| CVE-2026-95864 | 7.2 | 17.4 | themifyme | Themify Builder | CWE-79 | Themify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'c… |
| CVE-2026-93899 | 6.5 | 17.0 | wordplus | Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots | CWE-89 | Better Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'gro… |
| CVE-2026-97737 | 7.4 | 16.7 | muety | Wakapi | CWE-843 | In Wakapi before 2.17.6, the user caching service allows a lookup to be resol… |
| CVE-2026-95866 | 7.2 | 15.3 | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | CWE-79 | User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting v… |
| CVE-2026-97735 | 8.0 | 15.1 | ITFlow | ITFlow | CWE-79 | ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/t… |
| CVE-2026-97724 | 5.3 | 14.9 | swmansion | React Native Reanimated | CWE-1321 | A prototype pollution vulnerability in Software Mansion React Native Worklets… |
| CVE-2026-95811 | 6.5 | 14.9 | — | Lemonldap-NG-Handler | CWE-180 | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before… |
| CVE-2026-83591 | 7.2 | 14.2 | mohammed_kaludi | AMP for WP – Accelerated Mobile Pages | CWE-79 | AMP for WP <= 1.1.16 - Unauthenticated Stored Cross-Site Scripting via Commen… |
| CVE-2026-93303 | 7.2 | 14.2 | htplugins | HT Contact Form – Drag & Drop Form Builder for WordPress | CWE-79 | HT Contact Form <= 2.10.1 - Unauthenticated Stored DOM-Based Cross-Site Scrip… |
| CVE-2026-93654 | 7.2 | 13.6 | codename065 | Premium Packages – Sell Digital Products Securely | CWE-79 | Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via '… |
| CVE-2026-94573 | 7.2 | 13.6 | addonsorg | Repeater Fields for Elementor Forms | CWE-79 | Repeater Fields for Elementor Forms <= 2.2.7 - Unauthenticated Stored Cross-S… |
| CVE-2026-96039 | 7.2 | 13.6 | bookingalgorithms | BA Book Everything | CWE-79 | BA Book Everything <= 1.8.27 - Unauthenticated Stored Cross-Site Scripting vi… |
| CVE-2026-96568 | 7.2 | 13.6 | jetmonsters | Restaurant Menu and Food Ordering | CWE-79 | Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Si… |
| CVE-2026-96752 | 7.2 | 13.6 | bmarshall511 | Zero Spam for WordPress | CWE-79 | Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripti… |
| CVE-2026-96448 | 6.6 | 13.1 | Red Hat | Red Hat Build of Keycloak | CWE-285 | Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping al… |
| CVE-2026-97721 | 2.0 | 13.1 | Sanluan | PublicCMS | CWE-285 | Sanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsConte… |
| CVE-2026-19775 | 4.3 | 12.8 | allterraindeveloper | OpenStation: Desktop Windows, Dock & Virtual Desktops for WP Admin | CWE-862 | OpenStation <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) S… |
| CVE-2026-6082 | 5.1 | 12.4 | Novadigits technologies | StockAgile | CWE-79 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6083 | 5.1 | 12.4 | Novadigits technologies | StockAgile | CWE-79 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6084 | 5.1 | 12.4 | Novadigits technologies | StockAgile | CWE-79 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6085 | 5.1 | 12.4 | Novadigits technologies | StockAgile | CWE-79 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6086 | 5.1 | 12.4 | Novadigits technologies | StockAgile | CWE-79 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6087 | 5.1 | 12.4 | Novadigits technologies | StockAgile | CWE-79 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6088 | 5.1 | 12.4 | Novadigits technologies | StockAgile | CWE-79 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-97649 | 2.0 | 12.0 | ningzichun | student-management-system | CWE-1392 | ningzichun student-management-system example_lite.sql default credentials |
| CVE-2026-97764 | 3.7 | 11.9 | allauth | django-allauth | CWE-180 | django-allauth before 65.19.4 does not have the expected limits on failed log… |
| CVE-2026-92289 | await | 11.4 | — | Lemonldap-NG-Portal | CWE-1390 | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKC… |
| CVE-2026-93897 | 6.4 | 10.7 | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | CWE-79 | GeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scrip… |
| CVE-2026-92212 | 6.1 | 10.6 | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | CWE-79 | JetFormBuilder <= 3.6.5.3 - Reflected Cross-Site Scripting via 'jfb_xss' (URL… |
| CVE-2026-92288 | 9.1 | 10.2 | — | Lemonldap-NG-Portal | CWE-1390 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before … |
| CVE-2026-97723 | 5.4 | 9.9 | madpsy | ka9q_ubersdr | CWE-79 | madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vul… |
| CVE-2026-97736 | 5.4 | 9.7 | tinyauth | tinyauth | CWE-777 | tinyauth before 5.1.3 allows rule bypass by appending an allowed route string… |
| CVE-2026-84281 | 7.2 | 9.5 | radykal | Fancy Product Designer | CWE-79 | Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting… |
| CVE-2026-93656 | 6.4 | 8.9 | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | CWE-79 | User Profile Builder <= 4.0.2 - Authenticated (Subscriber+) Stored Cross-Site… |
| CVE-2026-93747 | 6.4 | 8.9 | tomdever | wpForo Forum | CWE-79 | wpForo Forum <= 3.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripti… |
| CVE-2026-96766 | 6.4 | 8.9 | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | CWE-79 | GeoDirectory <= 2.8.183 - Authenticated (Subscriber+) Stored Cross-Site Scrip… |
| CVE-2026-93477 | 5.9 | 8.4 | ash-project | ash | CWE-915 | Private action arguments can be set by user input on the bulk destroy and bul… |
| CVE-2026-92609 | 9.8 | 8.2 | Apache Software Foundation | Apache Qpid Broker-J | CWE-384 | Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentic… |
| CVE-2026-92550 | 7.5 | 8.0 | Apache Software Foundation | Apache Qpid Broker-J | CWE-789 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocati… |
| CVE-2026-92560 | 7.5 | 8.0 | Apache Software Foundation | Apache Qpid Broker-J | CWE-770 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocati… |
