Notable CVEs
All 2413 profiled CVEs (incl. severe-but-obscure long tail). Show notable only
| CVE | Product / weakness | CVSS | EPSS | Signal |
|---|---|---|---|---|
| CVE-2026-34910 | — A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | 10.0 | 78.6% |
KEV
|
| CVE-2026-34908 | — A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | 10.0 | 2.45% |
KEV
|
| CVE-2026-34909 | — A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an unde | 10.0 | 2.27% |
KEV
|
| CVE-2026-15409 | SonicWall SMA1000 Appliance Work Place Server-Side Request Forgery (SSRF) | 10.0 | 1.40% |
KEV
3 PoC
|
| CVE-2026-48558 | SimpleHelp OIDC authentication bypass via unsigned JWT / improper cryptographic signature verification | 10.0 | 1.22% |
KEV
1 PoC
|
| CVE-2026-72898 | — Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. | 10.0 | 1.07% |
KEV
|
| CVE-2026-16812 | — VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may | 10.0 | 0.98% |
KEV
|
| CVE-2021-30116 | — Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downl | 10.0 | — |
KEV
|
| CVE-2021-22893 | — Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect S | 10.0 | — |
KEV
|
| CVE-2021-44228 | — Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker control | 10.0 | — |
KEV
|
| CVE-2024-51378 | — getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus o | 10.0 | — |
KEV
|
| CVE-2025-55182 | — A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react- | 10.0 | — |
KEV
|
| CVE-2025-10035 | — A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, | 10.0 | — |
KEV
|
| CVE-2025-31324 | — SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely har | 10.0 | — |
KEV
|
| CVE-2024-51567 | — upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatu | 10.0 | — |
KEV
|
| CVE-2021-22205 | — An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote comm | 10.0 | — |
KEV
|
| CVE-2026-10520 | Ivanti Sentry OS Command Injection RCE | 10.0 | — |
KEV
5 PoC
|
| CVE-2025-20333 | — A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote a | 9.9 | — |
KEV
|
| CVE-2021-42237 | Sitecore Experience Platform (XP) Insecure deserialization unauthenticated RCE | 9.8 | 97.9% |
KEV
12 PoC
|
| CVE-2024-21413 | — Microsoft Outlook Remote Code Execution Vulnerability | 9.8 | 94.7% |
KEV
|
| CVE-2026-9082 | — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from 8.9.0 before 10.4.1 | 9.8 | 84.6% |
KEV
|
| CVE-2026-42208 | LiteLLM SQL Injection via unsanitized Authorization header in proxy API key check | 9.8 | 83.5% |
KEV
6 PoC
|
| CVE-2026-56290 | Page Builder CK (Joomla extension) Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE) | 9.8 | 83.3% |
KEV
3 PoC
|
| CVE-2026-56291 | Balbooa Forms (Joomla extension) Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE) | 9.8 | 76.1% |
KEV
1 PoC
|
| CVE-2026-50522 | Microsoft Office SharePoint Deserialization of untrusted data RCE | 9.8 | 21.0% |
KEV
1 PoC
|
| CVE-2026-48172 | — LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonap | 9.8 | 18.9% |
KEV
|
| CVE-2025-10585 | Google Chrome V8 JavaScript Engine Type confusion heap corruption RCE | 9.8 | 5.42% |
KEV
14 PoC
|
| CVE-2017-11357 | — Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co | 9.8 | — |
KEV
|
| CVE-2016-1019 | — Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild | 9.8 | — |
KEV
|
| CVE-2012-0507 | — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to af | 9.8 | — |
KEV
|
| CVE-2010-2861 | — Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/adm | 9.8 | — |
KEV
|
| CVE-2018-20753 | — Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attacker | 9.8 | — |
KEV
|
| CVE-2017-18362 | — ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers | 9.8 | — |
KEV
|
| CVE-2018-19323 | — The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write | 9.8 | — |
KEV
|
| CVE-2018-7602 | — A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result | 9.8 | — |
KEV
|
| CVE-2018-11138 | — The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system. | 9.8 | — |
KEV
|
| CVE-2017-12149 | — In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes | 9.8 | — |
KEV
|
| CVE-2021-21985 | — The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malic | 9.8 | — |
KEV
|
| CVE-2021-20021 | — A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | 9.8 | — |
KEV
|
| CVE-2021-21972 | — The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with | 9.8 | — |
KEV
|
| CVE-2021-20016 | — A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. Th | 9.8 | — |
KEV
|
| CVE-2020-3992 | — OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the mana | 9.8 | — |
KEV
|
| CVE-2019-11634 | — Citrix Workspace App before 1904 for Windows has Incorrect Access Control. | 9.8 | — |
KEV
|
| CVE-2019-2725 | — Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable v | 9.8 | — |
KEV
|
| CVE-2024-23692 | — Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary comma | 9.8 | — |
KEV
|
| CVE-2021-38647 | — Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 9.8 | — |
KEV
|
| CVE-2022-40684 | — An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 | 9.8 | — |
KEV
|
| CVE-2022-29499 | — The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA. | 9.8 | — |
KEV
|
| CVE-2026-63077 | — In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | 9.8 | — |
KEV
|
| CVE-2024-55591 | — An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 | 9.8 | — |
KEV
|
| CVE-2024-55956 | — In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by lever | 9.8 | — |
KEV
|
| CVE-2023-35078 | — An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. | 9.8 | — |
KEV
|
| CVE-2023-3519 | — Unauthenticated remote code execution | 9.8 | — |
KEV
|
| CVE-2026-24423 | — SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the mal | 9.8 | — |
KEV
|
| CVE-2026-23760 | — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails t | 9.8 | — |
KEV
|
| CVE-2025-61882 | — Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable | 9.8 | — |
KEV
|
| CVE-2025-53770 | — Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsoft is aware that an exploit for CVE-2025-53770 exist | 9.8 | — |
KEV
|
| CVE-2025-23006 | — Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditi | 9.8 | — |
KEV
|
| CVE-2024-9680 | — An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This | 9.8 | — |
KEV
|
| CVE-2024-21762 | — A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions | 9.8 | — |
KEV
|
| CVE-2022-37042 | — Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an att | 9.8 | — |
KEV
|
| CVE-2021-44529 | — A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). | 9.8 | — |
KEV
|
| CVE-2019-15107 | — An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. | 9.8 | — |
KEV
|
| CVE-2012-4681 | — Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses Se | 9.8 | — |
KEV
|
| CVE-2012-1723 | — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows re | 9.8 | — |
KEV
|
| CVE-2012-1710 | — Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via un | 9.8 | — |
KEV
|
| CVE-2024-50623 | — In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. | 9.8 | — |
KEV
|
| CVE-2023-47246 | — In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. | 9.8 | — |
KEV
|
| CVE-2023-27997 | — A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and b | 9.8 | — |
KEV
|
| CVE-2022-47966 | — Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the | 9.8 | — |
KEV
|
| CVE-2026-35616 | — A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | 9.8 | — |
KEV
|
| CVE-2026-9198 | — IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe | 9.8 | — |
KEV
|
| CVE-2026-45247 | — Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a | 9.8 | — |
KEV
|
| CVE-2026-16232 | — An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full | 9.8 | — |
KEV
|
| CVE-2026-48907 | — A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | 9.8 | — |
KEV
|
| CVE-2026-63030 | — WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), coul | 9.8 | — |
KEV
|
| CVE-2026-0770 | — Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins | 9.8 | — |
KEV
|
| CVE-2026-46817 | — Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow | 9.8 | — |
KEV
|
| CVE-2026-39808 | — A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code | 9.8 | — |
KEV
|
| CVE-2026-58644 | Microsoft Office SharePoint Deserialization of untrusted data RCE | 9.8 | — |
KEV
1 PoC
|
| CVE-2025-3248 | Langflow Unauthenticated Remote Code Execution via Python code injection (exec) | 9.8 | — |
KEV
80 PoC
|
| CVE-2024-11680 | ProjectSend Improper Authentication / Authentication Bypass leading to Unauthenticated RCE | 9.8 | — |
KEV
17 PoC
|
| CVE-2026-48939 | iCagenda extension for Joomla Arbitrary File Upload leading to Remote Code Execution (PHP code upload and execution) | 9.8 | — |
KEV
2 PoC
|
| CVE-2026-12569 | PTC Windchill PDMLink / PTC FlexPLM Deserialization of untrusted data RCE (CWE-502 / CWE-20) | 9.8 | — |
KEV
|
| CVE-2018-1273 | Spring Data Commons SpEL injection / remote code execution via property binder | 9.8 | — |
KEV
42 PoC
|
| CVE-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function (CWE-306) - Unauthenticated arbitrary file create/truncate via PostgreSQL sidecar service endpoint, leading to pre-auth RCE | 9.8 | — |
KEV
3 PoC
|
| CVE-2026-35273 | PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover via HTTP | 9.8 | — |
KEV
3 PoC
|
| CVE-2026-25089 | Fortinet FortiSandbox Unauthenticated OS Command Injection (CWE-78) | 9.8 | — |
KEV
2 PoC
|
| CVE-2023-41265 | — An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and | 9.6 | — |
KEV
|
| CVE-2026-8037 | Progress Kemp LoadMaster OS Command Injection RCE (unauthenticated, pre-auth) via API command endpoints | 9.6 | — |
KEV
2 PoC
|
| CVE-2023-4966 | — Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | 9.4 | — |
KEV
|
| CVE-2021-26855 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 9.1 | — |
KEV
|
| CVE-2025-42999 | — SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confi | 9.1 | — |
KEV
|
| CVE-2021-34473 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 9.1 | — |
KEV
|
| CVE-2024-41713 | — A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to in | 9.1 | — |
KEV
|
| CVE-2024-21887 | — A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests | 9.1 | — |
KEV
|
| CVE-2021-34523 | — Microsoft Exchange Server Elevation of Privilege Vulnerability | 9.0 | — |
KEV
|
| CVE-2025-22457 | — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenti | 9.0 | — |
KEV
|
| CVE-2025-0282 | — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remot | 9.0 | — |
KEV
|
| CVE-2021-40438 | — A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | 9.0 | — |
KEV
|
| CVE-2026-34197 | Apache ActiveMQ Authenticated RCE via Jolokia JMX-HTTP bridge — Code Injection through Spring XML remote application context loading (CWE-20, CWE-94, CWE-78) | 8.8 | 97.2% |
KEV
14 PoC
|
| CVE-2022-41080 | — Microsoft Exchange Server Elevation of Privilege Vulnerability | 8.8 | 77.3% |
KEV
|
| CVE-2021-25298 | Nagios XI OS Command Injection (CWE-78) | 8.8 | 75.2% |
KEV
2 PoC
|
| CVE-2021-25296 | Nagios XI OS Command Injection | 8.8 | 71.5% |
KEV
5 PoC
|
| CVE-2021-25297 | Nagios XI OS Command Injection (CWE-78) | 8.8 | 58.7% |
KEV
2 PoC
|
| CVE-2025-13223 | Google Chrome V8 JavaScript Engine Type Confusion heap corruption RCE | 8.8 | 4.83% |
KEV
|
| CVE-2020-0618 | — A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vu | 8.8 | — |
KEV
|
| CVE-2017-0145 | — The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; a | 8.8 | — |
KEV
|
| CVE-2017-0144 | — The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; a | 8.8 | — |
KEV
|
| CVE-2016-0034 | — Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) | 8.8 | — |
KEV
|
| CVE-2021-26411 | — Internet Explorer Memory Corruption Vulnerability | 8.8 | — |
KEV
|
| CVE-2025-8088 | — A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild | 8.8 | — |
KEV
|
| CVE-2022-2294 | — Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 | — |
KEV
|
| CVE-2026-5281 | — Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security | 8.8 | — |
KEV
|
| CVE-2026-11645 | — Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H | 8.8 | — |
KEV
|
| CVE-2025-34291 | langflow CORS misconfiguration leading to credential theft, account takeover, and remote code execution | 8.8 | — |
KEV
1 PoC
|
| CVE-2026-45659 | Microsoft Office SharePoint Deserialization of untrusted data RCE (CWE-502) | 8.8 | — |
KEV
5 PoC
|
| CVE-2026-42271 | LiteLLM Command Injection / Arbitrary OS Command Execution (CWE-77, CWE-78) via MCP stdio transport subprocess spawning | 8.8 | — |
KEV
3 PoC
|
| CVE-2025-31277 | WebKit Buffer overflow / memory corruption via maliciously crafted web content (CWE-119, CWE-120) | 8.8 | — |
KEV
1 PoC
|
| CVE-2026-20349 | — A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthe | 8.6 | 0.97% |
KEV
|
| CVE-2024-20353 | — A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta | 8.6 | — |
KEV
|
| CVE-2024-24919 | — Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Secu | 8.6 | — |
KEV
|
| CVE-2026-20230 | Cisco Unified Communications Manager (Unified CM / Unified CM SME) Server-Side Request Forgery (SSRF) with privilege escalation to root | 8.6 | — |
KEV
3 PoC
|
| CVE-2026-54420 | LiteSpeed cPanel Plugin / LiteSpeed WHM Plugin Symlink follow / CWE-61 UNIX symbolic link following leading to privilege escalation or path escape on shared hosting (CloudLinux/CageFS bypass) | 8.5 | — |
KEV
4 PoC
|
| CVE-2023-41266 | — A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2 | 8.2 | — |
KEV
|
| CVE-2025-22225 | — VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. | 8.2 | — |
KEV
|
| CVE-2024-21893 | — A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access cert | 8.2 | — |
KEV
|
| CVE-2023-46805 | — An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks. | 8.2 | — |
KEV
|
| CVE-2026-18577 | — An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | 8.1 | 2.53% |
KEV
|
| CVE-2025-24472 | — An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote | 8.1 | — |
KEV
|
| CVE-2017-12615 | — When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to th | 8.1 | — |
KEV
|
| CVE-2026-42897 | Microsoft Exchange Server Cross-Site Scripting (XSS) leading to spoofing | 8.1 | — |
KEV
1 PoC
|
| CVE-2026-31431 | Linux kernel crypto algif_aead kernel local privilege escalation / improper resource transfer (out-of-place vs in-place crypto buffer operation) | 7.8 | 94.5% |
KEV
90 PoC
|
| CVE-2021-4034 | — A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users accord | 7.8 | — |
KEV
|
| CVE-2013-0074 | — Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a cra | 7.8 | — |
KEV
|
| CVE-2010-0188 | — Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unk | 7.8 | — |
KEV
|
| CVE-2018-20250 | — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with s | 7.8 | — |
KEV
|
| CVE-2018-15982 | — Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | 7.8 | — |
KEV
|
| CVE-2018-19322 | — The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to re | 7.8 | — |
KEV
|
| CVE-2018-19321 | — The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to re | 7.8 | — |
KEV
|
| CVE-2018-19320 | — The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality | 7.8 | — |
KEV
|
| CVE-2021-27065 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 7.8 | — |
KEV
|
| CVE-2021-26858 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 7.8 | — |
KEV
|
| CVE-2021-26857 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 7.8 | — |
KEV
|
| CVE-2020-3433 | — A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. T | 7.8 | — |
KEV
|
| CVE-2021-38648 | — Open Management Infrastructure Elevation of Privilege Vulnerability | 7.8 | — |
KEV
|
| CVE-2021-38646 | — Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 7.8 | — |
KEV
|
| CVE-2021-38645 | — Open Management Infrastructure Elevation of Privilege Vulnerability | 7.8 | — |
KEV
|
| CVE-2024-1086 | — A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The nft_verdict_init() function allows positive values as | 7.8 | — |
KEV
|
| CVE-2023-38831 | — RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file ( | 7.8 | — |
KEV
|
| CVE-2015-2291 | — (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code | 7.8 | — |
KEV
|
| CVE-2025-38352 | — In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
If an exiting non-autoreaping task has alre | 7.8 | — |
KEV
|
| CVE-2026-33825 | — Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 7.8 | — |
KEV
|
| CVE-2026-41091 | — Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 7.8 | — |
KEV
|
