.9 | AWS | AWS Application Load Balancer | CWE-444 | HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load… |
| CVE-2026-37637 | 9.1 | 38.7 | n/a | n/a | CWE-94 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute ar… |
| CVE-2026-55955 | 6.5 | 38.5 | Apache Software Foundation | Apache Tomcat | CWE-287 | Apache Tomcat: EncryptInterceptor not protected against replay attacks |
| CVE-2026-13517 | 7.4 | 38.4 | Tenda | JD12L | CWE-119 | Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow |
| CVE-2026-13518 | 7.4 | 38.4 | Tenda | JD12L | CWE-119 | Tenda JD12L addressNat fromAddressNat stack-based overflow |
| CVE-2026-13519 | 7.4 | 38.4 | Tenda | JD12L | CWE-119 | Tenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflow |
| CVE-2026-13539 | 7.4 | 38.4 | Wavlink | WL-NU516U1-A | CWE-119 | Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflow |
| CVE-2026-56018 | 7.5 | 38.0 | GTERMARS | JavaScript::Minifier::XS | CWE-400 | JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every c… |
| CVE-2026-43705 | 8.8 | 37.9 | Apple | Safari | CWE-843 | A type confusion issue was addressed with improved checks. This issue is fixe… |
| CVE-2026-13582 | 7.4 | 37.7 | Edimax | EW-7478APC | CWE-119 | Edimax EW-7478APC POST Request formUSBAccount buffer overflow |
| CVE-2026-13528 | 5.5 | 37.2 | YunaiV | ruoyi-vue-pro | CWE-22 | YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint Fil… |
| CVE-2026-13562 | 7.4 | 37.0 | Edimax | EW-7478APC | CWE-119 | Edimax EW-7478APC POST Request formiNICSiteSurvey buffer overflow |
| CVE-2026-13563 | 7.4 | 37.0 | Edimax | EW-7478APC | CWE-119 | Edimax EW-7478APC POST Request formL2TPSetup stack-based overflow |
| CVE-2026-13564 | 7.4 | 37.0 | Edimax | EW-7478APC | CWE-119 | Edimax EW-7478APC POST Request formPPPoESetup stack-based overflow |
| CVE-2026-13580 | 7.4 | 37.0 | Edimax | EW-7478APC | CWE-119 | Edimax EW-7478APC POST Request formQoS buffer overflow |
| CVE-2026-13583 | 7.4 | 37.0 | Edimax | EW-7478APC | CWE-119 | Edimax EW-7478APC POST Request formUSBFolder buffer overflow |
| CVE-2026-13762 | 7.9 | 36.5 | AWS | Amazon CloudFront | CWE-444 | HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront wi… |
| CVE-2026-43718 | 6.5 | 36.4 | Apple | Safari | CWE-121 | A stack overflow was addressed with improved input validation. This issue is … |
| CVE-2026-43721 | 6.5 | 36.4 | Apple | Safari | CWE-732 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-43732 | 6.5 | 36.4 | Apple | Safari | CWE-22 | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-25707 | 8.8 | 35.1 | SUSE | libzypp | CWE-23 | Handcrafted repo metadata may cause arbitrary local files to be overwritten b… |
| CVE-2026-13587 | 2.9 | 35.0 | seladb | PcapPlusPlus | CWE-119 | seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based… |
| CVE-2026-13165 | 8.6 | 34.9 | Krajowa Izba Rozliczeniowa | SzafirHost | CWE-434 | Remote Code Execution in SzafirHost |
| CVE-2026-41052 | 9.4 | 34.5 | SUSE | Rancher | CWE-305 | Rancher Privilege Escalation from Project Owner to Host |
| CVE-2026-51218 | 7.5 | 34.1 | n/a | n/a | CWE-122 | A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/co… |
| CVE-2026-53427 | 2.3 | 33.7 | leandrocp | mdex | CWE-79 | Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence a… |
| CVE-2026-43703 | 6.5 | 33.7 | Apple | iOS and iPadOS | CWE-125 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43676 | 6.5 | 32.7 | Apple | Safari | CWE-125 | An out-of-bounds access issue was addressed with improved bounds checking. Th… |
| CVE-2026-13589 | 2.9 | 32.6 | seladb | PcapPlusPlus | CWE-119 | seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubComman… |
| CVE-2026-13590 | 2.9 | 32.6 | seladb | PcapPlusPlus | CWE-119 | seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow |
| CVE-2026-43742 | 6.5 | 32.5 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-56017 | 7.5 | 32.2 | GTERMARS | JavaScript::Minifier::XS | CWE-125 | JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL poin… |
| CVE-2026-13676 | 7.5 | 31.6 | fast-uri | fast-uri | CWE-436 | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| CVE-2026-13546 | 5.5 | 31.5 | Feehi | CMS | CWE-287 | Feehi CMS REST API Endpoint articles missing authentication |
| CVE-2026-13571 | 5.5 | 31.5 | SourceCodester | Simple Food Ordering System | CWE-840 | SourceCodester Simple Food Ordering System cart.php logic error |
| CVE-2026-43704 | 5.3 | 31.3 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-11720 | 9.3 | 31.3 | Google | MCP Toolbox for Databases (googleapis/mcp-toolbox) | CWE-22 | Path Traversal in googleapis/mcp-toolbox HTTP Tool URL Builder |
| CVE-2026-13588 | 2.9 | 31.1 | seladb | PcapPlusPlus | CWE-119 | seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based… |
| CVE-2026-13749 | 8.8 | 30.9 | Snowflake | Snowflake CLI | CWE-94 | Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Temp… |
| CVE-2026-13592 | 5.5 | 30.3 | liftoff-sr | CIPster | CWE-119 | liftoff-sr CIPster EtherNet IP Message append out-of-bounds write |
| CVE-2026-43708 | 4.3 | 30.2 | Apple | Safari | CWE-20 | The issue was addressed with improved input validation. This issue is fixed i… |
| CVE-2026-43706 | 6.5 | 29.9 | Apple | iOS and iPadOS | CWE-415 | A double free issue was addressed with improved memory management. This issue… |
| CVE-2026-56124 | 8.7 | 29.6 | shimosyan | phpUploader | CWE-359 | phpUploader < 2.0.2 Unauthenticated Database Exposure via index model |
| CVE-2026-13543 | 2.9 | 29.5 | n/a | Documenso | CWE-287 | Documenso Google OAuth Login handle-oauth-callback-url.ts improper authentica… |
| CVE-2026-43740 | 6.5 | 29.3 | Apple | Safari | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-56285 | 7.7 | 29.1 | zedeus | nitter | CWE-918 | Nitter - Server-Side Request Forgery in /video Media Proxy Endpoint |
| CVE-2026-43712 | 6.5 | 29.1 | Apple | Safari | CWE-125 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-51221 | 7.5 | 28.1 | n/a | n/a | CWE-284 | A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer … |
| CVE-2026-43727 | 6.5 | 28.0 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-57960 | 8.3 | 26.9 | HiEventsDev | Hi.Events | CWE-359 | Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List sho… |
| CVE-2026-41992 | 6.9 | 26.4 | GNU | gzip | CWE-126 | Global Buffer Overflow in GNU gzip |
| CVE-2026-57331 | 9.9 | 26.4 | videowhisper | Paid Videochat Turnkey Site | CWE-22 | WordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deleti… |
| CVE-2026-13744 | 8.8 | 24.7 | Snowflake | Snowflake CLI | CWE-89 | Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlle… |
| CVE-2026-43746 | 6.5 | 24.3 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-7656 | 6.8 | 23.9 | zephyrproject | zephyr | CWE-290 | Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA accep… |
| CVE-2026-54889 | 5.1 | 23.6 | leandrocp | mdex | CWE-79 | Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injectio… |
| CVE-2026-12616 | 6.9 | 23.4 | Eclipse Foundation | Eclipse CSI - PIA | CWE-117 | The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplie… |
| CVE-2026-43724 | 7.8 | 23.3 | Apple | iOS and iPadOS | CWE-20 | The issue was addressed with improved input sanitization. This issue is fixed… |
| CVE-2026-43735 | 8.1 | 22.8 | Apple | Safari | CWE-352 | The issue was addressed with improved checks. This issue is fixed in Safari 2… |
| CVE-2026-28979 | 6.5 | 22.5 | Apple | Safari | CWE-125 | An out-of-bounds access issue was addressed with improved bounds checking. Th… |