| CVE-2026-92746 | 6.4 | 8.0 | jegstudio | Gutenverse – WordPress Blocks, Page Builder & Site Editor | CWE-79 | Gutenverse <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-94376 | 6.4 | 8.0 | wordplus | Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots | CWE-79 | Better Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross… |
| CVE-2026-92564 | await | 8.0 | Apache Software Foundation | Apache Qpid Broker-J | CWE-674 | Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-a… |
| CVE-2026-85417 | 6.4 | 7.8 | Brocade | SANnav | CWE-532 | Incomplete property masking in the SANnav logging subsystem |
| CVE-2026-84279 | 7.2 | 7.7 | radykal | Fancy Product Designer | CWE-79 | Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting… |
| CVE-2026-86837 | 5.3 | 6.9 | Unknown | Bookly | CWE-639 | Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass |
| CVE-2026-97648 | 2.1 | 4.7 | ningzichun | student-management-system | CWE-352 | ningzichun student-management-system cross-site request forgery |
| CVE-2026-80514 | 5.3 | 4.4 | Unknown | wpForo Forum | CWE-348 | wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate… |
| CVE-2026-92608 | 7.5 | 4.3 | Apache Software Foundation | Apache Qpid Broker-J | CWE-248 | Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 t… |
| CVE-2026-92573 | 6.5 | 4.3 | Apache Software Foundation | Apache Qpid Broker-J | CWE-409 | Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery … |
| CVE-2026-78394 | 4.1 | 4.1 | Unknown | Link Library | CWE-22 | Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter |
| CVE-2025-14814 | 6.4 | 4.0 | wipeoutmedia | CSS & JavaScript Toolbox | CWE-79 | CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Contributor+) Stored Cros… |
| CVE-2026-97731 | 7.1 | 3.8 | MinIO | MinIO | CWE-347 | MinIO through 7aac2a2 does not verify that every x-amz-* header present on a … |
| CVE-2026-78393 | 6.1 | 3.6 | Unknown | Link Library | CWE-79 | Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort an… |
| CVE-2026-75553 | 2.4 | 2.8 | Tohoku Electric Power Company, Incorporated | Tohoku Electric Power "Yorisou e Net" Android App | CWE-321 | Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-code… |
| CVE-2026-97846 | 6.8 | 2.4 | Red Hat | Red Hat Build of Keycloak | CWE-287 | Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtl… |
| CVE-2026-78397 | 4.0 | 2.3 | Unknown | Link Library | CWE-918 | Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation |
| CVE-2026-62062 | 8.8 | 2.2 | Elementor | Elementor Website Builder | CWE-352 | WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forg… |
| CVE-2026-88848 | 4.2 | 1.6 | Unknown | MasterStudy LMS | CWE-863 | MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Catego… |
| CVE-2026-97732 | 5.1 | 0.0 | IRONMACE | Ironshield | CWE-347 | IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authentic… |
| CVE-2026-100382 | 10.0 | — | Wikimedia Foundation | Mediawiki - ExternalData Extension | CWE-78 | Unauthenticated remote code execution through wikitext in ExternalData |
| CVE-2026-92161 | 9.8 | — | FriendsOfFlarum | oauth | CWE-345 | FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email … |
| CVE-2026-93643 | 9.8 | — | Zimbra | Zimbra Collaboration Suite (ZCS) | CWE-22 | Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to R… |
| CVE-2026-100075 | 9.8 | — | Linux | Linux | — | RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters |
| CVE-2026-48482 | 9.4 | — | glpi-project | glpi | CWE-22 | GLPI: RCE via Form import |
| CVE-2026-93641 | 9.3 | — | Zimbra | Zimbra Collaboration Suite (ZCS) | CWE-79 | Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via… |
| CVE-2026-93642 | 9.3 | — | Zimbra | Zimbra Collaboration Suite (ZCS) | CWE-79 | Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via … |
| CVE-2026-93647 | 9.3 | — | Zimbra | Zimbra Collaboration Suite (ZCS) | CWE-79 | Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via… |
| CVE-2026-95832 | 9.3 | — | Kovid Goyal | kitty | CWE-74 | Reflected unknown field names in the kitty colour control escape code allow c… |
| CVE-2026-97063 | 9.3 | — | yzcheng90 | X-SpringBoot | CWE-287 | X-SpringBoot through 6.0 Authentication Bypass via Login Code |
| CVE-2026-97064 | 9.3 | — | yzcheng90 | X-SpringBoot | CWE-1392 | X-SpringBoot through 6.0 Authentication Bypass via Static Master Code |
| CVE-2026-100389 | 9.2 | — | GestSup | GestSup | CWE-434 | GestSup before 3.2.61 Remote Code Execution via IMAP Attachment |
| CVE-2026-39353 | 9.1 | — | InvoicePlane | InvoicePlane | CWE-98 | InvoicePlane: Remote Code Execution via Writable Templates Directory |
| CVE-2026-42322 | 9.1 | — | Piwigo | Piwigo | CWE-434 | Piwigo: Authenticated RCE via File Upload in Logo Upload Feature |
| CVE-2026-62262 | 9.1 | — | Piwigo | Piwigo | CWE-89 | Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` |
| CVE-2026-84458 | 9.1 | — | zammad | zammad | CWE-287 | Zammad: Account takeover via unverified email matching during SSO auto-link |
| CVE-2026-100390 | 9.1 | — | tobychui | zoraxy | CWE-290 | Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6 |
| CVE-2025-51457 | 8.8 | — | n/a | n/a | CWE-77 | D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection… |
| CVE-2026-61525 | 8.8 | — | zammad | zammad | CWE-22 | Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Po… |
| CVE-2026-85542 | 8.8 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-93834 | 8.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape |
| CVE-2026-94445 | 8.8 | — | golang.org/x/playground | golang.org/x/playground | CWE-20 | Malicious user input may lead to RCE in golang.org/x/playground |
| CVE-2026-96795 | 8.8 | — | horilla | horilla-hr | CWE-94 | Horilla: Authenticated RCE in Horilla List-View Export |
| CVE-2026-96812 | 8.8 | — | Google | gVisor | CWE-269 | Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE |
| CVE-2026-97527 | 8.8 | — | Linux | Linux | — | scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock |
| CVE-2026-97528 | 8.8 | — | Linux | Linux | — | scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error |
| CVE-2026-97555 | 8.8 | — | Linux | Linux | — | smb: client: fix heap overflow in DACL owner/group rewrite |
| CVE-2026-97957 | 8.8 | — | Linux | Linux | — | net: hinic: fix mailbox segment buffer overflow |
| CVE-2026-98115 | 8.8 | — | Linux | Linux | — | ksmbd: safely drain sessions during logoff |
| CVE-2026-100391 | 8.8 | — | mhdzumair | mediaflow-proxy | CWE-918 | MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Vali… |
| CVE-2026-56725 | 8.7 | — | zammad | zammad | CWE-306 | Zammad: Denial of Service via OTRS Import Controller |
| CVE-2026-56733 | 8.7 | — | zammad | zammad | CWE-269 | Zammad: Incorrect Authorization and Improper Privilege Management |
| CVE-2026-89032 | 8.7 | — | BerriAI | litellm | CWE-863 | BerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache Layer |
| CVE-2026-84462 | 8.6 | — | zammad | zammad | CWE-20 | Zammad: AI Agent template sanitizer bypass leads to remote code execution |
| CVE-2026-97060 | 8.6 | — | yzcheng90 | X-SpringBoot | CWE-639 | X-SpringBoot through 6.0 Authorization Bypass via User Management |
| CVE-2026-100372 | 8.6 | — | MacWarrior | clipbucket-v5 | CWE-22 | ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php |
| CVE-2026-47679 | 8.5 | — | glpi-project | glpi | CWE-22 | GLPI: arbitrary file deletion |
| CVE-2026-55214 | 8.5 | — | glpi-project | glpi | CWE-116 | GLPI: Stored XSS in suppliers |
| CVE-2026-71483 | 8.5 | — | horilla | horilla-hr | CWE-79 | Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View |
| CVE-2026-100172 | 8.5 | — | ail project | ail framework | CWE-79 | Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic va… |
| CVE-2026-100176 | 8.5 | — | ail project | ail framework | CWE-79 | Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip |
| CVE-2026-56731 | 8.4 | — | zammad | zammad | CWE-79 | Zammad: Cross-Site Scripting in Ticket Notifications |
| CVE-2026-97898 | 8.4 | — | akia | akia | CWE-639 | Broken authorization in Akia keyless entry lets an authenticated guest unlock… |
| CVE-2026-100248 | 8.4 | — | Rattadan | Cosmowarp Contract | CWE-1025 | The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to… |
| CVE-2026-100368 | 8.4 | — | alastairlundy | CliInvoke.Specializations | CWE-78 | CliInvoke.Specializations: Command injection in PowerShell and Cmd shell wrap… |
| CVE-2026-100369 | 8.4 | — | alastairlundy | CliInvoke | CWE-88 | CliInvoke: Argument Injection in Extensibility Runner Factory |
| CVE-2026-100501 | 8.3 | — | pawelmalak | flame | CWE-307 | Flame through 2.4.0 Brute-Force Attack via Login Endpoint |
| CVE-2026-67236 | 8.2 | — | rabbitmq | rabbitmq-server | CWE-312 | RabbitMQ: Plaintext username:password stored in an insecure cookie after succ… |
| CVE-2026-67409 | 8.2 | — | rabbitmq | rabbitmq-server | CWE-252 | RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruct… |
| CVE-2026-67410 | 8.2 | — | rabbitmq | rabbitmq-server | CWE-200 | RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint |
| CVE-2026-97525 | 8.2 | — | Linux | Linux | — | x86/mm/pat: Allocate split page tables as kernel page tables |
| CVE-2026-44642 | 8.1 | — | Piwigo | Piwigo | CWE-89 | Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrad… |
| CVE-2026-51773 | 8.1 | — | n/a | n/a | CWE-918 | An issue in the VMware datastore driver of OpenStack glance_store. When an au… |
| CVE-2026-97570 | 8.1 | — | Linux | Linux | — | bnxt_en: Bound SW TPA IDs to prevent crashes |
| CVE-2026-97573 | 8.1 | — | Linux | Linux | — | bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() |
| CVE-2026-97875 | 8.1 | — | rojo-rbx | rojo | CWE-350 | DNS rebinding vulnerability in rojo serve HTTP API |
| CVE-2026-98069 | 8.1 | — | Linux | Linux | — | net/rds: acquire the fastpath locks in rds_conn_shutdown() |
| CVE-2026-98070 | 8.1 | — | Linux | Linux | — | net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() |
| CVE-2026-98130 | 8.1 | — | Linux | Linux | — | sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START |
| CVE-2026-79153 | 7.8 | — | n/a | n/a | CWE-269 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access co… |
| CVE-2026-91837 | 7.8 | — | GNOME | NetworkManager-iodine | CWE-78 | Networkmanager-iodine: networkmanager-iodine: local privilege escalation to r… |
| CVE-2026-91838 | 7.8 | — | GNOME | NetworkManager-sstp | CWE-78 | Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root … |
| CVE-2026-91839 | 7.8 | — | GNOME | NetworkManager-fortisslvpn | CWE-93 | Networkmanager-fortisslvpn: networkmanager-fortisslvpn: local privilege escal… |
| CVE-2026-91840 | 7.8 | — | GNOME | NetworkManager-vpnc | CWE-93 | Networkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root … |
| CVE-2026-91841 | 7.8 | — | GNOME | NetworkManager-vpnc | CWE-93 | Networkmanager-vpnc: networkmanager-vpnc: incomplete fix for cve-2018-10900 a… |
| CVE-2026-97548 | 7.8 | — | Linux | Linux | — | xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions |
| CVE-2026-97575 | 7.8 | — | Linux | Linux | — | media: v4l2-ctrls: validate AV1 tile counts |
| CVE-2026-97576 | 7.8 | — | Linux | Linux | — | media: v4l2-ctrls: validate HEVC tile counts |
| CVE-2026-97577 | 7.8 | — | Linux | Linux | — | media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity |
| CVE-2026-97578 | 7.8 | — | Linux | Linux | — | media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer |
| CVE-2026-97579 | 7.8 | — | Linux | Linux | — | media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity |
| CVE-2026-97580 | 7.8 | — | Linux | Linux | — | media: rkvdec: bound HEVC tile loops and PPS id to the array capacity |
| CVE-2026-97584 | 7.8 | — | Linux | Linux | — | afs: Fix incorrect free in candidate cleanup in afs_lookup_server() |
| CVE-2026-97594 | 7.8 | — | Linux | Linux | — | landlock: Fix use-after-free of the source's parent directory |
| CVE-2026-97602 | 7.8 | — | Linux | Linux | — | inet: frags: invalidate queues before flushing them |