| CVE-2026-20245 | — A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBo | 7.8 | — |
KEV
|
| CVE-2023-38950 | ZKTeco BioTime Path Traversal (Unauthenticated Arbitrary File Read) | 7.5 | 84.9% |
KEV
2 PoC
|
| CVE-2026-34486 | — Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53 | 7.5 | 81.2% |
KEV
|
| CVE-2023-38180 | — .NET and Visual Studio Denial of Service Vulnerability | 7.5 | 14.8% |
KEV
|
| CVE-2010-1428 | — The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for | 7.5 | — |
KEV
|
| CVE-2017-10271 | — Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2 | 7.5 | — |
KEV
|
| CVE-2021-21975 | — Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server | 7.5 | — |
KEV
|
| CVE-2019-0752 | — A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is | 7.5 | — |
KEV
|
| CVE-2023-44487 | — The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | 7.5 | — |
KEV
|
| CVE-2020-3452 | — A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to c | 7.5 | — |
KEV
|
| CVE-2020-3259 | — A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to r | 7.5 | — |
KEV
|
| CVE-2018-0296 | — A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a d | 7.5 | — |
KEV
|
| CVE-2025-61884 | — Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows u | 7.5 | — |
KEV
|
| CVE-2025-5777 | — Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | 7.5 | — |
KEV
|
| CVE-2024-57727 | — SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHe | 7.5 | — |
KEV
|
| CVE-2022-30333 | — RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRA | 7.5 | — |
KEV
|
| CVE-2022-27924 | — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an o | 7.5 | — |
KEV
|
| CVE-2026-28318 | — SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure custom | 7.5 | — |
KEV
|
| CVE-2026-18556 | — Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1. | 7.4 | — |
KEV
|
| CVE-2024-38226 | — Microsoft Publisher Security Feature Bypass Vulnerability | 7.3 | 2.67% |
KEV
|
| CVE-2021-33766 | — Microsoft Exchange Server Information Disclosure Vulnerability | 7.3 | — |
KEV
|
| CVE-2026-6973 | Ivanti EPMM (Endpoint Manager Mobile) Improper Input Validation leading to Remote Code Execution | 7.2 | 4.79% |
KEV
|
| CVE-2026-15410 | SonicWall SMA1000 Appliance Management Console (AMC) Post-authentication Code Injection RCE (OS Command Execution) | 7.2 | 1.65% |
KEV
1 PoC
|
| CVE-2021-20022 | — SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | 7.2 | — |
KEV
|
| CVE-2021-31196 | — Microsoft Exchange Server Remote Code Execution Vulnerability | 7.2 | — |
KEV
|
| CVE-2023-0669 | — Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled ob | 7.2 | — |
KEV
|
| CVE-2022-27925 | — Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to up | 7.2 | — |
KEV
|
| CVE-2021-43890 | — We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially c | 7.1 | — |
KEV
|
| CVE-2021-38649 | — Open Management Infrastructure Elevation of Privilege Vulnerability | 7.0 | — |
KEV
|
| CVE-2026-34926 | — A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents | 6.7 | 12.7% |
KEV
|
| CVE-2016-3351 | — Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | 6.5 | — |
KEV
|
| CVE-2020-3153 | — A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories wi | 6.5 | — |
KEV
|
| CVE-2025-20362 | — Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and | 6.5 | — |
KEV
|
| CVE-2025-49706 | — Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 6.5 | — |
KEV
|
| CVE-2009-3960 | — Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8. | 6.5 | — |
KEV
|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager (SD-WAN vManage) Path Traversal / Arbitrary File Write (CWE-22) | 6.5 | — |
KEV
2 PoC
|
| CVE-2018-6882 | — Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers | 6.1 | — |
KEV
|
| CVE-2020-3580 | — Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atta | 6.1 | — |
KEV
|
| CVE-2022-24682 | — An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML | 6.1 | — |
KEV
|
| CVE-2024-20359 | — A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower T | 6.0 | — |
KEV
|
| CVE-2026-60137 | — WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme pas | 5.9 | — |
KEV
|
| CVE-2024-20481 | — A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote at | 5.8 | — |
KEV
|
| CVE-2013-0431 | — Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbo | 5.3 | — |
KEV
|
| CVE-2010-0738 | — The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for th | 5.3 | — |
KEV
|
| CVE-2026-20316 | — A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac | 5.3 | — |
KEV
|
| CVE-2023-20269 | — A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t | 5.0 | — |
KEV
|
| CVE-2021-20023 | — SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | 4.9 | — |
KEV
|
| CVE-2018-13374 | — A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGat | 4.3 | — |
KEV
|
| CVE-2026-45498 | — Microsoft Defender Denial of Service Vulnerability | 4.0 | 63.1% |
KEV
|
| CVE-2024-55550 | — Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allo | 2.7 | — |
KEV
|
| CVE-2026-26216 | crawl4ai Remote Code Execution via exec() with unrestricted __import__ builtin in Docker API hooks parameter | 10.0 | 1.59% | |
| CVE-2026-49261 | MariaDB Server OS Command Injection (CWE-78) via wsrep_notify_cmd joiner node name | 10.0 | 1.58% | |
| CVE-2024-42467 | — openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu ad | 10.0 | 1.03% | |
| CVE-2026-43997 | vm2 Sandbox Escape via Host Object Access (Code Injection) | 10.0 | 0.98% | 1 PoC
|
| CVE-2026-57106 | — Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | 10.0 | 0.92% | |
| CVE-2026-56163 | — Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 10.0 | 0.92% | |
| CVE-2026-45618 | — LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue. | 10.0 | 0.85% | |
| CVE-2026-20223 | Cisco Secure Workload Missing Authentication for Critical Function (CWE-306) - Unauthenticated REST API Access leading to privilege escalation to Site Admin | 10.0 | 0.83% | 1 PoC
|
| CVE-2026-44005 | vm2 Prototype Pollution via Sandbox Escape / Code Injection | 10.0 | 0.83% | |
| CVE-2026-44006 | vm2 Sandbox Escape via Prototype Manipulation (CWE-94, CWE-914) | 10.0 | 0.81% | |
| CVE-2026-54159 | — PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value o | 10.0 | 0.75% | |
| CVE-2026-56191 | — Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 10.0 | 0.68% | |
| CVE-2026-48330 | — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the c | 10.0 | 0.68% | |
| CVE-2026-48323 | — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the c | 10.0 | 0.62% | |
| CVE-2026-52887 | — NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api | 10.0 | 0.59% | |
| CVE-2026-48449 | — Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does n | 10.0 | 0.54% | |
| CVE-2025-67288 | Umbraco CMS Arbitrary File Upload leading to Remote Code Execution (CWE-434) | 10.0 | 0.50% | |
| CVE-2026-46595 | golang.org/x/crypto ssh Authorization bypass / incorrect authentication check in SSH server callback handling (CWE-863, CWE-303) | 10.0 | 0.50% | |
| CVE-2026-48331 | — Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. | 10.0 | 0.47% | |
| CVE-2026-44181 | — Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the env | 10.0 | 0.46% | |
| CVE-2026-63508 | — Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | 10.0 | 0.45% | |
| CVE-2026-60379 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 10.0 | 0.45% | |
| CVE-2026-47938 | — Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this is | 10.0 | 0.45% | |
| CVE-2026-66012 | — SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enfo | 10.0 | 0.44% | |
| CVE-2026-16367 | — Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 10.0 | 0.40% | |
| CVE-2026-64813 | — In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | 10.0 | 0.39% | |
| CVE-2026-60365 | — Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is af | 10.0 | 0.38% | |
| CVE-2026-64812 | — In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | 10.0 | 0.36% | |
| CVE-2026-44182 | — Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates unt | 10.0 | 0.35% | |
| CVE-2026-33712 | — Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Req | 10.0 | 0.35% | |
| CVE-2026-62422 | — In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access w | 10.0 | 0.35% | |
| CVE-2026-10134 | IBM Langflow OSS Server-Side Code Injection (CWE-94) via tool_code manipulation enabling RCE, SSRF, secret exfiltration, and persistence | 10.0 | 0.31% | |
| CVE-2025-67108 | eProsima Fast-DDS Improper validation of ticket revocation leading to insecure communications (CWE-298, CWE-370) | 10.0 | 0.29% | |
| CVE-2026-16117 | — Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but re | 10.0 | 0.27% | |
| CVE-2025-63314 | DDSN Interactive Acora CMS Static Password Reset Token / Account Takeover via Replay Attack (CWE-640) | 10.0 | 0.26% | 1 PoC
|
| CVE-2026-57834 | — Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10 | 10.0 | 0.26% | |
| CVE-2026-58150 | — Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 throug | 10.0 | 0.24% | |
| CVE-2026-48772 | — ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame a | 10.0 | 0.23% | |
| CVE-2026-5430 | — The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which | 10.0 | 0.22% | |
| CVE-2026-72851 | — Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook tri | 10.0 | — | |
| CVE-2018-0101 | — A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the aff | 10.0 | — | |
| CVE-2026-65667 | — Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-56162 | — Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-62825 | — Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-58275 | — Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-58630 | — Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-33267 | — Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.
Users are recommended to upgrade to | 10.0 | — | |
| CVE-2026-58162 | — The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.1 | 10.0 | — | |
| CVE-2026-60389 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 10.0 | — | |
| CVE-2026-54735 | — Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters | 10.0 | — | |
| CVE-2025-38429 | — In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Update read pointer only after buffer is written
Inside mhi_ep_ring_add_element, the read pointer (rd_offset) is upd | 10.0 | — | |
| CVE-2025-22021 | — In the Linux kernel, the following vulnerability has been resolved:
netfilter: socket: Lookup orig tuple for IPv6 SNAT
nf_sk_lookup_slow_v4 does the conntrack lookup for IPv4 packets to
restore the | 10.0 | — | |
| CVE-2025-21663 | — In the Linux kernel, the following vulnerability has been resolved:
net: stmmac: dwmac-tegra: Read iommu stream id from device tree
Nvidia's Tegra MGBE controllers require the IOMMU "Stream ID" (SID | 10.0 | — | |
| CVE-2026-60644 | — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily expl | 10.0 | — | |
| CVE-2026-50746 | — A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. | 10.0 | — | |
| CVE-2026-60360 | — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulner | 10.0 | — | |
| CVE-2026-60358 | — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita | 10.0 | — | |
| CVE-2026-47056 | — Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vuln | 10.0 | — | |
| CVE-2025-71389 | — Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes a | 10.0 | — | |
| CVE-2026-60217 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 10.0 | — | |
| CVE-2026-42298 | — Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows an | 10.0 | — | |
| CVE-2026-39907 | — Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LF | 10.0 | — | |
| CVE-2026-39906 | — Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashe | 10.0 | — | |
| CVE-2026-34938 | — PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing | 10.0 | — | |
| CVE-2026-32186 | — Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-33107 | — Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-33105 | — Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-32213 | — Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-34162 | — FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts | 10.0 | — | |
| CVE-2026-42960 | — NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority sect | 10.0 | — | |
| CVE-2026-34234 | — CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Executio | 10.0 | — | |
| CVE-2026-47668 | — DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parame | 10.0 | — | |
| CVE-2026-60366 | — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0. | 10.0 | — | |
| CVE-2026-44359 | — Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jo | 10.0 | — | |
| CVE-2026-46695 | — Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not rest | 10.0 | — | |
| CVE-2026-48567 | — Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-47280 | — Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-42901 | — Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | 10.0 | — | |
| CVE-2026-41104 | — Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. | 10.0 | — | |
| CVE-2026-40412 | — Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. | 10.0 | — | |
| CVE-2026-23652 | — Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. | 10.0 | — | |
| CVE-2026-7312 | — CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441 | 10.0 | — | |
| CVE-2026-45132 | — CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and | 10.0 | — | |
| CVE-2026-45131 | — CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in | 10.0 | — | |
| CVE-2026-45631 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker f | 10.0 | — | |
| CVE-2026-46840 | — Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker | 10.0 | — | |
| CVE-2026-63795 | — In the Linux kernel, the following vulnerability has been resolved:
9p: avoid putting oldfid in p9_client_walk() error path
When p9_client_walk() is called with clone set to false, fid aliases
oldfi | 10.0 | — | |
| CVE-2026-45336 | — HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used | 10.0 | — | |
| CVE-2026-43633 | HestiaCP PHP/Node.js session deserialization unauthenticated RCE | 10.0 | — | |
| CVE-2026-59726 | ruflo Unauthenticated RCE via exposed MCP bridge endpoint (OS Command Injection / Missing Authentication) | 10.0 | — | 1 PoC
|
| CVE-2026-54782 | CoreWCF.Primitives SAML token signature validation bypass / authentication spoofing (CWE-290, CWE-347) | 10.0 | — | |
| CVE-2026-57572 | crawl4ai Chromium argument injection leading to arbitrary command execution (CWE-88, CWE-94) | 10.0 | — | |
| CVE-2026-54763 | Traefik HTTP header spoofing via underscore-variant header bypass in authentication middleware (BasicAuth, DigestAuth, ForwardAuth) | 10.0 | — | |
| CVE-2025-67109 | Eclipse Cyclone DDS Improper verification of certificate time fields leading to privilege escalation / authentication bypass | 10.0 | — | |
| CVE-2026-50160 | hoppscotch-backend Mass Assignment leading to JWT Secret Overwrite (CWE-915) | 10.0 | — | |
| CVE-2026-13782 | Google Chrome Use-After-Free sandbox escape | 10.0 | — | |
| CVE-2026-48283 | Adobe ColdFusion Unrestricted File Upload leading to Remote Code Execution (CWE-434) | 10.0 | — | |
| CVE-2026-48282 | Adobe ColdFusion Path Traversal leading to arbitrary code execution (CWE-22) | 10.0 | — | 2 PoC
|
| CVE-2026-48281 | Adobe ColdFusion Improper Input Validation leading to arbitrary code execution (RCE) | 10.0 | — | |
| CVE-2026-48277 | Adobe ColdFusion Improper Input Validation leading to arbitrary code execution (RCE) | 10.0 | — | |
| CVE-2026-48276 | Adobe ColdFusion Unrestricted File Upload leading to Remote Code Execution (CWE-434) | 10.0 | — | |
| CVE-2026-54350 | Budibase JSON body parameter injection leading to NoSQL injection (query filter manipulation / unauthenticated data exfiltration and mass update) | 10.0 | — | 1 PoC
|
| CVE-2026-53622 | Traefik mTLS authentication bypass via HTTP/3 QUIC TLS configuration SNI wildcard mismatch (CWE-288, CWE-289) | 10.0 | — | |
| CVE-2026-48491 | Traefik Authentication Bypass via mTLS SNICheck wildcard host rule misconfiguration (CWE-288, CWE-807) | 10.0 | — | |
| CVE-2026-48020 | Traefik Authentication bypass via path traversal in StripPrefix middleware (CWE-288, CWE-22) | 10.0 | — | 1 PoC
|
| CVE-2026-39858 | Traefik Authentication bypass via HTTP header underscore/dash alias normalization in ForwardAuth middleware | 10.0 | — | |
| CVE-2026-35051 | Traefik Authentication Bypass via Insufficient Verification of Data Authenticity (ForwardAuth middleware trust header bypass) | 10.0 | — | |