| CVE-2026-13758 | 3.7 | 22.0 | MIK | CryptX | CWE-208 | CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in… |
| CVE-2026-57950 | 8.6 | 22.0 | Yunai | ruoyi-vue-pro | CWE-863 | ruoyi-vue-pro - Incorrect Permission Namespace in ErpSaleOrderController |
| CVE-2026-13522 | 2.1 | 21.9 | Investintech | SlimPDFReader | CWE-119 | Investintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-o… |
| CVE-2026-13549 | 2.1 | 21.8 | CodeAstro | Complaint Management System | CWE-285 | CodeAstro Complaint Management System Report Endpoint Report.php deletereport… |
| CVE-2026-12856 | 8.8 | 21.7 | Red Hat | Red Hat OpenShift Dev Spaces 3.29 | CWE-88 | Vscode-java: vscode: command injection vulnerability in the javadoc hover pro… |
| CVE-2026-43699 | 6.5 | 21.6 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-43734 | 6.5 | 21.6 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-13553 | 5.5 | 21.3 | itsourcecode | Online Hotel Management System | CWE-284 | itsourcecode Online Hotel Management System controller.php add unrestricted u… |
| CVE-2026-13533 | 5.5 | 21.1 | agentejo | Cockpit CMS | CWE-425 | agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access |
| CVE-2026-43709 | 6.5 | 21.0 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-13536 | 2.1 | 20.9 | n/a | GotoHTTP | CWE-79 | GotoHTTP reg.12x cross site scripting |
| CVE-2026-56783 | 7.1 | 20.4 | parseablehq | parseable | CWE-522 | Parseable < 2.9.2 - Cleartext Credential Exposure in Notification Target API |
| CVE-2026-13547 | 5.5 | 20.3 | Hanwang | e-Face General Management Platform | CWE-284 | Hanwang e-Face General Management Platform upload.do unrestricted upload |
| CVE-2026-13568 | 5.5 | 20.3 | SourceCodester | Inventory Management System | CWE-266 | SourceCodester Inventory Management System User Registration Endpoint users_h… |
| CVE-2026-40523 | 7.2 | 20.1 | FrontAccounting | FrontAccounting | CWE-89 | FrontAccounting < 2.4.20 SQL Injection via reporting/rep710.php |
| CVE-2026-40524 | 7.2 | 20.1 | FrontAccounting | FrontAccounting | CWE-89 | FrontAccounting < 2.4.20 SQL Injection via get_gl_transactions() |
| CVE-2026-13554 | 2.1 | 19.7 | itsourcecode | Online Hotel Management System | CWE-79 | itsourcecode Online Hotel Management System POST Request controller.php add c… |
| CVE-2026-13556 | 2.1 | 19.7 | itsourcecode | Online Hotel Management System | CWE-79 | itsourcecode Online Hotel Management System POST Request controller.php edit … |
| CVE-2026-13557 | 2.1 | 19.7 | itsourcecode | Online Hotel Management System | CWE-79 | itsourcecode Online Hotel Management System POST Request controller.php add c… |
| CVE-2026-13567 | 2.1 | 19.7 | code-projects | Online Music Site | CWE-79 | code-projects Online Music Site POST Request Feedback.php cross site scripting |
| CVE-2026-57946 | 6.3 | 19.6 | iv-org | Invidious | CWE-862 | Invidious - Private Playlist Disclosure via Unauthenticated RSS Feed Endpoint |
| CVE-2026-13521 | 5.5 | 19.1 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System preview5.php sql injection |
| CVE-2026-56780 | 7.7 | 18.5 | modoboa | modoboa | CWE-639 | Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change… |
| CVE-2026-13524 | 2.9 | 18.3 | CherryHQ | cherry-studio | CWE-266 | CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper a… |
| CVE-2026-13526 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_class.php sql injection |
| CVE-2026-13527 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System preview4.php sql injection |
| CVE-2026-13550 | 5.5 | 18.2 | itsourcecode | Baptism Information Management System | CWE-74 | itsourcecode Baptism Information Management System delbaptism.php sql injection |