| CVE-2026-97611 | 7.8 | — | Linux | Linux | — | net: openvswitch: fix use-after-free of the flow table mask array |
| CVE-2026-97612 | 7.8 | — | Linux | Linux | — | net: mpls: clear inner_protocol when the last label is popped |
| CVE-2026-97903 | 7.8 | — | Linux | Linux | — | exit: hold a reference to thread_pid across proc_flush_pid |
| CVE-2026-97910 | 7.8 | — | Linux | Linux | — | ASoC: sprd: validate compress buffer sizes against fixed allocations |
| CVE-2026-97911 | 7.8 | — | Linux | Linux | — | accel: ethosu: Ensure SRAM region size matches job |
| CVE-2026-97937 | 7.8 | — | Linux | Linux | — | ftrace: fork: Initialize function graph state before copy_exec_state() |
| CVE-2026-97940 | 7.8 | — | Linux | Linux | — | ipv6: fix fib6 walker UAF on seq stop |
| CVE-2026-97941 | 7.8 | — | Linux | Linux | — | mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race |
| CVE-2026-97971 | 7.8 | — | Linux | Linux | — | nstree: check listing permission before taking a namespace reference |
| CVE-2026-97991 | 7.8 | — | Linux | Linux | — | vdpa_sim_blk: reject out-of-range sector starts |
| CVE-2026-98002 | 7.8 | — | Linux | Linux | — | iommu/amd: Fix ineffective error check in nested domain allocation |
| CVE-2026-98017 | 7.8 | — | Linux | Linux | — | net/sched: defer qdisc freeing after failed creation |
| CVE-2026-98023 | 7.8 | — | Linux | Linux | — | vxlan: reject dynamic fdb entries that reference a nexthop id |
| CVE-2026-98052 | 7.8 | — | Linux | Linux | — | net: bcmasp: clear txcb->last before writing each descriptor |
| CVE-2026-98073 | 7.8 | — | Linux | Linux | — | net: Remove conflicting altnames for dying netns in __dev_change_net_namespac… |
| CVE-2026-98112 | 7.8 | — | Linux | Linux | — | ksmbd: fix listener task lifetime on netdev events |
| CVE-2026-98116 | 7.8 | — | Linux | Linux | — | ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF |
| CVE-2026-98122 | 7.8 | — | Linux | Linux | — | vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() |
| CVE-2026-98143 | 7.8 | — | Linux | Linux | — | accel: ethosu: Don't read the U65 rounding mode as a storage mode |
| CVE-2026-98156 | 7.8 | — | Linux | Linux | — | drm/virtio: use the DMA API for resource backing on Xen |
| CVE-2026-49470 | 7.7 | — | glpi-project | glpi | CWE-307 | GLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover… |
| CVE-2026-67239 | 7.6 | — | rabbitmq | rabbitmq-server | CWE-79 | RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI |
| CVE-2026-84893 | 7.6 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-5267 | 7.5 | — | Ciena | Navigator NCS | CWE-306 | Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS |
| CVE-2026-10758 | 7.5 | — | Esri | Lerc | CWE-190 | Esri Lerc has a security vulnerability |
| CVE-2026-49850 | 7.5 | — | InvoicePlane | InvoicePlane | CWE-22 | InvoicePlane: Missing CSRF Protection on State-Changing delete Actions |
| CVE-2026-50547 | 7.5 | — | InvoicePlane | InvoicePlane | CWE-22 | InvoicePlane permits local file inclusion through the e-invoice XML configura… |
| CVE-2026-52622 | 7.5 | — | n/a | n/a | CWE-200 | An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Termi… |
| CVE-2026-53610 | 7.5 | — | glpi-project | glpi | CWE-79 | GLPI: Reflected XSS in dashboards |
| CVE-2026-53625 | 7.5 | — | glpi-project | glpi | CWE-862 | GLPI: Privilege Escalation via authtype API manipulation |
| CVE-2026-57443 | 7.5 | — | issdandavis | SCBE-AETHERMOORE | CWE-306 | SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email… |
| CVE-2026-67237 | 7.5 | — | rabbitmq | rabbitmq-server | CWE-79 | RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint |
| CVE-2026-84882 | 7.5 | — | IBM | Guardium Data Protection | CWE-22 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84884 | 7.5 | — | IBM | Guardium Data Protection | CWE-256 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-85029 | 7.5 | — | IBM | Guardium Data Protection | CWE-22 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-88003 | 7.5 | — | InvoicePlane | InvoicePlane | CWE-863 | InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade |
| CVE-2026-88421 | 7.5 | — | n/a | n/a | CWE-284 | Incorrect access control in the BlogPage.get_entries() component of APSL pupu… |
| CVE-2026-91765 | 7.5 | — | PHP Group | PHP | CWE-674 | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node |
| CVE-2026-97523 | 7.5 | — | Linux | Linux | — | mptcp: close race between scheduler and state change |
| CVE-2026-97524 | 7.5 | — | Linux | Linux | — | mptcp: avoid unneeded actions on subflow reset |
| CVE-2026-97531 | 7.5 | — | Linux | Linux | — | scsi: qla2xxx: Skip vport under deletion in report ID acquisition |
| CVE-2026-97536 | 7.5 | — | Linux | Linux | — | scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown |
| CVE-2026-97557 | 7.5 | — | Linux | Linux | — | smb: client: avoid leaking refcount in cifs_queue_oplock_break() |
| CVE-2026-97562 | 7.5 | — | Linux | Linux | — | smb: client: pin DFS superblock in iterator callback |
| CVE-2026-97583 | 7.5 | — | Linux | Linux | — | afs: Clear stale peer app data after address list changes |
| CVE-2026-97595 | 7.5 | — | Linux | Linux | — | mac802154: fix use-after-free of sdata via queued RX frames |
| CVE-2026-97990 | 7.5 | — | Linux | Linux | — | vdpa_sim_net: check TX pull result before RX copy |
| CVE-2026-98050 | 7.5 | — | Linux | Linux | — | mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context |
| CVE-2026-98056 | 7.5 | — | Linux | Linux | — | nvme: remove stale namespaces by NSID range during scan |
| CVE-2026-98108 | 7.5 | — | Linux | Linux | — | Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan |
| CVE-2026-100208 | 7.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-190 | Microsoft Office Outlook Remote Code Execution Vulnerability |
| CVE-2026-98096 | 7.4 | — | Linux | Linux | — | ipv6: sr: restore network header before routing and forwarding |
| CVE-2026-100310 | 7.3 | — | GNU | libextractor | CWE-426 | GNU libextractor before 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX |
| CVE-2026-100419 | 7.3 | — | GitoxideLabs | gitoxide | CWE-59 | gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink |
| CVE-2026-33639 | 7.2 | — | InvoicePlane | InvoicePlane | CWE-89 | InvoicePlane permits DDL injection through tax_rate_decimal_places |
| CVE-2026-42323 | 7.2 | — | Piwigo | Piwigo | CWE-89 | Piwigo: SQL Injection in Batch Manager |
| CVE-2026-42324 | 7.2 | — | Piwigo | Piwigo | CWE-89 | Piwigo: Second-Order SQL Injection |
| CVE-2026-84862 | 7.2 | — | IBM | Guardium Data Protection | CWE-502 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-85750 | 7.2 | — | Piwigo | Piwigo | CWE-20 | Piwigo arbitrary file read and remote code execution via insecure image proce… |
| CVE-2026-100387 | 7.2 | — | pgpointcloud | pointcloud | CWE-125 | pgPointcloud through 1.2.5 heap out-of-bounds read via WKB deserialization |
| CVE-2026-53626 | 7.1 | — | glpi-project | glpi | CWE-639 | GLPI: Arbitrary Document Read via Form Context Authorization Bypass |
| CVE-2026-53629 | 7.1 | — | glpi-project | glpi | CWE-89 | GLPI: SQL injection in history tab |
| CVE-2026-56723 | 7.1 | — | zammad | zammad | CWE-863 | Zammad: Missing authorization on ticket attachment download |
| CVE-2026-56724 | 7.1 | — | zammad | zammad | CWE-639 | Zammad: Incorrect implementation of permission checks in the knowledge base m… |
| CVE-2026-56727 | 7.1 | — | zammad | zammad | CWE-287 | Zammad: PGP signature spoofing via unvalidated verification return |
| CVE-2026-57449 | 7.1 | — | actualbudget | actual | CWE-200 | Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Priva… |
| CVE-2026-67408 | 7.1 | — | rabbitmq | rabbitmq-server | CWE-400 | RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-P… |
| CVE-2026-67419 | 7.1 | — | rabbitmq | rabbitmq-server | CWE-407 | RabbitMQ: Consecutive topic wildcards cause combinatorial routing work |
| CVE-2026-84464 | 7.1 | — | zammad | zammad | CWE-200 | Zammad: IDOR in External Data Source rendering exposes ticket, user, group, a… |
| CVE-2026-84465 | 7.1 | — | zammad | zammad | CWE-290 | Zammad: S/MIME signature verification allows forged sender impersonation |
| CVE-2026-93306 | 7.1 | — | IBM | Server Firmware | CWE-125 | This Power System update is being released to address |
| CVE-2026-93365 | 7.1 | — | Bludit | Bludit CMS | CWE-862 | Bludit CMS 3.22.0 Missing Authorization via content-get-list AJAX Endpoint |
| CVE-2026-97589 | 7.0 | — | Linux | Linux | — | s390/crypto: Fix wrong return code to engine in asynch callbacks |
| CVE-2026-97608 | 7.0 | — | Linux | Linux | — | netfilter: nf_log: unregister loggers before per-net teardown |
| CVE-2026-97609 | 7.0 | — | Linux | Linux | — | netfilter: cttimeout: prevent UAF during module unload |
| CVE-2026-97926 | 7.0 | — | Linux | Linux | — | ufs: validate cylinder group metadata before caching it |
| CVE-2026-97931 | 7.0 | — | Linux | Linux | — | ALSA: us122l: Prevent write upgrades for read mappings |
| CVE-2026-97953 | 7.0 | — | Linux | Linux | — | net: stmmac: fix TX descriptor availability check for TSO traffic |
| CVE-2026-98027 | 7.0 | — | Linux | Linux | — | net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size |
| CVE-2026-98029 | 7.0 | — | Linux | Linux | — | eth: nfp: bound the ntuple rule dump by the caller's buffer size |
| CVE-2026-98030 | 7.0 | — | Linux | Linux | — | net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size |
| CVE-2026-98041 | 7.0 | — | Linux | Linux | — | bpf: Don't predict JMP32 pointer vs zero comparisons |
| CVE-2026-98083 | 7.0 | — | Linux | Linux | — | btrfs: fix transaction use-after-free in raid stripe insertion |
| CVE-2026-98150 | 7.0 | — | Linux | Linux | — | bpf: Fix BPF_F_CPU validation for sparse CPU IDs |
| CVE-2026-98154 | 7.0 | — | Linux | Linux | — | nvme-rdma: fix -EIO cleanup order in queue_rq |
| CVE-2026-17545 | 6.9 | — | PHP Group | PHP | CWE-67 | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O… |
| CVE-2026-63207 | 6.9 | — | zammad | zammad | CWE-200 | Zammad: Sensitive Information Exposure in Integration Administration API |
| CVE-2026-67226 | 6.9 | — | rabbitmq | rabbitmq-server | CWE-400 | RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list |
| CVE-2026-84461 | 6.9 | — | zammad | zammad | CWE-203 | Zammad: Missing rate limiting allows password brute-forcing during two-factor… |
| CVE-2026-96875 | 6.9 | — | The Wikimedia Foundation | Mediawiki - Cargo extension | CWE-79 | Reflected XSS in Cargo Drilldown hierarchy filters |
| CVE-2026-96876 | 6.9 | — | The Wikimedia Foundation | Mediawiki - Cargo extension | CWE-79 | Anonymous reflected XSS in CargoExport invalid-alias errors |
| CVE-2026-96877 | 6.9 | — | The Wikimedia Foundation | Mediawiki - Cargo extension | CWE-79 | Reflected XSS through Cargo Drilldown full-text search |
| CVE-2026-96878 | 6.9 | — | The Wikimedia Foundation | Mediawiki - Cargo extension | CWE-79 | Cargo Exhibit field alias allows stored XSS |
| CVE-2026-96879 | 6.9 | — | The Wikimedia Foundation | Mediawiki - FlaggedRevs extension | CWE-212 | "Checked by" label in page history should not be shown if the underlying revi… |
| CVE-2026-97865 | 6.9 | — | n/a | Open-Web-Analytics | CWE-20 | Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deseri… |
| CVE-2026-100187 | 6.9 | — | ail project | ail framework | CWE-20 | AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Byp… |
| CVE-2026-100192 | 6.9 | — | yzcheng90 | X-SpringBoot | CWE-306 | X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint |
| CVE-2026-100306 | 6.9 | — | TDuckCloud | tduck-survey-form | CWE-602 | TDuck survey form through 6.0 Write Password Bypass via Client-Side Enforcement |
| CVE-2026-100377 | 6.9 | — | Wikimedia Foundation | Mediawiki - WikiLambda Extension | CWE-200 | Revision-deleted pages can be viewed through WikiLambda's action=edit and Spe… |
| CVE-2026-100418 | 6.9 | — | pawelmalak | flame | CWE-200 | Flame through 2.4.0 Information Exposure via GET /api/config |