| CVE-2026-33453 | Apache Camel camel-coap Camel message header injection via CoAP URI query parameters leading to RCE (CWE-915 Mass Assignment) | 10.0 | — | 1 PoC
|
| CVE-2026-34078 | Flatpak Symlink following sandbox escape leading to arbitrary file access and host code execution | 10.0 | — | |
| CVE-2026-34444 | Lupa Improper Access Control / Attribute Filter Bypass leading to Arbitrary Code Execution | 10.0 | — | 1 PoC
|
| CVE-2026-32871 | FastMCP Path Traversal via URL parameter injection leading to Server-Side Request Forgery (SSRF) | 10.0 | — | 1 PoC
|
| CVE-2025-15036 | mlflow Path Traversal (Zip/Tar Slip) during archive extraction | 10.0 | — | |
| CVE-2026-4692 | Mozilla Firefox / Thunderbird Sandbox escape | 10.0 | — | |
| CVE-2026-4689 | Firefox / Thunderbird (XPCOM) Sandbox escape via integer overflow and incorrect boundary conditions in XPCOM (CWE-190, CWE-754, CWE-120) | 10.0 | — | |
| CVE-2026-4688 | Firefox / Thunderbird Sandbox escape via use-after-free in Disability Access APIs (CWE-416, CWE-825) | 10.0 | — | |
| CVE-2026-2778 | Mozilla Firefox / Thunderbird Sandbox escape via incorrect boundary conditions in DOM Core & HTML (CWE-119 buffer boundary violation) | 10.0 | — | |
| CVE-2026-2776 | Mozilla Firefox / Thunderbird Sandbox escape via incorrect boundary conditions (buffer overflow/memory safety) in Telemetry component | 10.0 | — | |
| CVE-2026-2768 | Mozilla Firefox / Thunderbird Sandbox escape via IndexedDB improper access control | 10.0 | — | |
| CVE-2026-2761 | Mozilla Firefox / Thunderbird (WebRender) Sandbox escape via Graphics WebRender component (Protection Mechanism Failure) | 10.0 | — | |
| CVE-2026-2760 | Mozilla Firefox / Thunderbird Sandbox escape via incorrect boundary conditions in Graphics WebRender | 10.0 | — | 1 PoC
|
| CVE-2026-0881 | Firefox / Thunderbird Sandbox escape via Messaging System component (improper access control / protection mechanism failure) | 10.0 | — | |
| CVE-2025-70974 | Fastjson (com.alibaba:fastjson) JNDI injection via autoType deserialization RCE | 10.0 | — | |
| CVE-2026-10561 | IBM Langflow OSS Authentication bypass leading to arbitrary Python code execution (RCE) | 10.0 | — | |
| CVE-2026-46778 | Oracle WebCenter Enterprise Capture Missing Authentication for Critical Function (CWE-306) via RMI leading to unauthenticated RCE / full takeover | 10.0 | — | |
| CVE-2026-46846 | Oracle WebCenter Portal Missing Authentication for Critical Function (CWE-306) leading to unauthenticated remote takeover | 10.0 | — | |
| CVE-2026-46803 | Oracle WebCenter Portal Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover | 10.0 | — | |
| CVE-2026-35308 | Oracle Coherence Improper Access Control / Unauthenticated RCE via HTTP (CWE-284, Scope Change) | 10.0 | — | |
| CVE-2026-35307 | Oracle Coherence Unauthenticated Remote Code Execution / Improper Access Control (CWE-284) via HTTP | 10.0 | — | |
| CVE-2026-46781 | Oracle WebCenter Enterprise Capture Missing Authentication for Critical Function via RMI (CWE-306) | 10.0 | — | |
| CVE-2026-10611 | MISP Authentication bypass via LDAP mixed auth with OTP enforcement skip | 10.0 | — | |
| CVE-2026-46389 | uds-identity-config Authentication Bypass via Logic Error in Client Secret Comparison (CWE-287, CWE-303) | 10.0 | — | |
| CVE-2026-48303 | Adobe Campaign Classic (ACC) Incorrect Authorization leading to arbitrary code execution (CWE-863) | 10.0 | — | |
| CVE-2026-48318 | Adobe ColdFusion Path Traversal arbitrary file read (CWE-22) | 9.9 | 6.68% | |
| CVE-2026-20186 | Cisco Identity Services Engine (ISE) Authenticated Remote Command Injection (CWE-77) leading to OS privilege escalation to root | 9.9 | 5.91% | |
| CVE-2026-23696 | Windmill CE/EE SQL Injection leading to RCE (JWT secret exfiltration via owner parameter) | 9.9 | 5.06% | 1 PoC
|
| CVE-2026-50517 | — Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | 9.9 | 1.25% | |
| CVE-2025-62718 | Axios NO_PROXY bypass via hostname normalization leading to SSRF and proxy bypass | 9.9 | 1.16% | |
| CVE-2026-63294 | — A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly | 9.9 | 1.02% | |
| CVE-2026-27130 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input | 9.9 | 0.98% | |
| CVE-2026-43999 | vm2 Sandbox escape via builtin allowlist bypass leading to RCE | 9.9 | 0.97% | 1 PoC
|
| CVE-2026-48322 | Adobe ColdFusion Code Injection (CWE-94) leading to Arbitrary Code Execution | 9.9 | 0.90% | |
| CVE-2026-45663 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploa | 9.9 | 0.87% | |
| CVE-2025-46157 | EfroTech Time Trax Unrestricted File Upload (Remote Code Execution) | 9.9 | 0.78% | 2 PoC
|
| CVE-2026-72901 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because th | 9.9 | 0.63% | |
| CVE-2026-45499 | Azure OpenAI Server-Side Request Forgery (SSRF) privilege escalation | 9.9 | 0.62% | |
| CVE-2026-9559 | — A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape | 9.9 | 0.58% | |
| CVE-2026-44935 | SUSE Rancher Fleet Missing input validation leading to cross-tenant credential access (CWE-1287) | 9.9 | 0.57% | |
| CVE-2026-61445 | PraisonAI Path Traversal Arbitrary File Write and OS Command Injection RCE via LLM Prompt Injection | 9.9 | 0.54% | 1 PoC
|
| CVE-2025-1782 | — In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized
before being used and can be misused to include an arbitrary file in the
PHP code allowing an at | 9.9 | 0.52% | |
| CVE-2026-48584 | Azure Synapse Execution with Unnecessary Privileges / Privilege Escalation | 9.9 | 0.50% | |
| CVE-2026-48326 | — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the c | 9.9 | 0.48% | |
| CVE-2026-16860 | — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element. | 9.9 | 0.46% | |
| CVE-2026-44774 | Traefik Improper Access Control via Kubernetes Gateway API HTTPRoute backend reference bypass (CWE-284, CWE-15) | 9.9 | 0.46% | |
| CVE-2026-60206 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.9 | 0.45% | |
| CVE-2026-59827 | Metabase Java deserialization RCE via H2 native query OTHER column type | 9.9 | 0.45% | 2 PoC
|
| CVE-2026-9558 | — A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated use | 9.9 | 0.44% | |
| CVE-2026-62830 | — Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | 9.9 | 0.43% | |
| CVE-2026-61211 | — Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacke | 9.9 | 0.42% | |
| CVE-2026-35280 | Oracle WebCenter Enterprise Capture Improper Access Control RCE via T3/IIOP (CWE-284) | 9.9 | 0.42% | |
| CVE-2026-61209 | — Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerabili | 9.9 | 0.39% | |
| CVE-2026-61076 | — Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vul | 9.9 | 0.39% | |
| CVE-2026-61072 | — Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vuln | 9.9 | 0.39% | |
| CVE-2026-60627 | — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerabil | 9.9 | 0.39% | |
| CVE-2026-61146 | — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is | 9.9 | 0.39% | |
| CVE-2026-35285 | Oracle WebCenter Enterprise Capture Improper Access Control leading to Remote Takeover (CWE-284) via T3/IIOP protocol | 9.9 | 0.39% | |
| CVE-2026-35284 | Oracle WebCenter Enterprise Capture Improper Access Control RCE (CWE-284) via T3/IIOP – scope change leading to full takeover | 9.9 | 0.39% | |
| CVE-2026-35283 | Oracle WebCenter Enterprise Capture Improper Access Control (CWE-284) leading to full product takeover via T3/IIOP network protocol | 9.9 | 0.39% | |
| CVE-2026-35282 | Oracle WebCenter Enterprise Capture Improper Access Control / Unauthorized Takeover via T3/IIOP (CWE-284) | 9.9 | 0.39% | |
| CVE-2026-35281 | Oracle WebCenter Enterprise Capture Improper Access Control (CWE-284) leading to full system takeover via T3/IIOP network protocol | 9.9 | 0.39% | |
| CVE-2026-45625 | — Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /ap | 9.9 | 0.39% | |
| CVE-2026-72911 | — ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_acc | 9.9 | 0.38% | |
| CVE-2026-63293 | — A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whe | 9.9 | 0.38% | |
| CVE-2026-60719 | — Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable | 9.9 | 0.37% | |
| CVE-2026-54051 | — Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.m | 9.9 | 0.37% | |
| CVE-2026-63298 | — An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying | 9.9 | 0.36% | |
| CVE-2026-72869 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/se | 9.9 | 0.35% | |
| CVE-2026-72865 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and p | 9.9 | 0.35% | |
| CVE-2026-47724 | — nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most | 9.9 | 0.35% | |
| CVE-2026-60377 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.9 | 0.35% | |
| CVE-2026-66898 | — A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validat | 9.9 | 0.34% | |
| CVE-2026-61237 | — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulne | 9.9 | 0.34% | |
| CVE-2026-48086 | — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN thr | 9.9 | 0.33% | |
| CVE-2026-72880 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a client-supplied certificatePa | 9.9 | 0.30% | |
| CVE-2026-45312 | — RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated us | 9.9 | 0.29% | |
| CVE-2026-63300 | — An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project | 9.9 | 0.29% | |
| CVE-2026-61242 | — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerab | 9.9 | 0.29% | |
| CVE-2026-60402 | — Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploita | 9.9 | 0.29% | |
| CVE-2026-60663 | — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily expl | 9.9 | 0.29% | |
| CVE-2026-60381 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.9 | 0.29% | |
| CVE-2026-72864 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates wi | 9.9 | 0.27% | |
| CVE-2026-60369 | — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0. | 9.9 | 0.27% | |
| CVE-2026-61239 | — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vuln | 9.9 | 0.26% | |
| CVE-2026-48765 | — TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite th | 9.9 | 0.26% | |
| CVE-2026-63296 | — An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accep | 9.9 | 0.25% | |
| CVE-2026-55115 | UniFi Protect Application Server-Side Request Forgery (SSRF) leading to privilege escalation | 9.9 | 0.23% | |
| CVE-2026-63297 | — An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copi | 9.9 | 0.20% | |
| CVE-2026-73656 | — Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWo | 9.9 | — | |
| CVE-2021-30120 | — Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Th | 9.9 | — | |
| CVE-2026-72902 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server because re | 9.9 | — | |
| CVE-2026-72868 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, | 9.9 | — | |
| CVE-2026-59115 | — '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 9.9 | — | |
| CVE-2026-50515 | — Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | 9.9 | — | |
| CVE-2026-50481 | — Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | 9.9 | — | |
| CVE-2026-60542 | — Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Eas | 9.9 | — | |
| CVE-2026-67622 | — Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other works | 9.9 | — | |
| CVE-2026-61041 | — Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulner | 9.9 | — | |
| CVE-2026-70615 | — boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's | 9.9 | — | |
| CVE-2026-54120 | — Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | 9.9 | — | |
| CVE-2026-44210 | — Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configu | 9.9 | — | |
| CVE-2026-17566 | — pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop | 9.9 | — | |
| CVE-2026-60711 | — Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.5. Easily exploitable vulnerability | 9.9 | — | |
| CVE-2026-60524 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.9 | — | |
| CVE-2026-60458 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.9 | — | |
| CVE-2026-60552 | — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable v | 9.9 | — | |
| CVE-2026-24304 | — Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | 9.9 | — | |
| CVE-2026-60547 | — Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily expl | 9.9 | — | |
| CVE-2026-60537 | — Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily expl | 9.9 | — | |
| CVE-2026-60531 | — Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable v | 9.9 | — | |
| CVE-2026-60361 | — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulner | 9.9 | — | |
| CVE-2026-60429 | — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulner | 9.9 | — | |
| CVE-2026-60422 | — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows | 9.9 | — | |
| CVE-2026-27577 | — n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CV | 9.9 | — | |
| CVE-2026-60333 | — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita | 9.9 | — | |
| CVE-2026-60568 | — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vu | 9.9 | — | |
| CVE-2026-60565 | — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vu | 9.9 | — | |
| CVE-2026-60562 | — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vu | 9.9 | — | |
| CVE-2026-60561 | — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vu | 9.9 | — | |
| CVE-2026-60461 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.9 | — | |
| CVE-2026-60459 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.9 | — | |
| CVE-2026-60457 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.9 | — | |
| CVE-2026-60456 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.9 | — | |
| CVE-2026-60447 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.9 | — | |
| CVE-2026-60445 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.9 | — | |
| CVE-2026-42454 | — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate th | 9.9 | — | |
| CVE-2026-35031 | — Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field i | 9.9 | — | |
| CVE-2026-39888 | — PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a | 9.9 | — | |
| CVE-2026-39355 | — Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary | 9.9 | — | |
| CVE-2026-34612 | — Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execu | 9.9 | — | |
| CVE-2026-34838 | — Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to ins | 9.9 | — | |
| CVE-2026-34717 | — OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input directly into SQL WHERE | 9.9 | — | |
| CVE-2026-25212 | — An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to | 9.9 | — | |
| CVE-2026-33579 | — OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privil | 9.9 | — | |
| CVE-2026-34156 | — NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScr | 9.9 | — | |
| CVE-2026-46624 | — Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If | 9.9 | — | |
| CVE-2026-33642 | — Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 3 | 9.9 | — | |
| CVE-2026-10523 | — An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts | 9.9 | — | |
| CVE-2026-46442 | — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authent | 9.9 | — | |
| CVE-2026-40411 | — Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. | 9.9 | — | |
| CVE-2026-43986 | — Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled entries from `image_hash | 9.9 | — | |
| CVE-2026-41283 | — OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials. | 9.9 | — | |
| CVE-2025-14771 | — Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24. | 9.9 | — | |
| CVE-2026-45372 | — cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header val | 9.9 | — | |
| CVE-2026-47744 | — Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/I | 9.9 | — | |
| CVE-2026-45661 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitra | 9.9 | — | |
| CVE-2026-45633 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and | 9.9 | — | |
| CVE-2026-45632 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, upd | 9.9 | — | |
| CVE-2026-45629 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to | 9.9 | — | |
| CVE-2026-44881 | — Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2 | 9.9 | — | |
| CVE-2026-46839 | — Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acce | 9.9 | — | |
| CVE-2026-46824 | — Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easi | 9.9 | — | |
| CVE-2026-46822 | — Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allo | 9.9 | — | |
| CVE-2026-46775 | — Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acce | 9.9 | — | |
| CVE-2026-8481 | — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python c | 9.9 | — | |