| CVE-2026-13551 | 5.5 | 18.2 | itsourcecode | Baptism Information Management System | CWE-74 | itsourcecode Baptism Information Management System editBaptism.php sql injection |
| CVE-2026-13552 | 5.5 | 18.2 | itsourcecode | Online Hotel Management System | CWE-74 | itsourcecode Online Hotel Management System controller.php edit sql injection |
| CVE-2026-13555 | 5.5 | 18.2 | itsourcecode | Online Hotel Management System | CWE-74 | itsourcecode Online Hotel Management System controller.php add sql injection |
| CVE-2026-13559 | 5.5 | 18.2 | code-projects | Real State Services | CWE-74 | code-projects Real State Services single-list_sale.php add sql injection |
| CVE-2026-13565 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_class1.php sql injection |
| CVE-2026-13566 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System preview3.php sql injection |
| CVE-2026-57953 | 5.3 | 18.3 | its-a-feature | Mythic | CWE-863 | Mythic < 3.4.0.60 - Unauthorized Automation Workflow Modification via eventin… |
| CVE-2026-43731 | 8.8 | 18.1 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-43722 | 5.5 | 18.0 | Apple | iOS and iPadOS | CWE-20 | The issue was addressed with improved input sanitization. This issue is fixed… |
| CVE-2026-12912 | 7.3 | 17.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed … |
| CVE-2026-57346 | 7.1 | 17.5 | Epiphyt | Embed Privacy | CWE-22 | WordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerability |
| CVE-2026-57332 | 7.1 | 17.4 | WP Swings | Wallet System for WooCommerce | CWE-862 | WordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Contr… |
| CVE-2026-13437 | 6.5 | 17.2 | Devolutions | PowerShell Universal | CWE-201 | Insertion of sensitive information into sent data in the AI Agent job API in … |
| CVE-2026-57498 | 9.6 | 17.0 | coollabsio | coolify | CWE-639 | Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and de… |
| CVE-2026-57341 | 6.5 | 16.7 | Colissimo | Colissimo Officiel : Méthodes de livraison pour WooCommerce | CWE-639 | WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin … |
| CVE-2026-39872 | 6.5 | 16.6 | Apple | Safari | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43663 | 6.5 | 16.6 | Apple | Safari | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-57957 | 2.3 | 16.6 | papermark | papermark | CWE-942 | Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint |
| CVE-2026-57327 | 6.3 | 16.5 | mainwp | MainWP | CWE-862 | WordPress MainWP plugin <= 6.1.1 - Broken Access Control vulnerability |
| CVE-2026-57951 | 7.1 | 16.2 | its-a-feature | Mythic | CWE-863 | Mythic < 3.4.0.60 - Broken Permission Filter in payload_build_step Table |
| CVE-2026-43700 | 6.5 | 15.9 | Apple | Safari | CWE-346 | A cross-origin issue was addressed with improved tracking of security origins… |
| CVE-2026-43726 | 6.5 | 15.7 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-57947 | 6.3 | 15.1 | pinpoint-apm | pinpoint | CWE-918 | Pinpoint - Server-Side Request Forgery via Alarm Webhook Registration |
| CVE-2026-13529 | 2.9 | 15.2 | n/a | YzmCMS | CWE-74 | YzmCMS index.php sql injection |
| CVE-2026-43717 | 6.5 | 15.0 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-57955 | 8.3 | 14.7 | SigNoz | signoz | CWE-89 | SigNoz 0.130.1 - SQL Injection in Alert History Endpoints via Rule ID Parameter |
| CVE-2026-41896 | 7.5 | 14.2 | coollabsio | coolify | CWE-287 | Coolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null… |
| CVE-2026-57949 | 7.1 | 14.1 | Yunai | ruoyi-vue-pro | CWE-862 | ruoyi-vue-pro - Missing Authorization in CRM Follow-up Record GET Endpoint |
| CVE-2026-56781 | 6.9 | 14.2 | teableio | teable | CWE-639 | Teable - Unauthenticated Hidden Field Disclosure via Projection Parameter Ove… |