| CVE-2026-80431 | 6.8 | — | Kovid Goyal | kitty | CWE-787 | Out-of-bounds write in the kitty text sizing protocol allows termination of t… |
| CVE-2025-14181 | 6.5 | — | PHP Group | PHP | CWE-190 | Integer overflow to buffer overflow in soap HTTP parsing |
| CVE-2026-63431 | 6.5 | — | horilla | horilla-hr | CWE-862 | Horilla: Missing Authorization on Payroll Component Views Exposes Employee Sa… |
| CVE-2026-63432 | 6.5 | — | horilla | horilla-hr | CWE-94 | Horilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allo… |
| CVE-2026-85274 | 6.5 | — | InvoicePlane | InvoicePlane | CWE-352 | InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Pro… |
| CVE-2026-85289 | 6.5 | — | InvoicePlane | InvoicePlane | CWE-352 | InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints |
| CVE-2026-85291 | 6.5 | — | InvoicePlane | InvoicePlane | CWE-639 | InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Withou… |
| CVE-2026-91767 | 6.5 | — | PHP Group | PHP | CWE-122 | Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server c… |
| CVE-2026-91768 | 6.5 | — | PHP Group | PHP | CWE-1023 | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comp… |
| CVE-2026-93030 | 6.5 | — | IBM | IBM Financial Transaction Manager (FTM) for Redhat OpenShift | CWE-611 | FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive i… |
| CVE-2026-61837 | 6.3 | — | rabbitmq | rabbitmq-server | CWE-285 | RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology t… |
| CVE-2026-67223 | 6.3 | — | rabbitmq | rabbitmq-server | CWE-90 | RabbitMQ: LDAP DN injection via unescaped substitution |
| CVE-2026-67225 | 6.3 | — | rabbitmq | rabbitmq-server | CWE-770 | RabbitMQ: Stream-protocol frame length never validated against frame_max |
| CVE-2026-67230 | 6.3 | — | rabbitmq | rabbitmq-server | CWE-770 | RabbitMQ: Web-STOMP unbounded pre-auth accumulation |
| CVE-2026-67242 | 6.3 | — | rabbitmq | rabbitmq-server | CWE-613 | RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp |
| CVE-2026-84463 | 6.3 | — | zammad | zammad | CWE-79 | Zammad: Stored HTML injection in Knowledge Base video widget enables forced s… |
| CVE-2026-100177 | 6.3 | — | ail project | ail framework | CWE-20 | Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Org… |
| CVE-2026-100190 | 6.3 | — | ail project | ail framework | CWE-79 | Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework… |
| CVE-2026-18311 | 6.1 | — | Readwise | Reader | CWE-79 | CVE-2026-18311 |
| CVE-2026-18312 | 6.1 | — | Readwise | Reader | CWE-79 | CVE-2026-18312 |
| CVE-2026-18320 | 6.1 | — | Readwise | Reader | CWE-79 | CVE-2026-18320 |
| CVE-2026-78902 | 6.1 | — | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows … |
| CVE-2026-100237 | 6.1 | — | The Wikimedia Foundation | Mediawiki - Thanks Extension | CWE-79 | Stored i18n XSS in the Flow integration of Thanks |
| CVE-2026-53627 | 6.0 | — | glpi-project | glpi | CWE-862 | GLPI: Unexpected access to update operations through the API |
| CVE-2026-54790 | 6.0 | — | InvoicePlane | InvoicePlane | CWE-89 | InvoicePlane: Second-order SQL injection through the unvalidated custom_field… |
| CVE-2026-66071 | 6.0 | — | rabbitmq | rabbitmq-server | CWE-400 | RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values |
| CVE-2026-66073 | 6.0 | — | rabbitmq | rabbitmq-server | CWE-400 | RabbitMQ: Atom table exhaustion via management API node field |
| CVE-2026-67411 | 6.0 | — | rabbitmq | rabbitmq-server | CWE-863 | RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permissi… |
| CVE-2026-67412 | 6.0 | — | rabbitmq | rabbitmq-server | CWE-862 | RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost … |
| CVE-2026-67413 | 6.0 | — | rabbitmq | rabbitmq-server | CWE-1333 | RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker … |
| CVE-2026-80432 | 6.0 | — | Kovid Goyal | kitty | CWE-862 | Missing authorization in the kitty drag and drop protocol allows a client to … |
| CVE-2026-100304 | 6.0 | — | TDuckCloud | tduck-survey-form | CWE-636 | TDuck survey form 6.0 Information Disclosure via Fail-Open Form Ownership Check |
| CVE-2026-53628 | 5.9 | — | glpi-project | glpi | CWE-285 | GLPI: Unallowed authentication method update by administrator |
| CVE-2026-67222 | 5.9 | — | rabbitmq | rabbitmq-server | CWE-400 | RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client |
| CVE-2026-67227 | 5.9 | — | rabbitmq | rabbitmq-server | CWE-400 | RabbitMQ: Atom exhaustion: to_atom on global-parameter :name |
| CVE-2026-67415 | 5.9 | — | rabbitmq | rabbitmq-server | CWE-400 | RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Den… |
| CVE-2026-86066 | 5.9 | — | horilla | horilla-hr | CWE-352 | Horilla attendance approval endpoint is vulnerable to cross-site request forgery |
| CVE-2026-91766 | 5.9 | — | PHP Group | PHP | CWE-200 | Cross-origin credential leak in HTTP stream wrapper redirects |
| CVE-2026-92842 | 5.9 | — | PHP Group | PHP | CWE-122 | OOB read / info leak in convert.* stream filters when line-break-chars contai… |
| CVE-2026-100502 | 5.9 | — | pawelmalak | flame | CWE-613 | Flame through 2.4.0 Admin Token Insufficient Session Expiration |
| CVE-2026-93682 | 5.8 | — | PHP Group | PHP | CWE-125 | Out-of-bounds read in the HTTP stream wrapper when following a redirect with … |
| CVE-2026-95835 | 5.6 | — | Kovid Goyal | kitty | CWE-862 | Missing ownership check on the shared memory object named by the kitty askpas… |
| CVE-2026-97222 | 5.5 | — | GNOME | Gnumeric | CWE-416 | Gnumeric: gnumeric: heap use-after-free when opening a malformed workbook |
| CVE-2026-97864 | 5.5 | — | GibbonEdu | Gibbon | CWE-287 | GibbonEdu Gibbon Unit Planner units_add_blockAjax.php makeBlock missing authe… |
| CVE-2026-97871 | 5.5 | — | Zhonglun | CloudPos | CWE-74 | Zhonglun CloudPos JSBridge JSBridge.cs OpenLocalBrowser code injection |
| CVE-2026-97877 | 5.5 | — | zhistaredu | StarTraining | CWE-255 | zhistaredu StarTraining JWT Token application.yml UserLoginService.createToke… |
