| OpenEMR 7.0.2 - Arbitrary File Read | multiple | webapps | | — | 2026-06-08 | — |
| WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection | multiple | webapps | | — | 2026-06-05 | — |
| WordPress OrderConvo 14 - Path Traversal | multiple | webapps | | — | 2026-06-01 | — |
| Drupal Core 10.5.5 - Error-Based SQL Injection | php | webapps | | 9.8 | 2026-06-01 | — |
| YAMCS yamcs-core 5.12.7 - No Rate Limiting | multiple | webapps | | — | 2026-05-30 | — |
| YAMCS yamcs-core 5.12.7 - LDAP Injection | multiple | webapps | | 4.3 | 2026-05-30 | — |
| Notepad++ 8.9.6 - Arbitrary Code Execution | windows | remote | | — | 2026-05-30 | — |
| YAMCS yamcs-core 5.12.7 - User Enumeration | multiple | webapps | | — | 2026-05-30 | — |
| CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated) | multiple | webapps | | 6.1 | 2026-05-29 | — |
| Prodigy Commerce 3.3.0 - Local File Inclusion | multiple | webapps | | — | 2026-05-29 | — |
| strongSwan 5.9.13 - DoS | multiple | dos | | — | 2026-05-29 | — |
| Microsoft - NTLMv2 Hash Capture | windows | remote | | 4.3 | 2026-05-29 | — |
| ZTE H298A / H108N - Unauthenticated Credential Exposure | multiple | local | | 7.5 | 2026-05-29 | — |
| Linux Kernel - Local Privilege Escalation | linux | local | | 8.8 | 2026-05-29 | — |
| ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion | multiple | local | | 7.5 | 2026-05-29 | — |
| Wing FTP Server 8.1.3 - Authenticated Remote Code Execution | multiple | remote | | 7.2 | 2026-05-29 | — |
| Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution | multiple | webapps | | — | 2026-05-29 | — |
| ZTE Routers - Unauthenticated Denial of Service | multiple | local | | 7.5 | 2026-05-29 | — |
| strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow | multiple | remote | | — | 2026-05-29 | — |
| MikroORM 7.0.13 - SQL Injection | multiple | webapps | | 7.6 | 2026-05-29 | — |
| Langflow 1.3.0 - Remote Code Execution | multiple | webapps | | — | 2026-05-29 | — |
| MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution | php | webapps | | — | 2026-05-29 | — |
| ZTE ZXHN H188A V6 - Authentication Bypass | multiple | local | | 7.1 | 2026-05-29 | — |
| Casdoor 3.54.1 - Arbitrary File Write via Path Traversal | go | webapps | | 5.9 | 2026-05-27 | — |
| MeiG Smart FORGE_SLT711 - OS Command Injection | linux | hardware | | — | 2026-05-27 | — |
| OpenCATS 0.9.7.4 - SQL Injection | multiple | webapps | — | — | 2026-05-27 | — |
| Realtek rtl819x - Local Privilege | linux | local | | — | 2026-05-27 | — |
| Linux Kernel - Local Privilege Escalation | linux | local | | 8.8 | 2026-05-27 | — |
| EspoCRM 9.3.3 - SSRF | multiple | webapps | | — | 2026-05-27 | — |
| scramble - Remote Code Execution | php | webapps | | 9.4 | 2026-05-27 | — |
| Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover | multiple | webapps | | — | 2026-05-26 | — |
| Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service | multiple | webapps | | — | 2026-05-26 | — |
| cPanel - CRLF Injection | php | webapps | | — | 2026-05-26 | — |
| Grav CMS 2.0.0-beta.2 - Remote Code Execution | php | webapps | | 9.1 | 2026-05-26 | — |
| D-Link DSL2600U - 'rom-0' Admin Password Disclosure | multiple | hardware | — | — | 2026-05-26 | — |
| Linux Kernel 6.8 - Local Privilege Escalation | linux | local | — | — | 2026-05-26 | — |
| BookStack 25.12.1 - Denial of Service | multiple | webapps | — | — | 2026-05-21 | — |
| Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path | windows | local | — | — | 2026-05-21 | — |
| Cockpit 359 - RCE | multiple | webapps | | — | 2026-05-21 | — |
| solaredge - (CSRF-OOB-Injection) | multiple | webapps | — | — | 2026-05-21 | — |
| FUXA 1.2.9 - RCE | multiple | webapps | | — | 2026-05-21 | — |
| Windows Snipping Tool - NTLMv2 Hash Hijack | windows | local | | — | 2026-05-15 | — |
| Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing | windows | local | — | — | 2026-05-15 | — |
| Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution | windows | local | — | — | 2026-05-15 | — |
| Apache HertzBeat 1.8.0 - Remote Code Execution | multiple | webapps | — | — | 2026-05-14 | — |
| PJPROJECT 2.16 - Heap Bufferoverflow | multiple | webapps | | — | 2026-05-14 | — |
| ePati Antikor NGFW 2.0.1301 - Authentication Bypass | multiple | webapps | | 9.8 | 2026-05-14 | — |
| WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI | multiple | webapps | | — | 2026-05-14 | — |
| glances 4.5.2 - command injection | multiple | webapps | | — | 2026-05-13 | — |
| Flowise < 3.0.5 - Missing Authentication for Critical Function | typescript | webapps | | — | 2026-05-13 | — |
