Critical vulnerabilities, curated daily for security professionals
đ¯ SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
đ
Archived Security Brief
Wednesday's disclosures center on widespread web platform and edge device exposure, with WordPress plugins, D-Link routers, and Eclipse developer tooling driving the critical caseload. Critical CVEs fell 57% to 15 while high-priority issues rose 42% to 92, indicating broader but less severe activity than the prior day. Notable entries include CVE-2026-7411 (CVSS 10) in Eclipse BaSyx Java Server SDK, CVE-2026-7853 and CVE-2026-7854 (CVSS 9.8) in D-Link DI series routers, and CVE-2026-27960 (CVSS 9.8) in Intel OpenCTI Platform. Remote code execution and unauthenticated access patterns dominate, affecting industrial automation, network edge equipment, and threat-intelligence infrastructure. Patch availability remains at 0% for the disclosed set, and eight CVEs carry confirmed active exploitation including issues in Samsung MagicINFO, SimpleHelp, and ConnectWise ScreenConnect.
Eclipse BaSyx Java Server SDK CVE-2026-7411 carries a maximum CVSS 10 score, with parallel exposure in Eclipse Equinox OSGi (CVE-2023-54342, CVE-2023-54344)
Critical CVEs decreased 57% day-over-day to 15, reflecting a narrower critical caseload than Tuesday's 35
High-priority CVEs increased 42% to 92, signaling broader exposure across the CVSS 7.0-8.9 band
Unauthenticated remote code execution affects D-Link DI routers (CVE-2026-7853, CVE-2026-7854) and EFM ipTIME NAS1dual (CVE-2026-7834), alongside multiple WordPress plugin flaws
Patch availability stands at 0% across the disclosed set, requiring compensating controls for exposed WordPress, D-Link, and Intel OpenCTI deployments
Eight CVEs are actively exploited, including Samsung MagicINFO 9 Server, SimpleHelp, ConnectWise ScreenConnect, and a Microsoft Windows issue (CVE-2026-32202)
Immediate action: Prioritize isolation and monitoring of Eclipse BaSyx, D-Link DI, WordPress, and Intel OpenCTI deployments while reviewing exposure on actively exploited Samsung MagicINFO, SimpleHelp, and ConnectWise ScreenConnect instances. With patch availability at 0% for the new disclosures, apply network segmentation, restrict administrative interfaces, and enable enhanced logging until vendor fixes are released.
đĄ Tip: Swipe CVE cards left to â star, right to â remove
Section Navigation
â
Featured Vulnerability
â FeaturedITWNoPatch
CVE-2026-0300
9.3đ
Palo Alto NetworksPAN-OS (PA-Series and VM-Series firewalls)
Unauthenticated RCE in Palo Alto PAN-OS firewalls
A buffer overflow in the User-ID Authentication Portal lets an unauthenticated network attacker execute arbitrary code as root on PA-Series and VM-Series firewalls. Palo Alto Networks confirms limited exploitation in the wild against portals reachable from untrusted IP space.
â ī¸
CISA Known Exploited Vulnerabilities
â ī¸ CISA KEVURGENT
CVE-2026-39987
9.5
MarimoMarimo
â° Federal Deadline:May 6, 2026(1 days remaining)
Marimo Remote Code Execution Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2025-29635
9.5
D-LinkDIR-823X
â° Federal Deadline:May 7, 2026(2 days remaining)
D-Link DIR-823X Command Injection Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2024-7399
9.5đ Late Disclosure
SamsungMagicINFO 9 Server
â° Federal Deadline:May 7, 2026(2 days remaining)
Samsung MagicINFO 9 Server Path Traversal Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2024-57728
9.5đ Late Disclosure
SimpleHelp SimpleHelp
â° Federal Deadline:May 7, 2026(2 days remaining)
SimpleHelp Path Traversal Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2024-57726
9.5đ Late Disclosure
SimpleHelp SimpleHelp
â° Federal Deadline:May 7, 2026(2 days remaining)
SimpleHelp Missing Authorization Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2024-1708
9.5đ Late Disclosure
ConnectWiseScreenConnect
â° Federal Deadline:May 11, 2026(6 days remaining)
ConnectWise ScreenConnect Path Traversal Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2026-32202
9.5
MicrosoftWindows
â° Federal Deadline:May 11, 2026(6 days remaining)
Microsoft Windows Protection Mechanism Failure Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2026-31431
9.5
LinuxKernel
â° Federal Deadline:May 14, 2026(9 days remaining)
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
đ¨
Critical Vulnerabilities
CVE-2026-7411
10đ
EclipseBaSyx Java Server SDK
The Eclipse BaSyx Java Server SDK is vulnerable to path traversal via the Submodel HTTP API, potentially leading to Remote Code Execution.