| CVE-2026-97878 | 5.5 | — | zhistaredu | StarTraining | CWE-287 | zhistaredu StarTraining Druid Console index.html anonymous missing authentica… |
| CVE-2026-97879 | 5.5 | — | zhistaredu | StarTraining | CWE-287 | zhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authent… |
| CVE-2026-97882 | 5.5 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project Faculty Authentication loginlinkfacul… |
| CVE-2026-97883 | 5.5 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project updatequery.php sql injection |
| CVE-2026-97885 | 5.5 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project updatefaculty.php sql injection |
| CVE-2026-45801 | 5.3 | — | glpi-project | glpi | CWE-269 | GLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escala… |
| CVE-2026-55217 | 5.3 | — | glpi-project | glpi | CWE-285 | GLPI: Unallowed modfication of knowbase items comments and translations |
| CVE-2026-56728 | 5.3 | — | zammad | zammad | CWE-200 | Zammad: Cross-User Taskbar Item Access Control Vulnerability |
| CVE-2026-56732 | 5.3 | — | zammad | zammad | CWE-20 | Zammad: Malicious input in Ticket Body Enables Session Termination |
| CVE-2026-56734 | 5.3 | — | zammad | zammad | CWE-918 | Zammad: Avatar Image URL Server-Side Request Forwarding |
| CVE-2026-56735 | 5.3 | — | zammad | zammad | CWE-82 | Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammad |
| CVE-2026-61855 | 5.3 | — | zammad | zammad | CWE-347 | Zammad: Invalid PGP Detached Signatures Reported as Good Signature on Inbound… |
| CVE-2026-63006 | 5.3 | — | zammad | zammad | CWE-22 | Zammad: HTML sanitizer API path allowlist bypass via interior path traversal … |
| CVE-2026-63206 | 5.3 | — | zammad | zammad | CWE-20 | Zammad: Remote image tracking bypass via shortened URL scheme |
| CVE-2026-63216 | 5.3 | — | zammad | zammad | CWE-80 | Zammad: Stored XSS via unescaped option labels in the object attribute option… |
| CVE-2026-84460 | 5.3 | — | zammad | zammad | CWE-639 | Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag … |
| CVE-2026-85290 | 5.3 | — | InvoicePlane | InvoicePlane | CWE-117 | InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging |
| CVE-2026-93363 | 5.3 | — | payloadcms | payload | CWE-862 | Payload CMS storage-vercel-blob Adapter Improper Access Control on Upload Route |
| CVE-2026-93364 | 5.3 | — | Bludit | Bludit CMS | CWE-915 | Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit() |
| CVE-2026-93366 | 5.3 | — | Bludit | Bludit CMS | CWE-639 | Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endp… |
| CVE-2026-100230 | 5.3 | — | input-leap | Input Leap | CWE-180 | Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag… |
| CVE-2026-100303 | 5.3 | — | TDuckCloud | tduck-survey-form | CWE-862 | TDuck survey form through 6.0 Missing Authorization in Form Theme Management … |
| CVE-2026-100305 | 5.3 | — | TDuckCloud | tduck-survey-form | CWE-862 | TDuck survey form through 6.0 Fill-In Restriction Bypass via Authenticated Su… |
| CVE-2026-100378 | 5.3 | — | Wikimedia Foundation | Mediawiki - Translate Extension | CWE-862 | Missing permission check in the Translate sandbox doRemind action |
| CVE-2026-100379 | 5.3 | — | Wikimedia Foundation | Wikipedia Android App | CWE-200 | Cross-request disclosure of CentralAuth cookies in Wikipedia Android App |
| CVE-2026-100380 | 5.3 | — | Wikimedia Foundation | Mediawiki - Wikibase Extension | CWE-79 | Reflected XSS in Wikibase Special:SetLabel language validation |
| CVE-2026-100381 | 5.3 | — | Wikimedia Foundation | Mediawiki - UploadWizard Extension | CWE-79 | UploadWizard Flickr collection and set titles allow DOM XSS |
| CVE-2026-100388 | 5.3 | — | rustdesk | rustdesk | CWE-862 | RustDesk before 1.5.0 Missing Authorization Check on Incoming File Clipboard … |
| CVE-2026-56726 | 5.1 | — | zammad | zammad | CWE-862 | Zammad: Missing authorization check in GitHub + GitLab integration allows cro… |
| CVE-2026-63205 | 5.1 | — | zammad | zammad | CWE-639 | Zammad: Channel admins can read unauthorized attachments via signature rich-t… |
| CVE-2026-63208 | 5.1 | — | zammad | zammad | CWE-116 | Zammad: Microsoft Graph error logs expose partially masked OAuth access tokens |
| CVE-2026-67407 | 5.1 | — | rabbitmq | rabbitmq-server | CWE-862 | RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not e… |
| CVE-2026-97897 | 5.1 | — | Krayin | laravel-crm | CWE-79 | Krayin laravel-crm TinyMCE Media Upload Sanitizer.php cross site scripting |
| CVE-2026-100174 | 5.1 | — | ail project | ail framework | CWE-79 | Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped… |
| CVE-2026-100373 | 5.1 | — | open-metadata | OpenMetadata | CWE-918 | OpenMetadata through 2.0.2 SSRF via Webhook URL Validation Bypass |
| CVE-2026-39372 | 4.9 | — | InvoicePlane | InvoicePlane | CWE-200 | InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata i… |
| CVE-2026-27867 | 4.8 | — | Teldat | Regesta Smart HD-PLC - TLDPH16D2 | CWE-79 | CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC O… |
| CVE-2026-67241 | 4.8 | — | rabbitmq | rabbitmq-server | CWE-862 | RabbitMQ: AMQP 1.0 management exchange.declare skips alternate-exchange permi… |
| CVE-2026-85292 | 4.8 | — | InvoicePlane | InvoicePlane | CWE-697 | InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-… |
| CVE-2026-85293 | 4.8 | — | InvoicePlane | InvoicePlane | CWE-79 | InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice a… |
| CVE-2026-100376 | 4.8 | — | Wikimedia Foundation | Mediawiki - TemplateSandbox Extension | CWE-79 | TemplateSandbox can be abused for XSS by asking another user to preview a pag… |
| CVE-2026-100383 | 4.8 | — | Wikimedia Foundation | Mediawiki - WikiLambda Extension | CWE-79 | Stored i18n XSS in WikiLambda's VisualEditor integration |
| CVE-2026-49469 | 4.6 | — | glpi-project | glpi | CWE-90 | GLPI: LDAP filter injection in user import feature |
| CVE-2026-67406 | 4.6 | — | rabbitmq | rabbitmq-server | CWE-200 | RabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Pla… |