| CVE-2026-9135 | — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integ | 9.9 | — | |
| CVE-2026-8859 | — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal v | 9.9 | — | |
| CVE-2026-8635 | — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system c | 9.9 | — | |
| CVE-2026-8476 | — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function | 9.9 | — | |
| CVE-2026-46512 | — Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/Dialp | 9.9 | — | |
| CVE-2026-52891 | — Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. | 9.9 | — | |
| CVE-2026-54052 | — n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT= | 9.9 | — | |
| CVE-2025-34267 | Flowise Authenticated RCE and Node VM sandbox escape via Puppeteer/Playwright browser binary path injection (Command Injection) | 9.9 | — | 1 PoC
|
| CVE-2026-54402 | UniFi OS Improper Input Validation Command Injection | 9.9 | — | |
| CVE-2026-57100 | Microsoft Entra Provisioning Service (SyncFabric) Server-Side Request Forgery (SSRF) leading to Privilege Escalation | 9.9 | — | 1 PoC
|
| CVE-2025-60306 | Simple Car Rental System Improper Access Control / Authentication Bypass (Privilege Escalation via Session Forgery) | 9.9 | — | 1 PoC
|
| CVE-2021-42952 | Zepl Notebooks Sandbox Escape leading to Remote Code Execution and Cloud Metadata Service Access | 9.9 | — | |
| CVE-2026-50195 | containerd CRI checkpoint import image reference validation bypass leading to local image cache poisoning and arbitrary code execution | 9.9 | — | |
| CVE-2026-7873 | IBM Langflow OSS Authenticated OS Command Injection / Arbitrary File Read (Code Injection, CWE-94) | 9.9 | — | |
| CVE-2026-5366 | Prefect Git argument injection RCE (CWE-94 - improper handling of user-controlled input in git commands) | 9.9 | — | 1 PoC
|
| CVE-2026-44477 | CloudNativePG Privilege escalation via RESET ROLE after SET ROLE demotion enabling COPY TO PROGRAM RCE | 9.9 | — | |
| CVE-2026-40906 | ElectricSQL (electric-sql/electric) Error-based SQL injection via ORDER BY parameter | 9.9 | — | 1 PoC
|
| CVE-2026-40453 | Apache Camel Case-sensitive header filter bypass leading to remote code execution and arbitrary file write | 9.9 | — | 1 PoC
|
| CVE-2026-55454 | Appsmith SSRF to unauthenticated Caddy Admin API RCE / reverse-proxy takeover | 9.9 | — | |
| CVE-2026-54305 | n8n Broken Access Control / Missing Authorization on EE Dynamic Credentials Endpoints (OAuth token hijack, credential enumeration, token revocation) | 9.9 | — | |
| CVE-2026-46893 | JD Edwards EnterpriseOne General Ledger Improper Privilege Management (CWE-269) leading to full system takeover via SMB with scope change | 9.9 | — | |
| CVE-2026-46847 | Oracle WebCenter Portal Improper Access Control / Privilege Escalation leading to full takeover (CWE-284) | 9.9 | — | |
| CVE-2026-46844 | Oracle WebCenter Portal Improper Access Control (CWE-284) leading to full system takeover / privilege escalation RCE | 9.9 | — | |
| CVE-2026-46838 | Oracle WebCenter Portal Improper Access Control (CWE-284) leading to full system takeover / privilege escalation RCE | 9.9 | — | |
| CVE-2026-46802 | Oracle WebCenter Portal Improper Access Control (CWE-284) leading to full system takeover / privilege escalation RCE | 9.9 | — | |
| CVE-2026-46767 | Oracle WebCenter Portal Improper Access Control (CWE-284) leading to full takeover / RCE | 9.9 | — | |
| CVE-2026-46765 | Oracle WebCenter Portal Improper Access Control (CWE-284) leading to full takeover / RCE via Composer component | 9.9 | — | |
| CVE-2026-35316 | Oracle WebCenter Content Improper Access Control / Unauthorized Takeover (CWE-284) | 9.9 | — | |
| CVE-2026-46964 | Oracle Universal Work Queue (Oracle E-Business Suite) Improper Privilege Management / Broken Access Control / Missing Authentication (Privilege Escalation to Takeover) | 9.9 | — | |
| CVE-2026-46963 | Oracle Universal Work Queue (Oracle E-Business Suite) Improper Access Control / Unauthorized Access leading to full product takeover (CWE-284) | 9.9 | — | |
| CVE-2026-46933 | Oracle Applications Manager (Oracle E-Business Suite) Improper Privilege Management / Broken Access Control / Missing Authentication (Privilege Escalation to Takeover) | 9.9 | — | |
| CVE-2026-46918 | Oracle Process Manufacturing Product Development (Oracle E-Business Suite) Improper Access Control leading to full product takeover (CWE-284) | 9.9 | — | |
| CVE-2026-46908 | JD Edwards EnterpriseOne Accounts Payable Improper Access Control (CWE-284) leading to full product takeover | 9.9 | — | |
| CVE-2026-46907 | JD Edwards EnterpriseOne Order Promising Improper Access Control (CWE-284) leading to full system takeover | 9.9 | — | |
| CVE-2026-46782 | Oracle WebCenter Enterprise Capture Improper Access Control (CWE-284) leading to full product takeover via HTTP | 9.9 | — | |
| CVE-2026-46779 | Oracle WebCenter Enterprise Capture Improper Access Control via T3 protocol leading to full product takeover (CWE-284) | 9.9 | — | |
| CVE-2026-35323 | Oracle WebCenter Content Improper Access Control (CWE-284) leading to full system takeover / RCE | 9.9 | — | |
| CVE-2026-35321 | Oracle WebCenter Content Improper Access Control (CWE-284) leading to full system takeover / RCE | 9.9 | — | |
| CVE-2023-37679 | NextGen Mirth Connect Remote Command Execution (RCE) via Command Injection (CWE-77) | 9.8 | 97.1% | 3 PoC
|
| CVE-2022-24562 | IOBit IOTransfer Unauthenticated arbitrary file read/write via missing authentication on Airserv API (CWE-306) | 9.8 | 53.9% | 2 PoC
|
| CVE-2021-44596 | Wondershare Dr. Fone Unauthenticated UDP Remote Code Execution leading to SYSTEM privilege escalation | 9.8 | 22.7% | |
| CVE-2023-52440 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob()
If authblob->SessionKey.Length is bigger than session key
size(CIFS_K | 9.8 | 21.9% | |
| CVE-2025-56005 | PLY (Python Lex-Yacc) Insecure Deserialization / Remote Code Execution via pickle.load() | 9.8 | 16.9% | 2 PoC
|
| CVE-2022-37434 | zlib heap-based buffer overflow / buffer over-read in inflate | 9.8 | 16.0% | 39 PoC
|
| CVE-2026-25874 | LeRobot (huggingface/lerobot) Unsafe deserialization (pickle.loads) RCE over unauthenticated gRPC | 9.8 | 15.5% | 1 PoC
|
| CVE-2022-38580 | github.com/zalando/skipper Server-Side Request Forgery (SSRF) | 9.8 | 11.0% | 3 PoC
|
| CVE-2026-27446 | Apache ActiveMQ Artemis Missing Authentication for Critical Function - unauthenticated Core protocol federation connection hijack (CWE-306) | 9.8 | 10.0% | |
| CVE-2016-9841 | zlib improper pointer arithmetic memory corruption | 9.8 | 7.55% | 7 PoC
|
| CVE-2026-26213 | thingino-firmware Unauthenticated OS Command Injection (CWE-78) via CGI HTTP parameter names leading to RCE as root | 9.8 | 6.24% | |
| CVE-2022-36536 | Syncovery 9 for Linux Insecure Session Token Generation / Privilege Escalation | 9.8 | 5.20% | |
| CVE-2024-23052 | WuKongOpenSource WukongCRM Fastjson deserialization Remote Code Execution (RCE) | 9.8 | 4.87% | 22 PoC
|
| CVE-2022-28568 | Sourcecodester Doctor's Appointment System Unrestricted File Upload to Remote Code Execution (RCE) | 9.8 | 4.06% | |
| CVE-2025-71210 | — A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.
Please note: although this vuln | 9.8 | 3.81% | |
| CVE-2025-71211 | — A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in s | 9.8 | 3.75% | |
| CVE-2020-26867 | ARC Informatique PcVue Deserialization of untrusted data RCE (CWE-502) | 9.8 | 3.72% | |
| CVE-2026-22778 | vllm Information Exposure via Error Messages / Heap Address Leak (CWE-532, CWE-209) enabling ASLR bypass and potential RCE chain | 9.8 | 3.68% | |
| CVE-2022-28397 | Ghost CMS Arbitrary File Upload RCE (CWE-434) | 9.8 | 3.44% | 1 PoC
|
| CVE-2021-42675 | Kreado Kreasfero Unrestricted File Upload RCE (CWE-434) | 9.8 | 3.10% | 1 PoC
|
| CVE-2022-48174 | BusyBox Stack overflow out-of-bounds write (CWE-787) leading to arbitrary code execution in ash shell | 9.8 | 2.98% | 4 PoC
|
| CVE-2022-23303 | hostapd / wpa_supplicant SAE side-channel attack via cache access patterns (CWE-203 Observable Discrepancy) | 9.8 | 2.94% | 3 PoC
|
| CVE-2023-45853 | MiniZip / zlib / pyminizip Integer overflow and heap-based buffer overflow in ZIP file creation (CWE-190) | 9.8 | 2.92% | 58 PoC
|
| CVE-2026-25244 | WebdriverIO Command Injection / Remote Code Execution (OS Command Injection via unsanitized git branch name in execSync) | 9.8 | 2.76% | |
| CVE-2026-31843 | — The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment | 9.8 | 2.76% | |
| CVE-2015-5721 | Malware Information Sharing Platform (MISP) PHP object injection via crafted serialized data | 9.8 | 2.61% | |
| CVE-2017-17674 | BMC Remedy Mid Tier Server Side Request Forgery (SSRF) / Remote File Inclusion (RFI) / Local File Inclusion (LFI) | 9.8 | 2.57% | 1 PoC
|
| CVE-2015-10138 | — The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, | 9.8 | 2.43% | |
| CVE-2022-29351 | TiddlyWiki5 Arbitrary File Upload leading to Code Execution (SVG) | 9.8 | 2.41% | |
| CVE-2015-5719 | Malware Information Sharing Platform (MISP) Improper filename restriction / path traversal | 9.8 | 2.27% | |
| CVE-2023-28531 | OpenSSH ssh-add Improper Access Control - smartcard keys added to ssh-agent without per-hop destination constraints | 9.8 | 2.22% | 15 PoC
|
| CVE-2026-61498 | — Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary command | 9.8 | 2.19% | |
| CVE-2022-32511 | jmespath.rb Unsafe deserialization via JSON.load instead of JSON.parse | 9.8 | 2.13% | |
| CVE-2022-29347 | Web@rchiv Arbitrary File Upload leading to Remote Code Execution (RCE) | 9.8 | 2.12% | 2 PoC
|
| CVE-2023-21709 | — Microsoft Exchange Server Elevation of Privilege Vulnerability | 9.8 | 2.10% | |
| CVE-2025-4334 | — The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can | 9.8 | 2.05% | |
| CVE-2020-26037 | Even Balance Punkbuster Directory Traversal leading to Remote Code Execution | 9.8 | 2.05% | |
| CVE-2022-36640 | influxData influxDB Missing authentication / unauthenticated remote command execution (CWE-276 incorrect default permissions) | 9.8 | 2.05% | 1 PoC
|
| CVE-2022-28945 | WeBankPartners wecube-platform Directory Traversal via Zip Slip (CWE-22) | 9.8 | 2.00% | |
| CVE-2023-48193 | JumpServer Insecure Permissions / Command Filter Bypass RCE | 9.8 | 1.96% | 2 PoC
|
| CVE-2022-23304 | hostapd / wpa_supplicant EAP-pwd side-channel attack via cache access patterns (CWE-203 Observable Timing Discrepancy) | 9.8 | 1.90% | 1 PoC
|
| CVE-2022-31384 | Directory Management System v1.0 SQL Injection (CWE-89) | 9.8 | 1.89% | 2 PoC
|
| CVE-2022-31383 | Directory Management System v1.0 SQL Injection | 9.8 | 1.89% | 2 PoC
|
| CVE-2022-31382 | Directory Management System v1.0 SQL Injection | 9.8 | 1.89% | 2 PoC
|
| CVE-2023-31541 | CKEditor plugin for Redmine Unrestricted File Upload (CWE-434) | 9.8 | 1.78% | 1 PoC
|
| CVE-2020-35276 | EgavilanMedia ECM Address Book SQL Injection Authentication Bypass | 9.8 | 1.76% | 6 PoC
|
| CVE-2026-8631 | HP Linux Imaging and Printing (HPLIP) Integer overflow leading to heap buffer overflow, enabling privilege escalation and/or arbitrary code execution | 9.8 | 1.75% | |
| CVE-2026-33937 | Handlebars.js AST injection via NumberLiteral node leading to Remote Code Execution (RCE) | 9.8 | 1.74% | 2 PoC
|
| CVE-2018-25357 | — Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can | 9.8 | 1.70% | |
| CVE-2024-23054 | Plone Docker Official Image Dependency Confusion / Uncontrolled Search Path Element (npm package squatting leading to RCE) | 9.8 | 1.68% | 1 PoC
|
| CVE-2024-38887 | Caterease OS Command Injection via excessive database privileges (CWE-78) | 9.8 | 1.68% | 29 PoC
|
| CVE-2026-46670 | — YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a defau | 9.8 | 1.65% | |
| CVE-2026-37281 | — An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter. | 9.8 | 1.62% | |
| CVE-2020-29312 | Zend Framework PHP object deserialization RCE (unserialize) | 9.8 | 1.52% | 1 PoC
|
| CVE-2023-41449 | phpkobo AjaxNewsTicker Server-Side Request Forgery (SSRF) leading to arbitrary code execution via crafted payload | 9.8 | 1.51% | 3 PoC
|
| CVE-2023-23059 | GeoVision GV-Edge Recording Manager Insecure Default File/Directory Permissions Privilege Escalation | 9.8 | 1.48% | |
| CVE-2024-21401 | — Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | 9.8 | 1.46% | |
| CVE-2024-28386 | Home-Made.io fastmagsync (PrestaShop module) Remote Code Execution via arbitrary code injection (CWE-94) | 9.8 | 1.45% | 1 PoC
|
| CVE-2026-60121 | — Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a doub | 9.8 | 1.41% | |
| CVE-2026-27606 | Rollup (JavaScript module bundler) Arbitrary File Write via Path Traversal (CWE-22) | 9.8 | 1.40% | 1 PoC
|
| CVE-2026-63766 | — GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into sh | 9.8 | 1.39% | |
| CVE-2023-26999 | NetScout nGeniusOne XML External Entity (XXE) Injection leading to RCE / DoS (CWE-611) | 9.8 | 1.39% | |
| CVE-2026-28780 | Apache HTTP Server mod_proxy_ajp Heap-based Buffer Overflow (CWE-122, CWE-787) | 9.8 | 1.38% | |
| CVE-2026-59800 | 9router OS command injection via stdin shell injection (CWE-78) | 9.8 | 1.37% | 1 PoC
|
| CVE-2026-73034 | — DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences in | 9.8 | 1.33% | |
| CVE-2021-45024 | ASG-Zena Cross Platform Server Enterprise Edition XML External Entity (XXE) Injection | 9.8 | 1.32% | 1 PoC
|
| CVE-2026-55944 | — Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | 9.8 | 1.31% | |
| CVE-2022-24239 | ACEweb Online Portal Unrestricted File Upload (CWE-434) | 9.8 | 1.28% | |
| CVE-2026-4809 | — plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. | 9.8 | 1.28% | |
| CVE-2022-35156 | Bus Pass Management System SQL Injection | 9.8 | 1.27% | |
| CVE-2026-65700 | — h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to th | 9.8 | 1.27% | |
| CVE-2023-39809 | N.V.K.INTER CO., LTD. (NVK) iBSG OS Command Injection via shell metacharacters | 9.8 | 1.27% | 1 PoC
|
| CVE-2026-44170 | MariaDB server OS Command Injection (CWE-78) via CONNECT engine REST/HTTP table attribute interpolated into curl command line | 9.8 | 1.19% | |
| CVE-2021-3262 | TripSpark VEO Transportation / NovusEDU SQL Injection (CWE-89) | 9.8 | 1.18% | 1 PoC
|
| CVE-2026-24781 | vm2 Sandbox breakout via inspect function leading to arbitrary command execution (RCE) | 9.8 | 1.16% | 1 PoC
|
| CVE-2024-22902 | Vinchin Backup & Recovery Default Root Credentials | 9.8 | 1.15% | 4 PoC
|
| CVE-2022-37257 | stealjs steal Prototype Pollution | 9.8 | 1.11% | |
| CVE-2022-31340 | — Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php. | 9.8 | 1.10% | |
| CVE-2026-54414 | — FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. | 9.8 | 1.09% | |
| CVE-2022-24240 | ACEweb Online Portal SQL Injection (CWE-89) | 9.8 | 1.07% | |
| CVE-2026-16956 | — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | 9.8 | 1.04% | |
| CVE-2023-29863 | Medical Systems Co. Medisys Weblab SQL Injection via WSDL parameter (CWE-89) | 9.8 | 1.02% | |
| CVE-2026-9862 | — Fortra's
Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to ca | 9.8 | 0.99% | |
| CVE-2026-29063 | Immutable.js (immutable-js) Prototype Pollution | 9.8 | 0.98% | 1 PoC
|
| CVE-2024-22922 | Projectworlds Visitor Management System in PHP Privilege Escalation via crafted login script (Improper Privilege Management) | 9.8 | 0.97% | 3 PoC
|
| CVE-2024-38882 | Horizon Business Services Caterease SQL Injection leading to OS Command Injection (CWE-78) | 9.8 | 0.95% | |
| CVE-2022-38619 | SmartVista SVFE2 SQL Injection | 9.8 | 0.94% | |
| CVE-2026-33701 | OpenTelemetry Java Instrumentation Unsafe Java deserialization RCE via RMI instrumentation endpoint | 9.8 | 0.93% | 1 PoC
|
| CVE-2025-55835 | SueamCMS Unrestricted File Upload leading to Remote Code Execution (CWE-434) | 9.8 | 0.92% | 1 PoC
|
| CVE-2024-39011 | chargeover redoc Prototype Pollution leading to RCE / DoS | 9.8 | 0.91% | |
| CVE-2023-48659 | MISP Reflected Cross-Site Scripting (XSS) via parameter parsing mishandling | 9.8 | 0.91% | |
| CVE-2023-48658 | MISP Time-based SQL Injection | 9.8 | 0.91% | |
| CVE-2023-48657 | MISP Time-based SQL Injection via mishandled filters | 9.8 | 0.91% | |
| CVE-2023-48656 | MISP Blind SQL Injection via order parameter | 9.8 | 0.91% | |
| CVE-2023-48655 | MISP Blind SQL Injection via improper query parameter filtering | 9.8 | 0.91% | |
| CVE-2024-38889 | Caterease SQL Injection / Command Injection (CWE-89, CWE-78) | 9.8 | 0.89% | 1 PoC
|