CVSS Base10
â
CRSSelect profile
CVE-2026-5294
9.8đ
WordPressis vulnerable
The Geeky Bot plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to achieve remote code execution via arbitrary plugin installation.
CVSS Base9.8
â
CRSSelect profile
CVE-2023-54342
9.8đđ Late Disclosure
the consoleEquinox OSGi
Eclipse Equinox OSGi versions 3.8 through 3.18 are vulnerable to unauthenticated remote code execution via the console interface's fork command.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-5722
9.8đ
WordPressis vulnerable
An authentication bypass vulnerability in MoreConvert Pro for WordPress allows unauthenticated attackers to hijack administrator accounts by manipulating email verification tokens.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-13618
9.8đ
WordPressis vulnerable
The Mentoring plugin for WordPress contains a privilege escalation vulnerability that allows unauthenticated attackers to register as administrators.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-7853
9.8đ
D-LinkDI
D-Link DI-8100 is vulnerable to a remote buffer overflow in the `sprintf` function within the HTTP Handler's `/auto_reboot.asp` script.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-7854
9.8đ
D-LinkDI
A buffer overflow vulnerability in the D-Link DI-8100 POST parameter handler allows remote attackers to execute arbitrary code via the url_rule.asp function.
CVSS Base9.8
â
CRSSelect profile
CVE-2023-54344
9.8đđ Late Disclosure
Eclipse EquinoxEquinox OSGi
Eclipse Equinox OSGi version 3.7.2 and earlier contains a remote code execution vulnerability allowing unauthenticated attackers to execute commands via the console interface.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-7834
9.8đ
EFMipTIME NAS1dual
The EFM ipTIME NAS1dual device is vulnerable to a remote stack-based buffer overflow via the `get_csrf_whites` function in `misc_main.cgi`.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-27960
9.8đ
IntelOpenCTI Platform
OpenCTI contains a privilege escalation vulnerability allowing unauthenticated attackers to query the API as any user, including the default administrator.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-7823
9.8đ
TotolinkA8000RU
A remote OS command injection vulnerability in the Totolink A8000RU allows unauthenticated attackers to execute arbitrary commands via the `setAppFilterCfg` function.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-36356
9.1đ
MeiG SmartFORGE_SLT711
The GoAhead web server on MeiG Smart FORGE_SLT711 devices allows unauthenticated remote attackers to perform OS command injection via the /action/SetRemoteAccessCfg endpoint.
CVSS Base9.1
â
CRSSelect profile
CVE-2026-40797
9.3đ
Saleswonder LLCWebinarIgnition
Saleswonder LLC's WebinarIgnition plugin for WordPress is vulnerable to Blind SQL Injection, allowing unauthenticated attackers to extract database information.
CVSS Base9.3
â
CRSSelect profile
CVE-2026-43566
9.1đ
OpenClawOpenClaw
OpenClaw contains a privilege escalation vulnerability where heartbeat owner downgrade logic incorrectly skips webhook wake events, allowing attackers to maintain elevated privileges.
CVSS Base9.1
â
CRSSelect profile
CVE-2026-43534
9.1đ
OpenClawOpenClaw
OpenClaw contains an input validation vulnerability allowing external hook metadata to be enqueued as trusted system events, leading to privilege escalation.
CVSS Base9.1
â
CRSSelect profile
â ī¸
High Priority Updates
CVE-2026-42440
7.5
ApacheOpenNLP AbstractModelReader
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReaderÂ
Versions Affected:Â
before 2
CVSS Base7.5
â
CRSSelect profile
CVE-2026-42151
7.5đ
AzureAD remote
Prometheus, an open-source monitoring system, is affected by a security vulnerability that may impact its time-series database and monitoring operations.
CVSS Base7.5
â
CRSSelect profile
CVE-2026-35228
8.7đ
OracleMCP Server
A vulnerability exists in the Oracle MCP Server Helper Tool component of Oracle Open Source Projects.