| CVE-2026-13593 | 6.5 | 14.0 | GTERMARS | CSS::Minifier::XS | CWE-401 | CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the e… |
| CVE-2026-57335 | 6.5 | 14.0 | Ads WPQuads | Ads by WPQuads | CWE-862 | WordPress Ads by WPQuads plugin <= 3.0.3 - Broken Access Control vulnerability |
| CVE-2025-7386 | 6.8 | 13.6 | Hitachi | Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8 | CWE-522 | Information exposure vulnerability in Hitachi Storage Navigator |
| CVE-2026-13540 | 2.1 | 13.6 | n/a | GitBucket | CWE-918 | GitBucket RepositoryCreationService.scala Git.cloneRepository.setURI server-s… |
| CVE-2026-13544 | 2.1 | 12.1 | Feehi | CMS | CWE-266 | Feehi CMS API users access control |
| CVE-2026-57956 | 6.1 | 11.9 | SigNoz | signoz | CWE-639 | SigNoz < 0.133.0 - Cross-Organization Insecure Direct Object Reference in Ale… |
| CVE-2026-34592 | 7.7 | 11.8 | coollabsio | coolify | CWE-639 | Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH … |
| CVE-2026-57943 | 6.0 | 11.4 | LibrePhotos | librephotos | CWE-639 | LibrePhotos < 1.0.0 - Insecure Direct Object Reference in SetPhotosShared End… |
| CVE-2026-13569 | 2.0 | 11.5 | weng-xianhu | EyouCMS | CWE-74 | weng-xianhu EyouCMS API index.php sql injection |
| CVE-2026-10647 | 5.3 | 11.0 | zephyrproject | zephyr | CWE-667 | Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure |
| CVE-2026-57328 | 6.5 | 10.8 | Strategy11 Team | Business Directory | CWE-79 | WordPress Business Directory plugin <= 6.4.22 - Cross Site Scripting (XSS) vu… |
| CVE-2026-57329 | 6.5 | 10.8 | WOOCOMMERCE DESIGNER PRO | WooCommerce Designer Pro | CWE-79 | WordPress WooCommerce Designer Pro plugin <= 1.9.34 - Cross Site Scripting (X… |
| CVE-2026-10083 | 7.5 | 10.7 | Unknown | APCu Manager | — | APCu Manager < 4.5.0 - Unauthenticated Stored XSS via Cache Key Pollution |
| CVE-2026-13532 | 2.1 | 10.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System departmentDoctor.php sql injection |
| CVE-2026-13535 | 2.1 | 10.7 | CodeAstro | Human Resource Management System | CWE-74 | CodeAstro Human Resource Management System View Endpoint Employee_model.php G… |
| CVE-2026-13520 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System Appointment appointmentapproval.php s… |
| CVE-2026-13525 | 2.1 | 10.2 | CodeAstro | Human Resource Management System | CWE-74 | CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employe… |
| CVE-2026-13530 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System Appointment appointmentdetail.php sql… |
| CVE-2026-13531 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System department.php sql injection |
| CVE-2026-13541 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System doctorchangepassword.php sql injection |
| CVE-2026-13542 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System doctorprofile.php sql injection |
| CVE-2026-13548 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System doctortimings.php sql injection |
| CVE-2026-13572 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System insertbillingrecord.php sql injection |
| CVE-2026-13578 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientdetail.php sql injection |
| CVE-2026-13579 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientchangepassword.php sql injection |
| CVE-2025-2902 | 8.3 | 10.0 | Hitachi | Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H | CWE-862 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtua… |
| CVE-2026-13558 | 2.0 | 10.0 | CodeAstro | Complaint Management System | CWE-79 | CodeAstro Complaint Management System Report addreport cross site scripting |
| CVE-2026-13534 | 1.3 | 10.1 | CherryHQ | cherry-studio | CWE-285 | CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authoriza… |