| CVE-2024-50660 | AdPortal 3.0.39 File Upload Bypass leading to Remote Code Execution (CWE-94: Improper Control of Code Generation) | 9.8 | 0.87% | |
| CVE-2026-10109 | IBM Db2 Remote Code Execution via improper pre-auth DRDA handshake handling (CWE-94 Code Injection) | 9.8 | 0.86% | |
| CVE-2026-44008 | vm2 Sandbox Escape leading to Remote Code Execution | 9.8 | 0.85% | |
| CVE-2024-23086 | Apfloat Stack Overflow (Out-of-bounds Read) | 9.8 | 0.84% | |
| CVE-2024-50658 | AdPortal Server-Side Template Injection (SSTI) RCE | 9.8 | 0.82% | |
| CVE-2026-44009 | vm2 Sandbox Escape / Exposure of Resource to Wrong Sphere (CWE-668, CWE-653) | 9.8 | 0.81% | |
| CVE-2026-27727 | mchange-commons-java JNDI deserialization RCE via remote factoryClassLocation | 9.8 | 0.81% | |
| CVE-2026-33228 | flatted Prototype Pollution via unsanitized array index key in JSON parser | 9.8 | 0.81% | |
| CVE-2024-38183 | — An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. | 9.8 | 0.79% | |
| CVE-2026-47391 | — PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` to | 9.8 | 0.78% | |
| CVE-2026-3843 | — Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially craf | 9.8 | 0.76% | |
| CVE-2025-57631 | TDuckCloud tduck-platform SQL Injection RCE via file upload module | 9.8 | 0.76% | |
| CVE-2026-55010 | — Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | 9.8 | 0.76% | |
| CVE-2024-38886 | Caterease Traffic Injection / Improper Verification of Communication Channel Source | 9.8 | 0.76% | 1 PoC
|
| CVE-2026-9079 | libcurl Insufficiently Protected Credentials (CWE-522) - Proxy authentication credentials not cleared | 9.8 | 0.75% | |
| CVE-2026-49980 | rclone Unauthenticated Remote Command Execution via inline remote configuration (CWE-306, CWE-78) | 9.8 | 0.75% | |
| CVE-2026-61500 | Rejetto HFS (HTTP File Server) Predictable PRNG session-cookie signing key forgery leading to RCE (CWE-338) | 9.8 | 0.75% | |
| CVE-2026-63888 | — In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
Two latent bugs in the Text-phase handler, both | 9.8 | 0.74% | |
| CVE-2026-63887 | — In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
iscsi_encode_text_output() concatenates "key=value\0" rec | 9.8 | 0.74% | |
| CVE-2026-41242 | protobuf.js (protobufjs) Code Injection via protobuf definition "type" field (CWE-94) | 9.8 | 0.74% | 2 PoC
|
| CVE-2026-63767 | — ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pic | 9.8 | 0.74% | |
| CVE-2026-15435 | — IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted UR | 9.8 | 0.73% | |
| CVE-2026-48908 | SP Page Builder for Joomla Unauthenticated Arbitrary File Upload leading to Remote Code Execution (RCE) | 9.8 | 0.73% | 9 PoC
|
| CVE-2026-44930 | Apache CXF LDAP Injection | 9.8 | 0.72% | |
| CVE-2026-30457 | Daylight Studio FuelCMS PHP Code Injection / Arbitrary Code Execution (CWE-94) | 9.8 | 0.71% | |
| CVE-2026-63912 | — In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: restore combined single-frag length gate
The ESP out-of-place fast path appends the trailer in esp_output_head()
before | 9.8 | 0.70% | |
| CVE-2026-27459 | pyOpenSSL Buffer overflow via oversized cookie value in set_cookie_generate_callback (CWE-120) | 9.8 | 0.70% | |
| CVE-2026-26210 | KTransformers Unsafe deserialization (pickle) RCE via unauthenticated ZMQ ROUTER socket | 9.8 | 0.70% | |
| CVE-2022-45597 | ComponentSpace.Saml2 Missing SSL Certificate Validation (Improper Certificate Validation) | 9.8 | 0.70% | |
| CVE-2023-36361 | Audimexee SQL Injection | 9.8 | 0.70% | 1 PoC
|
| CVE-2026-63924 | — In the Linux kernel, the following vulnerability has been resolved:
ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers.
| 9.8 | 0.69% | |
| CVE-2026-50628 | Apache (OAuthRequestFilter) Improper Input Validation / Inverted Security Check (CWE-20) - IP-based OAuth request filtering logic error | 9.8 | 0.69% | |
| CVE-2026-63922 | — In the Linux kernel, the following vulnerability has been resolved:
ipv6: exthdrs: refresh nh after handling HAO option
ip6_parse_tlv() caches skb_network_header(skb) in nh while walking
IPv6 TLVs.
| 9.8 | 0.68% | |
| CVE-2026-63886 | — In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Validate CHAP_R length before base64 decode
chap_server_compute_hash() allocates client_digest as
kzalloc(cha | 9.8 | 0.66% | |
| CVE-2026-25560 | WeKan LDAP filter injection authentication bypass | 9.8 | 0.65% | |
| CVE-2026-48773 | — ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol fi | 9.8 | 0.65% | |
| CVE-2026-39892 | pyca/cryptography Buffer overflow via non-contiguous buffer in Python buffer API | 9.8 | 0.65% | |
| CVE-2026-65008 | — Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its | 9.8 | 0.65% | |
| CVE-2026-45700 | FreeRDP Out-of-bounds heap write (OOB write) in planar bitmap RLE decoder | 9.8 | 0.63% | 1 PoC
|
| CVE-2026-10042 | — manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{m | 9.8 | 0.62% | |
| CVE-2023-4501 | — User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants | 9.8 | 0.62% | |
| CVE-2026-73519 | — WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypas | 9.8 | 0.62% | |
| CVE-2026-49819 | — UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reach | 9.8 | 0.61% | |
| CVE-2026-33815 | github.com/jackc/pgx/v5 Out-of-bounds Write (CWE-787) / Memory Safety Vulnerability | 9.8 | 0.60% | |
| CVE-2025-56218 | SigningHub Arbitrary File Upload leading to Remote Code Execution | 9.8 | 0.60% | 1 PoC
|
| CVE-2026-65688 | — Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files | 9.8 | 0.59% | |
| CVE-2023-39806 | iCMS SQL Injection | 9.8 | 0.59% | |
| CVE-2023-39805 | iCMS SQL Injection | 9.8 | 0.59% | |
| CVE-2026-65689 | — Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary fil | 9.8 | 0.58% | |
| CVE-2026-65687 | — Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files | 9.8 | 0.58% | |
| CVE-2026-64620 | — FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the call | 9.8 | 0.58% | |
| CVE-2026-48207 | — Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolu | 9.8 | 0.57% | |
| CVE-2026-45411 | vm2 Sandbox escape via async generator yield* expression host exception catch RCE | 9.8 | 0.57% | 1 PoC
|
| CVE-2026-43037 | Linux Kernel Out-of-bounds write / type confusion stack buffer overflow in ip6_tunnel ICMPv4 error handling (CWE-787, CWE-843) | 9.8 | 0.56% | |
| CVE-2026-33816 | github.com/jackc/pgx/v5 Memory safety out-of-bounds write (CWE-787) | 9.8 | 0.56% | |
| CVE-2026-52986 | Linux Kernel Out-of-bounds memory access / unsafe string parsing in netfilter conntrack SIP helper | 9.8 | 0.56% | |
| CVE-2023-47031 | NCR Terminal Handler Improper Access Control - Privilege Escalation via SOAP API | 9.8 | 0.55% | |
| CVE-2026-48085 | — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated P | 9.8 | 0.55% | |
| CVE-2026-64125 | — In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: keep RBUF EEE/PM disabled
Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX
path on GENET hardware | 9.8 | 0.55% | |
| CVE-2026-64091 | — In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tt: fix TOCTOU race for reported vlans
The local TT based TVLV is generated by first checking the number of VLANs
whic | 9.8 | 0.55% | |
| CVE-2026-64089 | — In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tt: fix negative last_changeset_len
batadv_piv_tt::last_changeset_len len was declared as s16, but the field is
never | 9.8 | 0.55% | |
| CVE-2026-52680 | — Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpo | 9.8 | 0.55% | |
| CVE-2022-49770 | — In the Linux kernel, the following vulnerability has been resolved:
ceph: avoid putting the realm twice when decoding snaps fails
When decoding the snaps fails it maybe leaving the 'first_realm'
and | 9.8 | 0.55% | |
| CVE-2026-17218 | — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. | 9.8 | 0.55% | |
| CVE-2026-52982 | Linux Kernel rtl8150 USB network driver use-after-free (UAF) in USB URB submission path | 9.8 | 0.54% | |
| CVE-2026-28808 | Erlang OTP inets Incorrect Authorization / Authentication Bypass via path mismatch in CGI script_alias | 9.8 | 0.54% | |
| CVE-2024-49604 | — Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: fro | 9.8 | 0.54% | |
| CVE-2026-14512 | — IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary c | 9.8 | 0.54% | |
| CVE-2023-39808 | N.V.K.INTER CO., LTD. (NVK) iBSG Hardcoded Credentials (Root Password) via SSH | 9.8 | 0.53% | |
| CVE-2026-53421 | — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying | 9.8 | 0.53% | |
| CVE-2022-23334 | Ip-label Newtest Improper Signature Verification / Privilege Escalation via Binary Replacement | 9.8 | 0.53% | |
| CVE-2026-53046 | Linux Kernel ksmbd use-after-free via async crypto completion callback (DMA in-flight free) | 9.8 | 0.53% | |
| CVE-2026-68502 | — LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches da | 9.8 | 0.53% | |
| CVE-2026-49875 | Apache CXF XML External Entity (XXE) injection via unsecured SAXParserFactory (CWE-611) | 9.8 | 0.53% | |
| CVE-2026-64606 | — Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected
This issue affects A | 9.8 | 0.53% | |
| CVE-2026-67340 | — ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authen | 9.8 | 0.52% | |
| CVE-2026-53045 | Linux Kernel - tegra124-emc memory controller driver Logic inversion bug in DLL enable check (memory timing misconfiguration) | 9.8 | 0.52% | |
| CVE-2023-39807 | N.V.K.INTER CO., LTD. (NVK) iBSG SQL Injection | 9.8 | 0.52% | 1 PoC
|
| CVE-2026-43011 | Linux Kernel Double free of socket buffer (skb) in X.25 network protocol handler (CWE-415) | 9.8 | 0.51% | |
| CVE-2026-32640 | SimpleEval Sandbox Escape / Code Injection via unsafe attribute access and callback abuse (CWE-94, CWE-915) | 9.8 | 0.51% | |
| CVE-2025-60889 | StellarGroup HPX Insecure Deserialization RCE (CWE-502) | 9.8 | 0.51% | |
| CVE-2026-53049 | Linux Kernel GFS2 Missing lock / race condition leading to concurrent transaction corruption | 9.8 | 0.51% | |
| CVE-2026-69098 | — kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying c | 9.8 | 0.51% | |
| CVE-2026-49048 | JoomCCK (Joomla extension by JoomCoder) SQL Injection (CWE-89) via unsanitised front-end controller task parameter concatenation | 9.8 | 0.51% | 1 PoC
|
| CVE-2026-73649 | — Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set as | 9.8 | 0.50% | |
| CVE-2026-64113 | — In the Linux kernel, the following vulnerability has been resolved:
ixgbevf: fix use-after-free in VEPA multicast source pruning
ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF' | 9.8 | 0.50% | |
| CVE-2026-64102 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Reject MPA FPDU length underflow before signed receive math
A malicious connected siw peer can send an iWARP FPDU whose | 9.8 | 0.50% | |
| CVE-2026-60292 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerabilit | 9.8 | 0.50% | |
| CVE-2026-60205 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerabilit | 9.8 | 0.50% | |
| CVE-2026-60198 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.8 | 0.50% | |
| CVE-2026-64136 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
Commit 96c4af418586 ("cifs: Fix locking usage for tc | 9.8 | 0.49% | |
| CVE-2026-64132 | — In the Linux kernel, the following vulnerability has been resolved:
ipv6: ioam: refresh hdr pointer before ioam6_event()
Reported by Sashiko:
In ipv6_hop_ioam(), the hdr pointer is initialized to p | 9.8 | 0.49% | |
| CVE-2023-52480 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix race condition between session lookup and expire
Thread A + Thread B
ksmbd_session_lookup | 9.8 | 0.48% | |
| CVE-2026-60294 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.8 | 0.48% | |
| CVE-2026-60291 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.8 | 0.48% | |
| CVE-2026-60204 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.8 | 0.48% | |
| CVE-2026-60200 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.8 | 0.48% | |
| CVE-2026-51807 | — Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths | 9.8 | 0.48% | |
| CVE-2026-71254 | — nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total | 9.8 | 0.48% | |
| CVE-2026-43501 | — In the Linux kernel, the following vulnerability has been resolved:
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, | 9.8 | 0.47% | |
| CVE-2026-48333 | — Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges | 9.8 | 0.47% | |
| CVE-2025-61168 | SIGB PMB PHP Object Deserialization RCE (CWE-502) | 9.8 | 0.47% | |
| CVE-2026-8091 | Mozilla Firefox / Thunderbird Incorrect boundary conditions (CWE-754, CWE-805) in Audio/Video Playback component | 9.8 | 0.47% | |
| CVE-2026-44180 | — Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 have a prohi | 9.8 | 0.46% | |
| CVE-2026-64122 | — In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
mlx5e_tx_reporter_timeout_recover() accesses sq->netdev after
m | 9.8 | 0.46% | |
| CVE-2025-65783 | Hubert Imoveis e Administracao Ltda Hub v2.0 Arbitrary File Upload leading to Remote Code Execution (CWE-434) | 9.8 | 0.46% | |
| CVE-2026-9698 | Perl DBI Stack/heap buffer overflow via unbounded error message write to fixed-size buffer | 9.8 | 0.45% | |
| CVE-2026-5450 | GNU C Library (glibc) Heap buffer overflow via scanf %mc format width specifier | 9.8 | 0.45% | |
| CVE-2026-60296 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60442 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.45% | |
| CVE-2026-61233 | — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerab | 9.8 | 0.45% | |
| CVE-2026-46983 | — Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability a | 9.8 | 0.45% | |
| CVE-2026-60541 | — Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60538 | — Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60386 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.45% | |
| CVE-2026-60385 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.45% | |
| CVE-2026-60384 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.45% | |
| CVE-2026-60378 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.45% | |
| CVE-2026-60376 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.45% | |
| CVE-2026-60375 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.45% | |
| CVE-2026-61131 | — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability | 9.8 | 0.45% | |
| CVE-2026-61129 | — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthent | 9.8 | 0.45% | |
| CVE-2026-60262 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60259 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60258 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60234 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-61161 | — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected | 9.8 | 0.45% | |
| CVE-2026-61145 | — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is | 9.8 | 0.45% | |
| CVE-2026-60300 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60299 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | 0.45% | |
| CVE-2026-60298 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | 0.45% | |
| CVE-2026-60297 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60289 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60288 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60287 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60286 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60280 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | 0.45% | |
| CVE-2026-60257 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | 0.45% | |
| CVE-2026-60256 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | 0.45% | |
| CVE-2026-60254 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60253 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60247 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allo | 9.8 | 0.45% | |
| CVE-2026-60242 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allo | 9.8 | 0.45% | |
| CVE-2026-60240 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-60197 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.45% | |
| CVE-2026-53753 | Crawl4AI AST sandbox escape leading to arbitrary code execution (CWE-94, CWE-913) | 9.8 | 0.45% | 2 PoC
|
| CVE-2026-64216 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
netfs_unlock_abandoned_read_pages(rreq) accesses the index of the | 9.8 | 0.45% | |
| CVE-2025-52239 | ZKEACMS Arbitrary File Upload RCE (CWE-434) | 9.8 | 0.45% | 1 PoC
|
| CVE-2026-8094 | Mozilla Firefox / Thunderbird WebRTC Improper Control of Code Generation (CWE-94) in WebRTC component | 9.8 | 0.45% | |
| CVE-2026-48062 | — CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of th | 9.8 | 0.44% | |