CVSS Base8.7
â
CRSSelect profile
CVE-2026-25863
7.5
WordPressplugin through
Conditional Fields for Contact Form 7 WordPress plugin through version 2
CVSS Base7.5
â
CRSSelect profile
CVE-2026-4803
7.2
WordPressis vulnerable
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1
CVSS Base7.2
â
CRSSelect profile
CVE-2026-42221
8.1
webUI is
Nginx UI is a web user interface for the Nginx web server
CVSS Base8.1
â
CRSSelect profile
CVE-2026-42222
8.1
webUI is
Nginx UI is a web user interface for the Nginx web server
CVSS Base8.1
â
CRSSelect profile
CVE-2026-5100
7.5
WordPressis vulnerable
The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4
CVSS Base7.5
â
CRSSelect profile
CVE-2026-3456
7.5
WordPressis vulnerable
The GeekyBot â Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attributekey' parameter in versions up to, and including, 1
CVSS Base7.5
â
CRSSelect profile
CVE-2026-3359
7.5
WordPressis vulnerable
The Form Maker by 10Web â Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1
CVSS Base7.5
â
CRSSelect profile
CVE-2026-4304
7.5
WordPressis vulnerable
The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions up to, and including, 3
CVSS Base7.5
â
CRSSelect profile
CVE-2026-1719
7.5
WordPressis vulnerable
The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2
CVSS Base7.5
â
CRSSelect profile
CVE-2026-43530
8.8đ
AppleOpenClaw
OpenClaw is affected by a security vulnerability requiring immediate attention to prevent potential exploitation of the software environment.
CVSS Base8.8
â
CRSSelect profile
CVE-2026-6261
8.8
WordPressis vulnerable
The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28
CVSS Base8.8
â
CRSSelect profile
CVE-2026-7412
8.6
JavaMultiple Products
In Eclipse BaSyx Java Server SDK versions prior to 2
CVSS Base8.6
â
CRSSelect profile
CVE-2026-23918
8.8
HTTPHTTP Server
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol
CVSS Base8.8
â
CRSSelect profile
CVE-2026-7791
7.8
WindowsMultiple Products
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2
CVSS Base7.8
â
CRSSelect profile
CVE-2026-32834
7.5
WordPressversion
Easy PayPal Events & Tickets plugin for WordPress version 1
CVSS Base7.5
â
CRSSelect profile
CVE-2026-41471
7.5
WordPressversions
Easy PayPal Events & Tickets plugin for WordPress versions 1
CVSS Base7.5
â
CRSSelect profile
CVE-2026-42154
7.5đ
PrometheusPrometheus
A vulnerability has been identified in Prometheus, an open-source monitoring system and time series database.
CVSS Base7.5
â
CRSSelect profile
CVE-2026-5192
7.5
WordPressis vulnerable
The Forminator Forms â Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1
CVSS Base7.5
â
CRSSelect profile
CVE-2023-54346
7.5đ Late Disclosure
WordPressPlugin Backup
WordPress Plugin Backup Migration 1
CVSS Base7.5
â
CRSSelect profile
CVE-2026-7332
7.2
WordPressis vulnerable
The LatePoint â Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, and including, 5
CVSS Base7.2
â
CRSSelect profile
CVE-2026-7448
7.2
WordPressis vulnerable
The LatePoint â Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 5
CVSS Base7.2
â
CRSSelect profile
CVE-2026-40563
8.1
Apache Atlas
Apacheendpoint that
Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas
Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings
CVSS Base8.1
â
CRSSelect profile
CVE-2026-29169
7.5
HTTPHTTP Server
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2
CVSS Base7.5
â
CRSSelect profile
CVE-2026-43869
7.3
ApacheThrift
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift
CVSS Base7.3
â
CRSSelect profile
CVE-2026-29168
7.3
HTTPHTTP Server
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data
CVSS Base7.3
â
CRSSelect profile
CVE-2026-36355
7.7đ
F5rtl819x Jungle SDK
A vulnerability exists in the Realtek rtl819x Jungle SDK affecting the rtl8192cd Wi-Fi kernel driver, which may allow for unauthorized system impact.
CVSS Base7.7
â
CRSSelect profile
CVE-2026-29004
8.1
beforeMultiple Products
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc
CVSS Base8.1
â
CRSSelect profile
CVE-2026-38751
7.2
HPMultiple Products
OpenSTAManager version 2
CVSS Base7.2
â
CRSSelect profile
CVE-2026-0073
8.8đ
Android Open Source Project (AOSP)adbd (Android Debug Bridge Daemon)
A vulnerability in the adbd_tls_verify_cert function of the Android Debug Bridge Daemon (adbd) affects certificate verification.