| CVE-2026-13591 | 1.3 | 10.0 | DeepMyst | Mysti | CWE-266 | DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation impro… |
| CVE-2026-57959 | 8.2 | 9.3 | HiEventsDev | Hi.Events | CWE-367 | Hi.Events 1.9.0 - Promo Code Max-Usage Bypass via Asynchronous Job Race Condi… |
| CVE-2026-57942 | 6.9 | 9.2 | LibreTranslate | LibreTranslate | CWE-348 | LibreTranslate - IP Spoofing via X-Forwarded-For Header |
| CVE-2026-57334 | 6.5 | 9.0 | weDevs | WP User Frontend | CWE-862 | WordPress WP User Frontend plugin <= 4.3.7 - Broken Access Control vulnerability |
| CVE-2026-57339 | 6.5 | 9.0 | Strategy11 Team | Business Directory | CWE-862 | WordPress Business Directory plugin <= 6.4.23 - Broken Access Control vulnera… |
| CVE-2026-57340 | 6.5 | 9.0 | shohei.tanaka | Japanized For WooCommerce | CWE-862 | WordPress Japanized For WooCommerce plugin <= 2.9.12 - Broken Access Control … |
| CVE-2026-13570 | 2.0 | 9.1 | SourceCodester | Inventory Management System | CWE-79 | SourceCodester Inventory Management System User Registration Endpoint users_h… |
| CVE-2026-57945 | 5.3 | 8.9 | photoprism | photoprism | CWE-639 | PhotoPrism - Unauthorized User Profile Modification via PUT /api/v1/users/{ui… |
| CVE-2026-13752 | 8.0 | 8.7 | Snowflake | Snowflake CLI | CWE-89 | Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in … |
| CVE-2026-31016 | 6.5 | 8.4 | n/a | n/a | CWE-352 | Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 a… |
| CVE-2026-56457 | 4.3 | 7.9 | HCLSoftware | HCL DevOps Deploy / HCL Launch | CWE-532 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive inf… |
| CVE-2026-57326 | 6.1 | 7.4 | Strategy11 Team | Business Directory | CWE-79 | WordPress Business Directory plugin <= 6.4.22 - Cross Site Scripting (XSS) vu… |
| CVE-2026-57676 | 4.3 | 7.4 | Matteo Manna | Simple User Avatar | CWE-639 | WordPress Simple User Avatar plugin <= 4.9 - Insecure Direct Object Reference… |
| CVE-2026-57320 | 7.1 | 7.2 | RealMag777 | BEAR | CWE-79 | WordPress BEAR plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57952 | 6.0 | 6.8 | its-a-feature | Mythic | CWE-862 | Mythic < 3.4.0.60 - Unauthorized C2 Profile Configuration Access via Unverifi… |
| CVE-2026-54888 | 6.9 | 6.5 | leandrocp | mdex | CWE-674 | Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex |
| CVE-2026-57954 | 5.3 | 6.5 | yahoo | elide | CWE-862 | Elide 7.1.17 - Permission Bypass in Sort Expression Validation |
| CVE-2026-57958 | 5.1 | 6.6 | inovector | mixpost | CWE-79 | Mixpost 2.6.0 - Reflected XSS via OAuth Callback Error Parameter |
| CVE-2026-9267 | 6.9 | 6.3 | Eclipse Foundation | Eclipse tinydtls | CWE-125 | Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 conta… |
| CVE-2026-57330 | 6.5 | 6.4 | Stylemix | MasterStudy LMS | CWE-79 | WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-13537 | 2.1 | 5.9 | CodeAstro | Human Resource Management System | CWE-352 | CodeAstro Human Resource Management System cross-site request forgery |
| CVE-2026-55844 | 7.5 | 5.7 | home-assistant | core | CWE-319 | Home Assistant: iOS Companion App ignores internal SSID allowlist for connect… |
| CVE-2026-54369 | 8.4 | 5.0 | acl project | acl | CWE-59 | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions |
| CVE-2026-10648 | 5.5 | 4.6 | zephyrproject | zephyr | CWE-476 | NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-poo… |
| CVE-2026-40522 | 7.1 | 4.5 | FrontAccounting | FrontAccounting | CWE-89 | FrontAccounting < 2.4.20 SQL Injection via rep601.php |
| CVE-2026-13757 | 6.2 | 4.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-674 | P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing |
| CVE-2026-57997 | 6.3 | 4.5 | strapi | strapi | CWE-327 | Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Conf… |