| CVE-2026-69102 | — MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authent | 9.8 | 0.44% | |
| CVE-2026-22189 | Panda3D egg-mkfont Stack-based buffer overflow (CWE-121, CWE-787) via unbounded sprintf() with attacker-controlled glyph pattern input | 9.8 | 0.44% | |
| CVE-2026-53055 | Linux Kernel - hisilicon/sec2 crypto driver use-after-free (UAF) in crypto request handling | 9.8 | 0.43% | |
| CVE-2026-16383 | — Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.43% | |
| CVE-2026-16377 | — Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.43% | |
| CVE-2026-16357 | — Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.43% | |
| CVE-2026-16355 | — JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.43% | |
| CVE-2026-16353 | — Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.43% | |
| CVE-2026-16350 | — Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.43% | |
| CVE-2026-63087 | — Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install | 9.8 | 0.43% | |
| CVE-2026-43125 | Linux Kernel DLM (Distributed Lock Manager) Out-of-bounds write / Buffer overflow via unvalidated network-supplied length parameter | 9.8 | 0.43% | |
| CVE-2026-16382 | — Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.43% | |
| CVE-2026-46376 | — FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if t | 9.8 | 0.43% | |
| CVE-2026-28802 | Authlib JWT algorithm confusion / "alg:none" signature bypass (CWE-347 Improper Verification of Cryptographic Signature) | 9.8 | 0.43% | 1 PoC
|
| CVE-2025-50433 | imonnit.com (Monnit IoT Monitoring Platform) Account Takeover via Weak/Improper Password Reset (CWE-640) | 9.8 | 0.42% | 3 PoC
|
| CVE-2026-61459 | mcp-server-kubernetes argument injection via kubectl structured tools (CWE-88) | 9.8 | 0.42% | 1 PoC
|
| CVE-2026-16356 | — Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140. | 9.8 | 0.42% | |
| CVE-2026-16352 | — Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140. | 9.8 | 0.42% | |
| CVE-2026-16351 | — Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.42% | |
| CVE-2025-61140 | jsonpath (dchester/jsonpath) Prototype Pollution | 9.8 | 0.42% | |
| CVE-2026-16369 | — Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.41% | |
| CVE-2026-16368 | — Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.41% | |
| CVE-2026-16363 | — JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.41% | |
| CVE-2026-60090 | PraisonAI SQL/CQL Injection via unsanitized vector dimension parameter in CREATE TABLE DDL | 9.8 | 0.41% | |
| CVE-2026-47393 | — PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API s | 9.8 | 0.41% | |
| CVE-2026-31649 | Linux Kernel net/stmmac Integer underflow (wrap-around) leading to kernel memory disclosure and potential DMA memory corruption (CWE-190) | 9.8 | 0.41% | |
| CVE-2026-16388 | — Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.40% | |
| CVE-2026-31669 | Linux Kernel MPTCP Use-After-Free (CWE-416) - slab-use-after-free via missing SLAB_TYPESAFE_BY_RCU on MPTCP v6 subflow slab cache | 9.8 | 0.40% | |
| CVE-2025-56385 | WellSky Harmony SQL Injection Authentication Bypass | 9.8 | 0.40% | |
| CVE-2026-14739 | Perl DBI heap buffer overflow via SQL placeholder preparsing | 9.8 | 0.40% | |
| CVE-2026-68503 | — LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema. | 9.8 | 0.40% | |
| CVE-2026-72839 | — filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inheri | 9.8 | 0.39% | |
| CVE-2026-14454 | Imager (Perl) Signed/Unsigned Integer Misinterpretation leading to excessive memory allocation DoS (CWE-196, CWE-789) | 9.8 | 0.39% | |
| CVE-2025-52161 | Scholl Communications AG Weblication CMS Core Cross-Site Scripting (XSS) | 9.8 | 0.39% | 1 PoC
|
| CVE-2026-12535 | drupal/formatter_field Improperly Controlled Modification of Dynamically-Determined Object Attributes (Object Injection) | 9.8 | 0.39% | |
| CVE-2026-16379 | — Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.38% | |
| CVE-2026-16371 | — Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.38% | |
| CVE-2026-31414 | Linux Kernel Use-after-free / unsafe pointer dereference in netfilter conntrack expectation handling | 9.8 | 0.38% | |
| CVE-2026-67289 | — FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client' | 9.8 | 0.38% | |
| CVE-2026-53006 | Linux Kernel Use-After-Free (UAF) in ICMPv6 receive path after pskb_pull() head pointer change | 9.8 | 0.38% | |
| CVE-2026-51540 | — OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData). | 9.8 | 0.38% | |
| CVE-2026-67324 | — GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes atta | 9.8 | 0.38% | |
| CVE-2026-19001 | — The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function | 9.8 | 0.38% | |
| CVE-2026-52955 | Linux Kernel (libceph) Out-of-bounds memory access in CRUSH map decoding (CWE-131 incorrect buffer size calculation) | 9.8 | 0.38% | |
| CVE-2026-24014 | Apache IoTDB Path Traversal Arbitrary File Write via Trigger JAR upload (CWE-284, CWE-434) | 9.8 | 0.38% | |
| CVE-2026-57308 | — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve execution of arbitrary SQ | 9.8 | 0.38% | |
| CVE-2026-16372 | — Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.37% | |
| CVE-2026-16366 | — Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.37% | |
| CVE-2026-16365 | — Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.37% | |
| CVE-2026-52993 | Linux Kernel double-free (CWE-763) in TIPC buffer reassembly path | 9.8 | 0.37% | |
| CVE-2026-26218 | newbee-mall Hard-coded / Default Credentials (CWE-798) | 9.8 | 0.37% | 1 PoC
|
| CVE-2026-60199 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.8 | 0.36% | |
| CVE-2026-26338 | Hyland Alfresco Transformation Service Server-Side Request Forgery (SSRF) | 9.8 | 0.36% | |
| CVE-2026-60264 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | 0.36% | |
| CVE-2026-63071 | — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted co | 9.8 | 0.36% | |
| CVE-2026-55652 | — Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-F | 9.8 | 0.36% | |
| CVE-2026-68979 | — Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Conte | 9.8 | 0.35% | |
| CVE-2026-46135 | — In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: fix race between ICReq handling and queue teardown
nvmet_tcp_handle_icreq() updates queue->state after sending an
Initi | 9.8 | 0.35% | |
| CVE-2026-64625 | — AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can | 9.8 | 0.35% | |
| CVE-2026-16360 | — Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could | 9.8 | 0.35% | |
| CVE-2026-64162 | — In the Linux kernel, the following vulnerability has been resolved:
idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
In idpf_ptp_init(), read_dev_clk_lock is initialized after
ptp_schedu | 9.8 | 0.35% | |
| CVE-2026-63857 | — In the Linux kernel, the following vulnerability has been resolved:
net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()
The transmit loop in airoha_dev_xmit() reads fragment | 9.8 | 0.35% | |
| CVE-2026-61808 | — LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an un | 9.8 | 0.34% | |
| CVE-2026-47410 | — PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcode | 9.8 | 0.34% | |
| CVE-2026-47396 | — PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured. | 9.8 | 0.34% | |
| CVE-2026-53405 | — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start t | 9.8 | 0.34% | |
| CVE-2026-52989 | Linux Kernel CWE-390 Detection of Error Condition Without Action / uninitialized iterator use after fatal error in nvmet-tcp PDU handling | 9.8 | 0.34% | |
| CVE-2026-14104 | Google Chrome Insufficient input validation sandbox escape via WebAppInstalls | 9.8 | 0.34% | |
| CVE-2026-57827 | RSFiles (Joomla extension) Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE) | 9.8 | 0.33% | 1 PoC
|
| CVE-2026-60279 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.33% | |
| CVE-2026-60276 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.33% | |
| CVE-2026-60269 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.33% | |
| CVE-2026-61245 | — Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerabi | 9.8 | 0.33% | |
| CVE-2026-60999 | — Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allo | 9.8 | 0.33% | |
| CVE-2026-60364 | — Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affec | 9.8 | 0.33% | |
| CVE-2026-47036 | — Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager). Supported versions that are affected are 17.0-26.3. Easily exploitable vulnerability all | 9.8 | 0.33% | |
| CVE-2026-60441 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.33% | |
| CVE-2026-46982 | — Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability | 9.8 | 0.33% | |
| CVE-2026-60463 | — Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerab | 9.8 | 0.33% | |
| CVE-2026-60380 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.33% | |
| CVE-2026-60374 | — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita | 9.8 | 0.33% | |
| CVE-2026-60232 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | 0.33% | |
| CVE-2026-60278 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allo | 9.8 | 0.33% | |
| CVE-2026-60251 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.33% | |
| CVE-2026-60250 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.33% | |
| CVE-2026-60246 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | 0.33% | |
| CVE-2026-60244 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allo | 9.8 | 0.33% | |
| CVE-2026-60241 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | 0.33% | |
| CVE-2026-16396 | — Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.33% | |
| CVE-2026-10768 | drupal/localgov_workflows Missing Authorization / Forceful Browsing (CWE-862) | 9.8 | 0.33% | |
| CVE-2026-16361 | — Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbi | 9.8 | 0.33% | |
| CVE-2026-47767 | symfony/runtime Interpretation Conflict / Query String Bypass leading to environment variable injection (APP_ENV/APP_DEBUG flag manipulation via argv) | 9.8 | 0.33% | |
| CVE-2021-32084 | — An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If | 9.8 | 0.33% | |
| CVE-2026-16410 | — JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.33% | |
| CVE-2026-53260 | — In the Linux kernel, the following vulnerability has been resolved:
tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
syzbot reported a weird reqsk->rsk_refcnt underflow in
__ine | 9.8 | 0.33% | |
| CVE-2026-69240 | — Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the va | 9.8 | 0.32% | |
| CVE-2026-62183 | — Improper Privilege Management vulnerability in Apache Syncope.
When:
* the all-Java user workflow adapter is configured, or
* the Flowable user workflow adapter is configured, bearing a BPMN definit | 9.8 | 0.32% | |
| CVE-2026-16402 | — Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.32% | |
| CVE-2026-66756 | — Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, | 9.8 | 0.32% | |
| CVE-2026-53175 | — In the Linux kernel, the following vulnerability has been resolved:
inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
On netns teardown, fqdir_pre_exit() walks the fqdir rhashtabl | 9.8 | 0.31% | |
| CVE-2026-16407 | — Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.31% | |
| CVE-2026-28812 | — UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges.
Users are recommended to upgrade to version 2.12.4 or newer which fixes | 9.8 | 0.31% | |
| CVE-2026-31607 | — In the Linux kernel, the following vulnerability has been resolved:
usbip: validate number_of_packets in usbip_pack_ret_submit()
When a USB/IP client receives a RET_SUBMIT response,
usbip_pack_ret_s | 9.8 | 0.31% | |
| CVE-2026-71256 | — nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_device_identification_res in nanomodbus.c. A fixed | 9.8 | 0.31% | |
| CVE-2026-14241 | Mozilla Firefox Memory corruption out-of-bounds write RCE | 9.8 | 0.30% | |
| CVE-2021-32088 | — An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypass | 9.8 | 0.30% | |
| CVE-2026-43198 | — In the Linux kernel, the following vulnerability has been resolved:
tcp: fix potential race in tcp_v6_syn_recv_sock()
Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock()
is done | 9.8 | 0.30% | |
| CVE-2026-1728 | — Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
Exploitation of this vulnerability allows a low-privileged us | 9.8 | 0.30% | |
| CVE-2026-60367 | — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0. | 9.8 | 0.30% | |
| CVE-2026-16401 | — Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | 0.29% | |
| CVE-2026-9202 | — IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly cr | 9.8 | 0.29% | |
| CVE-2026-14446 | — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. | 9.8 | 0.29% | |
| CVE-2026-14121 | Google Chrome / Chromoting (Chrome Remote Desktop) Use-After-Free (UAF) Remote Code Execution | 9.8 | 0.29% | |
| CVE-2026-32253 | — Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are ha | 9.8 | 0.29% | |
| CVE-2026-60372 | — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0. | 9.8 | 0.29% | |
| CVE-2026-6653 | libxml2 Use After Free / XML External Entity (XXE) injection leading to Denial of Service | 9.8 | 0.29% | |
| CVE-2026-15734 | — A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. | 9.8 | 0.28% | |
| CVE-2026-52924 | Linux Kernel SCTP Use-After-Free (CWE-416 / CWE-825) in SCTP stream scheduler via stale COOKIE-ECHO rollback | 9.8 | 0.27% | |
| CVE-2023-34575 | PrestaShop opartsavecart SQL Injection | 9.8 | 0.27% | |
| CVE-2026-31533 | Linux Kernel Use-After-Free (CWE-416) in TLS encryption async/backlog error path | 9.8 | 0.26% | |
| CVE-2026-43038 | Linux Kernel Type Confusion (CWE-843) via IPv4/IPv6 control block overlap enabling out-of-bounds memory access in ICMPv6 error handling | 9.8 | 0.26% | |
| CVE-2026-65888 | — Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site. | 9.8 | 0.25% | |
| CVE-2026-65887 | — Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these us | 9.8 | 0.25% | |
| CVE-2026-16349 | — Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.24% | |
| CVE-2026-65890 | — Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. | 9.8 | 0.24% | |
| CVE-2026-16358 | — Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.23% | |
| CVE-2026-16375 | — Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.22% | |
| CVE-2026-16387 | — Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.8 | 0.22% | |
| CVE-2023-34576 | PrestaShop opartfaq SQL Injection | 9.8 | 0.22% | |
| CVE-2021-32086 | — An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for e | 9.8 | 0.19% | |
| CVE-2026-16770 | — PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document.
For an HTML string or file source, the constructor collects every <meta name= | 9.8 | 0.18% | |
| CVE-2026-64056 | — In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: cortina: Make RX SKB per-port
The SKB used to assemble packets from fragments in gmac_rx()
is static local, but the | 9.8 | 0.18% | |
| CVE-2026-64142 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: close durable scavenger races against m_fp_list lookups
ksmbd_durable_scavenger() has two related races against any walker
| 9.8 | 0.18% | |
| CVE-2026-64055 | — In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: cortina: Carry over frag counter
The gmac_rx() NAPI poll function assembles packets in an
SKB from a ring buffer.
| 9.8 | 0.18% | |
| CVE-2026-64047 | — In the Linux kernel, the following vulnerability has been resolved:
net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
When an sk_msg scatterlist ring wraps (sg.end < sg.start) | 9.8 | 0.18% | |
| CVE-2026-64046 | — In the Linux kernel, the following vulnerability has been resolved:
net: tls: prevent chain-after-chain in plain text SG
Sashiko points out that if end = 0 (start != 0) the current
code will create | 9.8 | 0.18% | |
| CVE-2026-64007 | — In the Linux kernel, the following vulnerability has been resolved:
netfilter: synproxy: refresh tcphdr after skb_ensure_writable
synproxy_tstamp_adjust() rewrites the TCP timestamp option in place
| 9.8 | 0.18% | |
| CVE-2026-63994 | — In the Linux kernel, the following vulnerability has been resolved:
tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
Sashiko found that iptunnel_pmtud_build_icmp() an | 9.8 | 0.18% | |
| CVE-2026-63993 | — In the Linux kernel, the following vulnerability has been resolved:
vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
skb_tunnel_check_pmtu() can change skb->head.