CVSS Base8.8
â
CRSSelect profile
CVE-2026-7841
8.8đ
GeoVisionGV-ASWeb
A remote code execution vulnerability exists in the Notification Settings of GeoVision GV-ASWeb 6.
n8n is an open source workflow automation platform
CVSS Base8.8
â
CRSSelect profile
CVE-2026-7855
8.8
D-LinkDI
A vulnerability was detected in D-Link DI-8100 16
CVSS Base8.8
â
CRSSelect profile
CVE-2026-7776
7.5
BoundaryMultiple Products
Boundary Community Edition and Boundary Enterprise (âBoundaryâ) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
CVSS Base7.5
â
CRSSelect profile
CVE-2026-7810
7.3
InforMultiple Products
A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2
CVSS Base7.3
â
CRSSelect profile
CVE-2025-47407
7.8
Signalprocessor due
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level
CVSS Base7.8
â
CRSSelect profile
CVE-2026-43532
7.7
Discordevent cover
OpenClaw versions 2026
CVSS Base7.7
â
CRSSelect profile
CVE-2026-7851
7.2
D-LinkDI
A vulnerability was identified in D-Link DI-8100 16
CVSS Base7.2
â
CRSSelect profile
CVE-2026-7856
7.2
D-LinkDI
A flaw has been found in D-Link DI-8100 16
CVSS Base7.2
â
CRSSelect profile
CVE-2026-7857
7.2
D-LinkDI
A vulnerability has been found in D-Link DI-8100 16
CVSS Base7.2
â
CRSSelect profile
CVE-2026-29514
8.8
NetBoxMultiple Products
NetBox versions 4
CVSS Base8.8
â
CRSSelect profile
CVE-2023-54345
8.8đ Late Disclosure
FrameworkMultiple Products
Frappe Framework ERPNext 13
CVSS Base8.8
â
CRSSelect profile
CVE-2023-54348
8.8đ Late Disclosure
ERPGoMultiple Products
ERPGo SaaS 3
CVSS Base8.8
â
CRSSelect profile
CVE-2026-42434
8.8
OpenClawMultiple Products
OpenClaw versions 2026
CVSS Base8.8
â
CRSSelect profile
CVE-2026-42435
8.8
versionsMultiple Products
OpenClaw versions from 2026
CVSS Base8.8
â
CRSSelect profile
CVE-2026-43569
8.8
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.8
â
CRSSelect profile
CVE-2026-43571
8.8
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.8
â
CRSSelect profile
CVE-2025-31951
8.8đ
HCLBigFix RunBookAI
HCL BigFix RunBookAI is affected by a command smuggling vulnerability due to unvalidated command input.
CVSS Base8.8
â
CRSSelect profile
CVE-2026-42079
8.6đ
PPTAgentPPTAgent
A security vulnerability exists in PPTAgent, an agentic framework for reflective PowerPoint generation.
CVSS Base8.6
â
CRSSelect profile
CVE-2026-43533
8.6
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.6
â
CRSSelect profile
CVE-2026-42439
8.5
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.5
â
CRSSelect profile
CVE-2026-43526
8.2
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.2
â
CRSSelect profile
CVE-2026-42075
8.1
evolvingMultiple Products
Evolver is a GEP-powered self-evolving engine for AI agents
CVSS Base8.1
â
CRSSelect profile
CVE-2026-42084
8.1đ
OpenC3COSMOS
A vulnerability has been identified in OpenC3 COSMOS, a system used for command and control of embedded systems.
CVSS Base8.1
â
CRSSelect profile
CVE-2025-67796
8.1
RdiffwebMultiple Products
IKUS Rdiffweb before 2
CVSS Base8.1
â
CRSSelect profile
CVE-2026-44331
8.1
ProFTPDMultiple Products
In ProFTPD through 1
CVSS Base8.1
â
CRSSelect profile
CVE-2026-36365
7.8
includingMultiple Products
An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions
CVSS Base7.8
â
CRSSelect profile
CVE-2025-47405
7.8
MemoryMultiple Products
Memory corruption when processing camera sensor input/output control codes with invalid output buffers
CVSS Base7.8
â
CRSSelect profile
CVE-2025-47408
7.8
MemoryMultiple Products
Memory corruption when another driver calls an IOCTL with invalid input/output buffer
CVSS Base7.8
â
CRSSelect profile
CVE-2026-24082
7.8
MemoryMultiple Products
Memory Corruption when copying data from a freed source while executing performance counter deselect operation
CVSS Base7.8
â
CRSSelect profile
CVE-2026-42436
7.7
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base7.7
â
CRSSelect profile
CVE-2026-42438
7.7
OpenClawMultiple Products
OpenClaw versions 2026
CVSS Base7.7
â
CRSSelect profile
CVE-2026-43527
7.7
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base7.7
â
CRSSelect profile
CVE-2026-43573
7.7
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base7.7
â
CRSSelect profile
CVE-2026-42997
7.7
IronicMultiple Products
An issue was discovered in idrac in OpenStack Ironic before 35
CVSS Base7.7
â
CRSSelect profile
CVE-2026-37461
7.5đ
FRRoutingFRRouting (FRR)
An out-of-bounds read vulnerability exists in the ParseIP6Extended function of the FRRouting (FRR) BGP component.