| CVE-2026-57333 | 7.1 | 4.0 | Spencer Haws | Link Whisper Free | CWE-79 | WordPress Link Whisper Free plugin <= 0.9.4 - Reflected Cross Site Scripting … |
| CVE-2026-57336 | 7.1 | 4.0 | Astoundify | Jobify | CWE-79 | WordPress Jobify theme <= 4.3.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57337 | 7.1 | 4.0 | PluginOps | Landing Page Builder | CWE-79 | WordPress Landing Page Builder plugin <= 1.5.3.5 - Cross Site Scripting (XSS)… |
| CVE-2026-57338 | 7.1 | 4.0 | Repute InfoSystems | ARForms | CWE-79 | WordPress ARForms plugin <= 7.1.2 - Reflected Cross Site Scripting (XSS) vuln… |
| CVE-2026-53428 | 6.9 | 4.0 | leandrocp | mdex | CWE-789 | Unbounded memory allocation in highlight_lines range expansion in mdex |
| CVE-2026-13748 | 6.3 | 3.8 | Snowflake | Snowflake CLI | CWE-22 | Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper Fil… |
| CVE-2026-13601 | 6.5 | 3.2 | Red Hat | Red Hat Enterprise Linux 8 | CWE-693 | Yelp: yelp-xsl: overly permissive content security policy in yelp allows host… |
| CVE-2026-54371 | 8.4 | 3.1 | attr project | attr | CWE-59 | attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr |
| CVE-2026-57919 | 7.8 | 3.1 | n/a | n/a | CWE-276 | PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a… |
| CVE-2026-13746 | 5.4 | 3.1 | Snowflake | Snowflake CLI | CWE-89 | Snowflake CLI SQL Injection Through Improper Neutralization of Local CLI Para… |
| CVE-2026-53426 | 8.2 | 2.7 | leandrocp | mdex | CWE-770 | Atom-table exhaustion denial-of-service via JSON parse_document in MDEx |
| CVE-2026-57948 | 7.6 | 2.7 | pinpoint-apm | pinpoint | CWE-614 | Pinpoint - Insecure Session Cookie Attributes in pinpointJwt |
| CVE-2026-53429 | 6.9 | 2.7 | leandrocp | mdex | CWE-401 | Unbounded native memory leak in mdex escaped-tag rendering enables unauthenti… |
| CVE-2026-53325 | 5.5 | 2.7 | Linux | Linux | CWE-476 | agp/amd64: Fix broken error propagation in agp_amd64_probe() |
| CVE-2026-57966 | 4.4 | 2.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-22 | Spice-vdagent: path traversal in file transfer via unsanitized filename |
| CVE-2026-13751 | 9.6 | 2.0 | Snowflake | Snowflake CLI | CWE-829 | Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/… |
| CVE-2026-46406 | 4.4 | 2.0 | anthropics | claude-code | CWE-59 | Claude Code: Insecure Temporary File in /copy Command Enables Response Disclo… |
| CVE-2026-41991 | 2.0 | 2.0 | GNU | gzip | CWE-377 | Predictable Temporary File in GNU gzip |
| CVE-2026-57965 | 5.1 | 1.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow |
| CVE-2026-43743 | 4.7 | 1.6 | Apple | iOS and iPadOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-13523 | 1.9 | 1.6 | n/a | GPAC | CWE-404 | GPAC ISOBMFF base_encoding.c data amplification |
| CVE-2026-13595 | 5.3 | 1.5 | Red Hat | Red Hat Hardened Images | CWE-416 | Util-linux: util-linux: heap use-after-free in libblkid nested partition probing |
| CVE-2026-13750 | 5.5 | 1.4 | Snowflake | Snowflake CLI | CWE-532 | Snowflake CLI Sensitive Credential Exposure Through Debug Logging |
| CVE-2026-9676 | 4.3 | 1.1 | Unknown | F4 Post Tree | — | f4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification |
| CVE-2026-54370 | 7.2 | 0.5 | acl project | acl | CWE-367 | acl < 2.4.0 TOCTOU Symlink Traversal via getfacl/setfacl/chacl |
| CVE-2026-22078 | 7.3 | 0.4 | OPPO | O+ Connect | CWE-266 | O+ Connect's lack of authentication for IPC channels led to a local privilege… |
| CVE-2026-13742 | 5.9 | 0.3 | Honeywell Technologies | IQ MultiAccess | CWE-367 | Lack of signature verification before execution of downloaded content |
| CVE-2025-0824 | 3.7 | 0.3 | Hitachi | Hitachi Virtual Storage Platform One Block 23, 24, 26, 28 | CWE-347 | lack of validation for firmware update in Hitachi Virtual Storage |