Reusing old | 9.8 | 0.18% | |
| CVE-2026-63984 | — In the Linux kernel, the following vulnerability has been resolved:
ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
ipv6_rpl_srh_decompress() computes:
outhdr->hdrlen = (((n + 1) * | 9.8 | 0.18% | |
| CVE-2026-57433 | Storable (Perl module) Signed integer overflow in deserialization (CWE-190) | 9.8 | 0.17% | |
| CVE-2026-64033 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/rtrs: Fix use-after-free in path file creation cleanup
In the error path of rtrs_srv_create_path_files(), the sysfs root fold | 9.8 | 0.17% | |
| CVE-2026-64000 | — In the Linux kernel, the following vulnerability has been resolved:
net: hsr: fix potential OOB access in supervision frame handling
Ensure the entire TLV header is linearized before access by addin | 9.8 | 0.17% | |
| CVE-2026-64061 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix early put of sink folio in netfs_read_gaps()
Fix netfs_read_gaps() to release the sink page it uses after waiting for
t | 9.8 | 0.17% | |
| CVE-2026-64025 | — In the Linux kernel, the following vulnerability has been resolved:
bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
sk_psock_strp_data_ready() already checks tls_sw_has_ctx_rx() and
defers | 9.8 | 0.17% | |
| CVE-2026-64150 | — In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_inner: release local_lock before re-enabling softirqs
Quoting sashiko:
In the error path, local_bh_enable() is cal | 9.8 | 0.17% | |
| CVE-2026-64069 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix cancellation of a DIO and single read subrequests
When the preparation of a new subrequest for a read fails, if the
sub | 9.8 | 0.17% | |
| CVE-2026-64066 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix netfs_read_to_pagecache() to pause on subreq failure
Fix netfs_read_to_pagecache() so that it pauses the generation of | 9.8 | 0.17% | |
| CVE-2026-64037 | — In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
When the TLC notification disables AMSDU for a TID, the | 9.8 | 0.17% | |
| CVE-2026-64035 | — In the Linux kernel, the following vulnerability has been resolved:
igc: set tx buffer type for SMD frames
Sashiko pointed out that igc_fpe_init_smd_frame() initializes
igc_tx_buffer fields for an S | 9.8 | 0.17% | |
| CVE-2026-64016 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix durable reconnect error path file lifetime
After a durable reconnect succeeds, ksmbd_reopen_durable_fd() republishes
th | 9.8 | 0.17% | |
| CVE-2026-64160 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
Fix potential tearing in using ->remote_i_size and ->zero_poi | 9.8 | 0.16% | |
| CVE-2026-55810 | Drupal Plotly.js Graphing (drupal/plotly_js) Improperly Controlled Modification of Dynamically-Determined Object Attributes (Object Injection) | 9.8 | 0.16% | |
| CVE-2026-15732 | — A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve | 9.8 | 0.16% | |
| CVE-2026-64068 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix missing locking around retry adding new subreqs
Fix netfs_retry_read_subrequests() and netfs_retry_write_stream() to ta | 9.8 | 0.15% | |
| CVE-2026-64067 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix missing barriers when accessing stream->subrequests locklessly
The list of subrequests attached to stream->subrequests | 9.8 | 0.15% | |
| CVE-2026-13236 | drupal/ai_agents Missing Authorization (Forceful Browsing) CWE-862 | 9.8 | 0.14% | |
| CVE-2026-13235 | Drupal AI (Artificial Intelligence) module Missing Authorization / Forceful Browsing (CWE-862) | 9.8 | 0.14% | |
| CVE-2026-11909 | drupal/examples Missing Authorization (Forceful Browsing) CWE-862 | 9.8 | 0.14% | |
| CVE-2026-13243 | Drupal Salesforce Suite Cross-Site Request Forgery (CSRF) | 9.8 | 0.10% | |
| CVE-2023-36263 | Prestashop opartlimitquantity SQL Injection | 9.8 | 0.05% | |
| CVE-2026-68302 | — In the Linux kernel, the following vulnerability has been resolved:
amt: re-read skb header pointers after every pull
Several AMT receive and transmit paths cache a pointer into the skb head
(ip_hdr | 9.8 | — | |
| CVE-2026-68300 | — In the Linux kernel, the following vulnerability has been resolved:
sctp: auth: verify auth requirement when auth_chunk is NULL
sctp_auth_chunk_verify() returns true unconditionally when
chunk->auth | 9.8 | — | |
| CVE-2026-68170 | — In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix stale skb->sk reference on subflow close
The backlog list is updated by mptcp_data_ready() under
mptcp_data_lock(). The | 9.8 | — | |
| CVE-2026-68161 | — In the Linux kernel, the following vulnerability has been resolved:
sctp: close UDP tunnel sockets during netns teardown
proc_sctp_do_udp_port() starts per-net SCTP UDP tunneling sockets when
net.sc | 9.8 | — | |
| CVE-2026-68160 | — In the Linux kernel, the following vulnerability has been resolved:
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
ceph_handle_caps() reads snap_trace_len from the wire-for | 9.8 | — | |
| CVE-2026-68159 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
__decode_pg_temp() decodes an user-controlled length but onl | 9.8 | — | |
| CVE-2026-68158 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix multiplication overflow in decode_new_up_state_weight()
If a message of type CEPH_MSG_OSD_MAP contains a (maliciously | 9.8 | — | |
| CVE-2026-68156 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: refresh auth->authorizer_buf{,_len} after authorizer update
ceph_x_create_authorizer() caches au->buf->vec.iov_base and
a | 9.8 | — | |
| CVE-2026-68154 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: reject zero bucket types in crush_decode
CRUSH bucket type 0 is reserved for devices. The mapper relies on
that invarian | 9.8 | — | |
| CVE-2026-68144 | — In the Linux kernel, the following vulnerability has been resolved:
phonet: pep: fix use-after-free in pep_get_sb()
pep_get_sb() doesn't consider that pskb_may_pull() might have relocated
the skb da | 9.8 | — | |
| CVE-2026-68137 | — In the Linux kernel, the following vulnerability has been resolved:
net/x25: fix use-after-free in x25_kill_by_neigh()
x25_kill_by_neigh() walks the global X.25 socket list looking for sockets
attac | 9.8 | — | |
| CVE-2026-68136 | — In the Linux kernel, the following vulnerability has been resolved:
net: gro: fix double aggregation of flush-marked skbs
Commit 0ab03f353d36 ("net-gro: Fix GRO flush when receiving a GSO
packet.") | 9.8 | — | |
| CVE-2026-68127 | — In the Linux kernel, the following vulnerability has been resolved:
ila: reload IPv6 header after pskb_may_pull in checksum adjust
ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before call | 9.8 | — | |
| CVE-2026-68123 | — In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix GSO userspace truncation underflow
OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb
length in | 9.8 | — | |
| CVE-2026-68117 | — In the Linux kernel, the following vulnerability has been resolved:
tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
When tipc_sk_create() fails to insert the new socket (tipc_sk_i | 9.8 | — | |
| CVE-2026-68082 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: fix two unsafe bare decodes in decode_lockers()
decode_lockers() in cls_lock_client.c contains two bare decode operations | 9.8 | — | |
| CVE-2026-56654 | — Privilege Escalation via Access Token Scope Escalation in API | 9.8 | — | |
| CVE-2026-59124 | — Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | 9.8 | — | |
| CVE-2026-16280 | — An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and | 9.8 | — | |
| CVE-2018-9206 | — Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 | 9.8 | — | |
| CVE-2026-64608 | — Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field ty | 9.8 | — | |
| CVE-2026-51080 | — libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | 9.8 | — | |
| CVE-2026-53412 | — Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network | 9.8 | — | |
| CVE-2026-21662 | — Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.
This issue affects FM Systems Employee: before 2025.3.1. | 9.8 | — | |
| CVE-2026-12943 | — IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arb | 9.8 | — | |
| CVE-2026-12118 | — IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | 9.8 | — | |
| CVE-2026-23600 | — A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS). | 9.8 | — | |
| CVE-2026-64597 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_close() replay
A response-bearing attempt can return a replayable error and free its
response | 9.8 | — | |
| CVE-2026-64566 | — In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
When iptfs_skb_add_frags() copies frag references from the sourc | 9.8 | — | |
| CVE-2026-64564 | — In the Linux kernel, the following vulnerability has been resolved:
sctp: don't free the ASCONF's own transport in DEL-IP processing
sctp_process_asconf() caches the transport the ASCONF chunk is pr | 9.8 | — | |
| CVE-2026-71558 | — Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility check | 9.8 | — | |
| CVE-2026-70558 | — Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore | 9.8 | — | |
| CVE-2026-14537 | — Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequir | 9.8 | — | |
| CVE-2026-62873 | — Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | 9.8 | — | |
| CVE-2026-48087 | — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` valid | 9.8 | — | |
| CVE-2026-15733 | — A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root. | 9.8 | — | |
| CVE-2026-67261 | — Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could | 9.8 | — | |
| CVE-2026-24254 | — NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code | 9.8 | — | |
| CVE-2026-68079 | — In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. | 9.8 | — | |
| CVE-2026-66909 | — Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the ser | 9.8 | — | |
| CVE-2026-61486 | — ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project is retired, we do not plan to release a versio | 9.8 | — | |
| CVE-2026-61484 | — ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project is retired, we do not plan to release a | 9.8 | — | |
| CVE-2026-18108 | — Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature.
_verify_encrypted_ | 9.8 | — | |
| CVE-2026-17544 | — Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9. | 9.8 | — | |
| CVE-2026-17543 | — Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and | 9.8 | — | |
| CVE-2026-65884 | — Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with a | 9.8 | — | |
| CVE-2026-65883 | — Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code executio | 9.8 | — | |
| CVE-2026-59243 | — The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callba | 9.8 | — | |
| CVE-2026-67342 | — ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissio | 9.8 | — | |
| CVE-2026-67341 | — ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript co | 9.8 | — | |
| CVE-2026-66402 | — FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). | 9.8 | — | |
| CVE-2026-68771 | — ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pi | 9.8 | — | |
| CVE-2026-68770 | — sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sen | 9.8 | — | |
| CVE-2026-61154 | — Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability | 9.8 | — | |
| CVE-2026-60173 | — Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerab | 9.8 | — | |
| CVE-2026-65321 | — PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format( | 9.8 | — | |
| CVE-2026-63223 | — CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacke | 9.8 | — | |
| CVE-2026-15976 | — SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fa | 9.8 | — | |
| CVE-2026-15971 | — SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests. | 9.8 | — | |
| CVE-2026-15969 | — SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle | 9.8 | — | |
| CVE-2026-61183 | — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable | 9.8 | — | |
| CVE-2026-61178 | — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitab | 9.8 | — | |
| CVE-2026-60363 | — Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnera | 9.8 | — | |
| CVE-2026-58066 | — Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Ass | 9.8 | — | |
| CVE-2026-60113 | — AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthent | 9.8 | — | |
| CVE-2026-60112 | — AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraf | 9.8 | — | |
| CVE-2026-15704 | — In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC mi | 9.8 | — | |
| CVE-2026-60555 | — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable v | 9.8 | — | |
| CVE-2026-60551 | — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable v | 9.8 | — | |
| CVE-2026-64541 | — In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
smc_cdc_rx_handler() looks up the connection by token under the lin | 9.8 | — | |
| CVE-2026-64535 | — In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: Fix potential UAF when ddgst mismatch
Shivam Kumar found via vulnerability testing:
When data digest is enabled on an N | 9.8 | — | |
| CVE-2026-64534 | — In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
In nvmet_tcp_try_recv_ddgst(), when a data digest mismat | 9.8 | — | |
| CVE-2025-71159 | — In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix use-after-free warning in btrfs_get_or_create_delayed_node()
Previously, btrfs_get_or_create_delayed_node() set the del | 9.8 | — | |
| CVE-2025-71068 | — In the Linux kernel, the following vulnerability has been resolved:
svcrdma: bound check rq_pages index in inline path
svc_rdma_copy_inline_range indexed rqstp->rq_pages[rc_curpage] without
verifyin | 9.8 | — | |
| CVE-2025-68817 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
Under high concurrency, A tree-connection object (tcon) is f | 9.8 | — | |
| CVE-2025-68811 | — In the Linux kernel, the following vulnerability has been resolved:
svcrdma: use rc_pageoff for memcpy byte offset
svc_rdma_copy_inline_range added rc_curpage (page index) to the page
base instead o | 9.8 | — | |
| CVE-2025-68794 | — In the Linux kernel, the following vulnerability has been resolved:
iomap: adjust read range correctly for non-block-aligned positions
iomap_adjust_read_range() assumes that the position and length | 9.8 | — | |
| CVE-2025-68775 | — In the Linux kernel, the following vulnerability has been resolved:
net/handshake: duplicate handshake cancellations leak socket
When a handshake request is cancelled it is removed from the
handshak | 9.8 | — | |
| CVE-2025-68745 | — In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Clear cmds after chip reset
Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling
and host reset h | 9.8 | — | |
| CVE-2025-68741 | — In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix improper freeing of purex item
In qla2xxx_process_purls_iocb(), an item is allocated via
qla27xx_copy_multiple_ | 9.8 | — | |
| CVE-2025-68726 | — In the Linux kernel, the following vulnerability has been resolved:
crypto: aead - Fix reqsize handling
Commit afddce13ce81d ("crypto: api - Add reqsize to crypto_alg")
introduced cra_reqsize field | 9.8 | — | |
| CVE-2025-68359 | — In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix double free of qgroup record after failure to add delayed ref head
In the previous code it was possible to incur into a | 9.8 | — | |
| CVE-2025-68341 | — In the Linux kernel, the following vulnerability has been resolved:
veth: reduce XDP no_direct return section to fix race
As explain in commit fa349e396e48 ("veth: Fix race with AF_XDP exposing
old | 9.8 | — | |
| CVE-2025-68315 | — In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to detect potential corrupted nid in free_nid_list
As reported, on-disk footer.ino and footer.nid is the same and
out-of | 9.8 | — | |
| CVE-2025-68301 | — In the Linux kernel, the following vulnerability has been resolved:
net: atlantic: fix fragment overflow handling in RX path
The atlantic driver can receive packets with more than MAX_SKB_FRAGS (17) | 9.8 | — | |
| CVE-2025-68285 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: fix potential use-after-free in have_mon_and_osd_map()
The wait loop in __ceph_open_session() can race with the client
re | 9.8 | — | |
| CVE-2025-68284 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: prevent potential out-of-bounds writes in handle_auth_session_key()
The len field originates from untrusted network packe | 9.8 | — | |
| CVE-2025-68192 | — In the Linux kernel, the following vulnerability has been resolved:
net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
Raw IP packets have no MAC header, leaving skb->mac_header uni | 9.8 | — | |
| CVE-2025-40350 | — In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ
XDP programs can change the layout of an xdp_buff throu | 9.8 | — | |
| CVE-2025-40343 | — In the Linux kernel, the following vulnerability has been resolved:
nvmet-fc: avoid scheduling association deletion twice
When forcefully shutting down a port via the configfs interface,
nvmet_port_ | 9.8 | — | |
| CVE-2025-40320 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential cfid UAF in smb2_query_info_compound
When smb2_query_info_compound() retries, a previously allocated cf | 9.8 | — | |
| CVE-2025-40261 | — In the Linux kernel, the following vulnerability has been resolved:
nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
nvme_fc_delete_assocation() waits for pending I/O to comp | 9.8 | — | |
| CVE-2025-40258 | — In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix race condition in mptcp_schedule_work()
syzbot reported use-after-free in mptcp_schedule_work() [1]
Issue here is that | 9.8 | — | |
| CVE-2025-40257 | — In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix a race in mptcp_pm_del_add_timer()
mptcp_pm_del_add_timer() can call sk_stop_timer_sync(sk, &entry->add_timer)
while an | 9.8 | — | |
| CVE-2025-40252 | — In the Linux kernel, the following vulnerability has been resolved:
net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end()
The loops in 'qede_tpa_cont()' and 'qede_ | 9.8 | — | |
| CVE-2025-40212 | — In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix refcount leak in nfsd_set_fh_dentry()
nfsd exports a "pseudo root filesystem" which is used by NFSv4 to find
the various | 9.8 | — | |
| CVE-2025-40176 | — In the Linux kernel, the following vulnerability has been resolved:
tls: wait for pending async decryptions if tls_strp_msg_hold fails
Async decryption calls tls_strp_msg_hold to create a clone of t | 9.8 | — | |
| CVE-2025-40074 | — In the Linux kernel, the following vulnerability has been resolved:
ipv4: start using dst_dev_rcu()
Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF.