CVSS Base7.5
â
CRSSelect profile
CVE-2026-37459
7.5đ
FRRoutingFRRouting (FRR)
An integer underflow vulnerability exists in the FRRouting (FRR) stable/10 release.
CVSS Base7.5
â
CRSSelect profile
CVE-2026-6321
7.5đ
fast-urifast-uri
A vulnerability in the fast-uri library causes improper normalization of percent-encoded path separators and dot segments.
CVSS Base7.5
â
CRSSelect profile
CVE-2026-7768
7.5đ
Fastify@fastify/accepts-serializer
The @fastify/accepts-serializer package fails to limit the size or evict cached serializer-selection results based on the request Accept header.
CVSS Base7.5
â
CRSSelect profile
CVE-2026-44028
7.5
NixMultiple Products
An issue was discovered in Nix before 2
CVSS Base7.5
â
CRSSelect profile
CVE-2026-6322
7.5đ
Fastifyfast-uri
The fast-uri library improperly handles percent-encoded authority delimiters during normalization, leading to potential injection or parsing errors during re-serialization.
CVSS Base7.5
â
CRSSelect profile
CVE-2023-54347
7.5đ Late Disclosure
OpenEMRMultiple Products
OpenEMR 7
CVSS Base7.5
â
CRSSelect profile
CVE-2026-42437
7.5
OpenClawMultiple Products
OpenClaw versions 2026
CVSS Base7.5
â
CRSSelect profile
CVE-2026-6918
7.5đ
Eclipse FoundationOpenJ9
A vulnerability in Eclipse OpenJ9 may lead to undefined behavior or potential system instability.
CVSS Base7.5
â
CRSSelect profile
CVE-2025-71251
7.5đ
UnknownIMS (IP Multimedia Subsystem)
A vulnerability in the IP Multimedia Subsystem (IMS) allows for potential system crashes due to improper input validation.
CVSS Base7.5
â
CRSSelect profile
CVE-2025-71252
7.5đ
UnknownModem IMS
A vulnerability in the Modem IMS component allows for potential exploitation due to improper input validation.
CVSS Base7.5
â
CRSSelect profile
CVE-2025-71253
7.5
UnknownMultiple Products
In Modem IMS, there is a possible improper input validation
CVSS Base7.5
â
CRSSelect profile
CVE-2025-71254
7.5
UnknownMultiple Products
In Modem IMS, there is a possible improper input validation
CVSS Base7.5
â
CRSSelect profile
CVE-2025-71255
7.5
UnknownMultiple Products
In Modem IMS, there is a possible improper input validation
CVSS Base7.5
â
CRSSelect profile
CVE-2025-71256
7.5
UnknownMultiple Products
In nr modem, there is a possible improper input validation
CVSS Base7.5
â
CRSSelect profile
CVE-2026-7784
7.3
InforMultiple Products
A vulnerability has been found in RTGS2017 NagaAgent up to 5
CVSS Base7.3
â
CRSSelect profile
CVE-2026-7785
7.3
InforMultiple Products
A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89
CVSS Base7.3
â
CRSSelect profile
CVE-2026-7788
7.3
InforMultiple Products
A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0
CVSS Base7.3
â
CRSSelect profile
CVE-2026-7811
7.3
foundMultiple Products
A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8
CVSS Base7.3
â
CRSSelect profile
CVE-2026-7812
7.3
foundMultiple Products
A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8
CVSS Base7.3
â
CRSSelect profile
CVE-2026-43531
7.3
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base7.3
â
CRSSelect profile
CVE-2026-7833
7.2
UnknownMultiple Products
A weakness has been identified in EFM ipTIME C200 up to 1
CVSS Base7.2
â
CRSSelect profile
CVE-2026-43616
7.1
priorMultiple Products
Detect-It-Easy prior to 3
CVSS Base7.1
â
CRSSelect profile
CVE-2026-7832
7
AdvancedMultiple Products
A security flaw has been discovered in IObit Advanced SystemCare 19