| CVE-2026-80430 | 4.6 | — | Kovid Goyal | kitty | CWE-59 | Improper link resolution in the kitty drag and drop protocol allows a client … |
| CVE-2026-95834 | 4.6 | — | Kovid Goyal | kitty | CWE-416 | Use after free in the kitty drag and drop protocol when a drag source item is… |
| CVE-2026-67421 | 4.5 | — | rabbitmq | rabbitmq-server | CWE-862 | RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling |
| CVE-2026-6103 | 4.3 | — | PHP Group | PHP | CWE-190 | Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection |
| CVE-2026-91769 | 4.3 | — | PHP Group | PHP | CWE-297 | TLS Hostname Verification Falls Back to CN After SAN Mismatch |
| CVE-2026-97469 | 4.3 | — | DALIBO | PostgreSQL Anonymizer | CWE-328 | PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink |
| CVE-2025-1218 | 3.4 | — | PHP Group | PHP | CWE-122 | Various packet overreads in mysqlnd_writeprotocol.c |
| CVE-2026-97866 | 2.9 | — | Zhonglun | CloudPOS | CWE-300 | Zhonglun CloudPOS Automatic Update Program.cs channel accessible |
| CVE-2026-97228 | 2.7 | — | Rapid7 | Platform | CWE-943 | Rapid7 Bulk Export MCP — GraphQL Query Injection in Export Status Lookup |
| CVE-2026-63204 | 2.3 | — | zammad | zammad | CWE-639 | Zammad: Authenticated agents can read AI summary error messages from inaccess… |
| CVE-2026-65828 | 2.3 | — | zammad | zammad | CWE-862 | Zammad: Pending upload deletion bypass via legacy attachment endpoint |
| CVE-2026-67234 | 2.3 | — | rabbitmq | rabbitmq-server | CWE-20 | RabbitMQ: Non-RFC-conformant cookie name when clearing the auth-mechanism pre… |
| CVE-2026-67420 | 2.3 | — | rabbitmq | rabbitmq-server | CWE-862 | RabbitMQ OAuth credential refresh retains revoked runtime tags |
| CVE-2026-96874 | 2.3 | — | The Wikimedia Foundation | Mediawiki - Cargo extension | CWE-79 | Stored XSS in Cargo Drilldown tab names |
| CVE-2026-100417 | 2.3 | — | rustdesk | rustdesk | CWE-862 | RustDesk before 1.5.0 One-Way File Transfer Bypass |
| CVE-2026-56729 | 2.1 | — | zammad | zammad | CWE-200 | Zammad: Titles of knowledge base answers will be shown across all categories … |
| CVE-2026-56730 | 2.1 | — | zammad | zammad | CWE-862 | Zammad: Missing authorization in GraphQL mutation for suggesting knowledge ba… |
| CVE-2026-66078 | 2.1 | — | rabbitmq | rabbitmq-server | CWE-862 | RabbitMQ: protected tag bypass via bulk-delete |
| CVE-2026-97884 | 2.1 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project Student Update Functionality updatest… |
| CVE-2026-97886 | 2.1 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project managevideos2.php sql injection |
| CVE-2026-97895 | 2.1 | — | krayin | laravel-crm | CWE-266 | krayin laravel-crm User Management UserController.php privileges management |
| CVE-2026-97868 | 2.0 | — | sheshbabu | zen | CWE-79 | sheshbabu zen Note Editor NotesEditor.jsx dangerouslySetInnerHTML cross site … |
| CVE-2026-97896 | 2.0 | — | krayin | laravel-crm | CWE-79 | krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross sit… |
| CVE-2026-97869 | 1.2 | — | n/a | langchain4j | CWE-20 | langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticS… |
| CVE-2026-51772 | await | — | n/a | n/a | — | A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v… |
| CVE-2026-88389 | await | — | n/a | n/a | — | Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerabil… |
| CVE-2026-88420 | await | — | n/a | n/a | — | A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.sav… |
| CVE-2026-97522 | await | — | Linux | Linux | — | mptcp: fix bad accounting in __mptcp_subflow_push_pending() |
| CVE-2026-97526 | await | — | Linux | Linux | — | s390/pai: Support CPU hotplug for PMU PAI |
| CVE-2026-97529 | await | — | Linux | Linux | — | scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] |
| CVE-2026-97530 | await | — | Linux | Linux | — | scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature |
| CVE-2026-97532 | await | — | Linux | Linux | — | scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path |
| CVE-2026-97533 | await | — | Linux | Linux | — | x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF |
| CVE-2026-97534 | await | — | Linux | Linux | — | f2fs: accurately adjust free_sections during free_segment_range |
| CVE-2026-97535 | await | — | Linux | Linux | — | scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size |
| CVE-2026-97537 | await | — | Linux | Linux | — | scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking |
| CVE-2026-97538 | await | — | Linux | Linux | — | hwmon: (asus_rog_ryujin) Validate HID report lengths |
| CVE-2026-97539 | await | — | Linux | Linux | — | usb: xusbatm: don't rely on id table pointer arithmetic |
| CVE-2026-97540 | await | — | Linux | Linux | — | net: usb: pegasus: don't rely on id table pointer arithmetic |
| CVE-2026-97541 | await | — | Linux | Linux | — | wifi: ath9k_htc: don't store usb_device_id |
| CVE-2026-97542 | await | — | Linux | Linux | — | xfs: bail out on bitmap errors in xrep_agfl_fill |
| CVE-2026-97543 | await | — | Linux | Linux | — | xfs: destroy seen inode bitmap when we fail to add a dirpath |
| CVE-2026-97544 | await | — | Linux | Linux | — | xfs: don't leak dqacct if rhashtable insertion fails |
| CVE-2026-97545 | await | — | Linux | Linux | — | xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails |
| CVE-2026-97546 | await | — | Linux | Linux | — | xfs: don't spin forever on zero-length dirents when salvaging them |
| CVE-2026-97547 | await | — | Linux | Linux | — | xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN |
| CVE-2026-97549 | await | — | Linux | Linux | — | xfs: fix under-reservation of blocks when repairing sf directories |
| CVE-2026-97550 | await | — | Linux | Linux | — | xfs: fix unit conversions in per_binval computation |
| CVE-2026-97551 | await | — | Linux | Linux | — | xfs: initialise args->total for parent pointer updates |
| CVE-2026-97552 | await | — | Linux | Linux | — | xfs: initialise error in xfs_defer_finish_one() |