| coreruleset 4.21.0 - Firewall Bypass | multiple | webapps | | — | 2026-05-13 | — |
| Ninja Forms Uploads - Unauthenticated PHP File Upload | multiple | webapps | | — | 2026-05-13 | — |
| NocoBase 2.0.27 - VM Sandbox Escape | multiple | local | | — | 2026-05-07 | — |
| telnetd 2.7 - Buffer Overflow | multiple | remote | | — | 2026-05-07 | — |
| LuaJIT 2.1.1774638290 - Arbitrary Code Execution | multiple | webapps | — | — | 2026-05-07 | — |
| Ghost CMS 6.19.0 - SQLi | multiple | webapps | | 9.4 | 2026-05-07 | — |
| ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF) | multiple | webapps | | — | 2026-05-07 | — |
| Bludit CMS 3.18.4 - RCE | multiple | webapps | | — | 2026-05-07 | — |
| Linux nf_tables 6.19.3 - Local Privilege Escalation | linux | local | | 7.8 | 2026-05-04 | — |
| Windows 11 24H2 - Local Privilege Escalation | windows | local | | — | 2026-05-04 | — |
| Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation | linux | local | | — | 2026-05-04 | — |
| MindsDB 25.9.1.1 - Path Traversal | multiple | webapps | | — | 2026-05-04 | — |
| Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH) | multiple | webapps | | — | 2026-05-04 | — |
| Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE) | multiple | hardware | | — | 2026-05-04 | — |
| Google Chrome 145.0.7632.75 - CSSFontFeatureValuesMap | multiple | local | | — | 2026-04-30 | — |
| Python-Multipart 0.0.22 - Path Traversal | python | webapps | | — | 2026-04-30 | — |
| Camaleon CMS v2.9.0 - Path Traversal | multiple | webapps | | — | 2026-04-30 | — |
| Repetier-Server 1.4.10 - Path Traversal | multiple | webapps | | — | 2026-04-30 | — |
| deephas 1.0.7 - Prototype Pollution | multiple | webapps | | — | 2026-04-30 | — |
| Windows 11 23H2 - Denial of Service (DoS) | windows | local | | — | 2026-04-30 | — |
| BusyBox 1.37.0 - Path Traversal | multiple | webapps | | 7.0 | 2026-04-30 | — |
| JUNG Smart Visu Server 1.1.1050 - Dos | multiple | webapps | | — | 2026-04-30 | — |
| Erugo 0.2.14 - Remote Code Execution (RCE) | multiple | webapps | | — | 2026-04-30 | — |
| FUXA 1.2.8 - Authentication Bypass + RCE Exploit | multiple | webapps | | — | 2026-04-30 | — |
| HUSTOJ Zip-Slip v26.01.24 - RCE | multiple | webapps | | — | 2026-04-30 | — |
| SumatraPDF 3.5.2 - Remote Code Execution | multiple | webapps | | — | 2026-04-30 | — |
| SUSE Manager 4.3.15 - Code Execution | multiple | webapps | | — | 2026-04-30 | — |
| Windows 11 25H2 - Heap Overflow | windows | local | | — | 2026-04-30 | — |
| Js2Py 0.74 - RCE | multiple | webapps | | — | 2026-04-30 | — |
| Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection | multiple | webapps | — | — | 2026-04-30 | — |
| Frigate NVR 0.16.3 - Remote Code Execution | multiple | webapps | | — | 2026-04-30 | — |
| NiceGUI 3.6.1 - Path Traversal | multiple | webapps | | — | 2026-04-30 | — |
| Atlona ATOMERX21 - Authenticated Command Injection | multiple | local | | — | 2026-04-29 | — |
| GeographicLib v2.5.1 - stack buffer overflow | multiple | webapps | | — | 2026-04-29 | — |
| GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation | linux | local | | — | 2026-04-29 | — |
| LangChain Core 1.2.4 - SSTI/RCE | multiple | webapps | | — | 2026-04-29 | — |
| phpMyFAQ 4.0.16 - Improper Authorization | php | webapps | | — | 2026-04-29 | — |
| Craft CMS 5.6.16 - RCE | multiple | webapps | | — | 2026-04-29 | — |
| Fedora - Local Privilege Escalation | linux | local | | — | 2026-04-29 | — |
| FacturaScripts 2025.43 - XSS | multiple | webapps | | — | 2026-04-29 | — |
| JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution | multiple | webapps | — | — | 2026-04-29 | — |
| HAX CMS 24.x - Stored Cross-Site Scripting (XSS) | multiple | webapps | | — | 2026-04-29 | — |
| OpenKM 6.3.12 - Multiple | multiple | webapps | — | — | 2026-04-29 | — |
| Xibo CMS 4.3.0 - RCE via SSTI | multiple | webapps | | — | 2026-04-29 | — |
| GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE) | multiple | webapps | | — | 2026-04-29 | — |
| OpenWrt 23.05 - Authenticated Remote Code Execution (RCE) | multiple | local | — | — | 2026-04-29 | — |
| AVAST Antivirus 25.11 - Unquoted Service Path | windows | local | — | — | 2026-04-22 | — |
| Throttlestop Kernel Driver - Kernel Out-of-Bounds Write Privilege Escalation | windows | local | | — | 2026-04-22 | — |
| WordPress Plugin 5.2.0 - Broken Access Control | multiple | webapps | | — | 2026-04-22 | — |
| D-Link DIR-650IN - Authenticated Command Injection | multiple | webapps | — | — | 2026-04-10 | — |