Change ipmr_prepare_xmit(), ipm | 9.8 | — | |
| CVE-2025-39975 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix wrong index reference in smb2_compound_op()
In smb2_compound_op(), the loop that processes each command's respons | 9.8 | — | |
| CVE-2025-39948 | — In the Linux kernel, the following vulnerability has been resolved:
ice: fix Rx page leak on multi-buffer frames
The ice_put_rx_mbuf() function handles calling ice_put_rx_buf() for each
buffer in th | 9.8 | — | |
| CVE-2025-39932 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
In smbd_destroy() we may destroy the memory | 9.8 | — | |
| CVE-2025-39880 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: fix invalid accesses to ceph_connection_v1_info
There is a place where generic code in messenger.c is reading and
another | 9.8 | — | |
| CVE-2025-39841 | — In the Linux kernel, the following vulnerability has been resolved:
scsi: lpfc: Fix buffer free/clear order in deferred receive path
Fix a use-after-free window by correcting the buffer release sequ | 9.8 | — | |
| CVE-2025-39758 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages
Ever since commit c2ff29e99a76 ("siw: Inline do_tcp_sendpages()"),
we ha | 9.8 | — | |
| CVE-2025-39726 | — In the Linux kernel, the following vulnerability has been resolved:
s390/ism: fix concurrency management in ism_cmd()
The s390x ISM device data sheet clearly states that only one
request-response se | 9.8 | — | |
| CVE-2025-39703 | — In the Linux kernel, the following vulnerability has been resolved:
net, hsr: reject HSR frame if skb can't hold tag
Receiving HSR frame with insufficient space to hold HSR tag in the skb
can result | 9.8 | — | |
| CVE-2025-39702 | — In the Linux kernel, the following vulnerability has been resolved:
ipv6: sr: Fix MAC comparison to be constant-time
To prevent timing attacks, MACs need to be compared in constant time.
Use the app | 9.8 | — | |
| CVE-2025-39682 | — In the Linux kernel, the following vulnerability has been resolved:
tls: fix handling of zero-length records on the rx_list
Each recvmsg() call must process either
- only contiguous DATA records (a | 9.8 | — | |
| CVE-2025-39673 | — In the Linux kernel, the following vulnerability has been resolved:
ppp: fix race conditions in ppp_fill_forward_path
ppp_fill_forward_path() has two race conditions:
1. The ppp->channels list can | 9.8 | — | |
| CVE-2025-38737 | — In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix oops due to uninitialised variable
Fix smb3_init_transform_rq() to initialise buffer to NULL before calling
netfs_alloc_ | 9.8 | — | |
| CVE-2025-38734 | — In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix UAF on smcsk after smc_listen_out()
BPF CI testing report a UAF issue:
[ 16.446633] BUG: kernel NULL pointer der | 9.8 | — | |
| CVE-2025-38724 | — In the Linux kernel, the following vulnerability has been resolved:
nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
Lei Lu recently reported that nfsd4_setclientid_confirm() | 9.8 | — | |
| CVE-2025-38708 | — In the Linux kernel, the following vulnerability has been resolved:
drbd: add missing kref_get in handle_write_conflicts
With `two-primaries` enabled, DRBD tries to detect "concurrent" writes
and ha | 9.8 | — | |
| CVE-2025-38660 | — In the Linux kernel, the following vulnerability has been resolved:
[ceph] parse_longname(): strrchr() expects NUL-terminated string
... and parse_longname() is not guaranteed that. That's the reas | 9.8 | — | |
| CVE-2025-38566 | — In the Linux kernel, the following vulnerability has been resolved:
sunrpc: fix handling of server side tls alerts
Scott Mayhew discovered a security exploit in NFS over TLS in
tls_alert_recv() due | 9.8 | — | |
| CVE-2025-38561 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix Preauh_HashValue race condition
If client send multiple session setup requests to ksmbd,
Preauh_HashValue race conditio | 9.8 | — | |
| CVE-2025-38533 | — In the Linux kernel, the following vulnerability has been resolved:
net: libwx: fix the using of Rx buffer DMA
The wx_rx_buffer structure contained two DMA address fields: 'dma' and
'page_dma'. Howe | 9.8 | — | |
| CVE-2025-38527 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix use-after-free in cifs_oplock_break
A race condition can occur in cifs_oplock_break() leading to a
use-after-free | 9.8 | — | |
| CVE-2025-38490 | — In the Linux kernel, the following vulnerability has been resolved:
net: libwx: remove duplicate page_pool_put_full_page()
page_pool_put_full_page() should only be invoked when freeing Rx buffers
or | 9.8 | — | |
| CVE-2025-38488 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix use-after-free in crypt_message when using async crypto
The CVE-2024-50047 fix removed asynchronous crypto handli | 9.8 | — | |
| CVE-2025-38476 | — In the Linux kernel, the following vulnerability has been resolved:
rpl: Fix use-after-free in rpl_do_srh_inline().
Running lwt_dst_cache_ref_loop.sh in selftest with KASAN triggers
the splat below | 9.8 | — | |
| CVE-2025-38472 | — In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack: fix crash due to removal of uninitialised entry
A crash in conntrack was reported while trying to unlink | 9.8 | — | |
| CVE-2025-38471 | — In the Linux kernel, the following vulnerability has been resolved:
tls: always refresh the queue when reading sock
After recent changes in net-next TCP compacts skbs much more
aggressively. This un | 9.8 | — | |
| CVE-2025-38439 | — In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
When transmitting an XDP_REDIRECT packet, call dma_unmap_len_set()
with the | 9.8 | — | |
| CVE-2025-38430 | — In the Linux kernel, the following vulnerability has been resolved:
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
If the request being processed is not a v4 compound request, | 9.8 | — | |
| CVE-2025-38411 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix double put of request
If a netfs request finishes during the pause loop, it will have the ref
that belongs to the IN_PR | 9.8 | — | |
| CVE-2025-38325 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add free_transport ops in ksmbd connection
free_transport function for tcp connection can be called from smbdirect.
It will | 9.8 | — | |
| CVE-2025-38264 | — In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: sanitize request list handling
Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of
any list, otherw | 9.8 | — | |
| CVE-2025-38246 | — In the Linux kernel, the following vulnerability has been resolved:
bnxt: properly flush XDP redirect lists
We encountered following crash when testing a XDP_REDIRECT feature
in production:
[56251. | 9.8 | — | |
| CVE-2025-38211 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
The commit 59c68ac31e15 ("iw_cm: free cm_id resources on the | 9.8 | — | |
| CVE-2025-38209 | — In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: remove tag set when second admin queue config fails
Commit 104d0e2f6222 ("nvme-fabrics: reset admin connection for secur | 9.8 | — | |
| CVE-2025-38139 | — In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix oops in write-retry from mis-resetting the subreq iterator
Fix the resetting of the subrequest iterator in netfs_retry_ | 9.8 | — | |
| CVE-2025-38123 | — In the Linux kernel, the following vulnerability has been resolved:
net: wwan: t7xx: Fix napi rx poll issue
When driver handles the napi rx polling requests, the netdev might
have been released by t | 9.8 | — | |
| CVE-2025-38089 | — In the Linux kernel, the following vulnerability has been resolved:
sunrpc: handle SVC_GARBAGE during svc auth processing as auth error
tianshuo han reported a remotely-triggerable crash if the clie | 9.8 | — | |
| CVE-2025-38075 | — In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Fix timeout on deleted connection
NOPIN response timer may expire on a deleted connection and crash with
such | 9.8 | — | |
| CVE-2025-37935 | — In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM
If the mtk_poll_rx() function detects the MTK_RESETTING flag, it will
jump | 9.8 | — | |
| CVE-2025-37894 | — In the Linux kernel, the following vulnerability has been resolved:
net: use sock_gen_put() when sk_state is TCP_TIME_WAIT
It is possible for a pointer of type struct inet_timewait_sock to be
return | 9.8 | — | |
| CVE-2025-37879 | — In the Linux kernel, the following vulnerability has been resolved:
9p/net: fix improper handling of bogus negative read/write replies
In p9_client_write() and p9_client_read_once(), if the server
i | 9.8 | — | |
| CVE-2025-37750 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix UAF in decryption with multichannel
After commit f7025d861694 ("smb: client: allocate crypto only for
primary ser | 9.8 | — | |
| CVE-2025-22110 | — In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink_queue: Initialize ctx to avoid memory allocation error
It is possible that ctx in nfqnl_build_packet_message( | 9.8 | — | |
| CVE-2025-22088 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/erdma: Prevent use-after-free in erdma_accept_newconn()
After the erdma_cep_put(new_cep) being called, new_cep will be freed, | 9.8 | — | |
| CVE-2025-22077 | — In the Linux kernel, the following vulnerability has been resolved:
Revert "smb: client: fix TCP timers deadlock after rmmod"
This reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.
Commit e9 | 9.8 | — | |
| CVE-2025-21988 | — In the Linux kernel, the following vulnerability has been resolved:
fs/netfs/read_collect: add to next->prev_donated
If multiple subrequests donate data to the same "next" request
(depending on the | 9.8 | — | |
| CVE-2025-21954 | — In the Linux kernel, the following vulnerability has been resolved:
netmem: prevent TX of unreadable skbs
Currently on stable trees we have support for netmem/devmem RX but not
TX. It is not safe to | 9.8 | — | |
| CVE-2025-21927 | — In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
nvme_tcp_recv_pdu() doesn't check the validity of the header leng | 9.8 | — | |
| CVE-2025-21850 | — In the Linux kernel, the following vulnerability has been resolved:
nvmet: Fix crash when a namespace is disabled
The namespace percpu counter protects pending I/O, and we can
only safely diable the | 9.8 | — | |
| CVE-2025-21829 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix the warning "__rxe_cleanup+0x12c/0x170 [rdma_rxe]"
The Call Trace is as below:
"
<TASK>
? show_regs.cold+0x1a/0x | 9.8 | — | |
| CVE-2025-21805 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/rtrs: Add missing deinit() call
A warning is triggered when repeatedly connecting and disconnecting the
rnbd:
list_add corru | 9.8 | — | |
| CVE-2025-21796 | — In the Linux kernel, the following vulnerability has been resolved:
nfsd: clear acl_access/acl_default after releasing them
If getting acl_default fails, acl_access and acl_default will be released
| 9.8 | — | |
| CVE-2025-21748 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix integer overflows on 32 bit systems
On 32bit systems the addition operations in ipc_msg_alloc() can
potentially overflo | 9.8 | — | |
| CVE-2025-21707 | — In the Linux kernel, the following vulnerability has been resolved:
mptcp: consolidate suboption status
MPTCP maintains the received sub-options status is the bitmask carrying
the received suboption | 9.8 | — | |
| CVE-2025-21673 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double free of TCP_Server_Info::hostname
When shutting down the server in cifs_put_tcp_session(), cifsd thread
mi | 9.8 | — | |
| CVE-2026-51302 | — SQLite 3.41 has a use-after-free vulnerability exists in the expression evaluation logic. The sqlite3ReleaseTempReg function improperly releases temporary register resources, and the subsequent exprCo | 9.8 | — | |
| CVE-2026-46634 | — Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyI | 9.8 | — | |
| CVE-2026-53633 | — Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without bein | 9.8 | — | |
| CVE-2026-54658 | — Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substit | 9.8 | — | |
| CVE-2026-66713 | — Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat
(only when Tribes clustering i | 9.8 | — | |
| CVE-2026-60880 | — Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabil | 9.8 | — | |
| CVE-2026-60535 | — Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. E | 9.8 | — | |
| CVE-2026-60532 | — Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. E | 9.8 | — | |
| CVE-2026-60362 | — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulner | 9.8 | — | |
| CVE-2026-60355 | — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita | 9.8 | — | |
| CVE-2026-60202 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.8 | — | |
| CVE-2026-55971 | — Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 9.8 | — | |
| CVE-2026-16634 | — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.
The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly r | 9.8 | — | |
| CVE-2026-65590 | — n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands exec | 9.8 | — | |
| CVE-2026-61167 | — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated a | 9.8 | — | |
| CVE-2026-60308 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | — | |
| CVE-2026-60306 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60302 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60290 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | — | |
| CVE-2026-60275 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60274 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60272 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-16766 | — Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.
Options are passed directly to the wkhtmltopdf command without sanitization.
An | 9.8 | — | |
| CVE-2026-61196 | — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vu | 9.8 | — | |
| CVE-2026-61065 | — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita | 9.8 | — | |
| CVE-2026-60329 | — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vu | 9.8 | — | |
| CVE-2026-60328 | — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita | 9.8 | — | |
| CVE-2026-64530 | — In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
tcf_classify() can return TC_ACT_CONSUMED while the skb is held by | 9.8 | — | |
| CVE-2026-64523 | — In the Linux kernel, the following vulnerability has been resolved:
net/handshake: Take a long-lived file reference at submit
handshake_nl_accept_doit() needs the file pointer backing
req->hr_sk->sk | 9.8 | — | |
| CVE-2026-64459 | — In the Linux kernel, the following vulnerability has been resolved:
tcp: restore RCU grace period in tcp_ao_destroy_sock
Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU")
remove | 9.8 | — | |
| CVE-2026-64439 | — In the Linux kernel, the following vulnerability has been resolved:
crypto: krb5 - filter out async aead implementations at alloc
krb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and | 9.8 | — | |
| CVE-2026-64410 | — In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: IPIP tunnel hardware offload is not yet support
No driver supports for IPIP tunnels yet, give up early on se | 9.8 | — | |
| CVE-2026-64399 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrite | 9.8 | — | |
| CVE-2026-64397 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: serialize QUERY_DIRECTORY requests per file
smb2_query_dir() stores a pointer to its stack-allocated private data in
the ks | 9.8 | — | |
| CVE-2026-64391 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: use opener credentials for ADS I/O
Alternate data streams are stored as xattrs. Unlike regular file I/O,
their read and wri | 9.8 | — | |
| CVE-2026-64387 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix query directory replay double-free
A response-bearing attempt can return a replayable error and free its
response | 9.8 | — | |
| CVE-2026-64386 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix query_info() replay double-free
A response-bearing attempt can return a replayable error and free its
response bu | 9.8 | — | |
| CVE-2026-64385 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_ioctl() replay
A response-bearing attempt can return a replayable error and free its
response | 9.8 | — | |
| CVE-2026-64384 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix change notify replay double-free
A response-bearing attempt can return a replayable error and free its
response b | 9.8 | — | |
| CVE-2026-64383 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_flush() replay
SMB2_flush() keeps its response buffer bookkeeping across replay
attempts. If | 9.8 | — | |
| CVE-2026-64355 | — In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject fragmented frames in devmap
Devmap broadcast redirects clone the packet for all but the last
destination.
For native | 9.8 | — | |
| CVE-2026-64303 | — In the Linux kernel, the following vulnerability has been resolved:
spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
When dmaengine_prep_slave_sg() fails for the TX channel, the e | 9.8 | — | |
| CVE-2026-64268 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: bound Read Response placement to the RREAD length
In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each | 9.8 | — | |
| CVE-2026-64232 | — In the Linux kernel, the following vulnerability has been resolved:
block: recompute nr_integrity_segments in blk_insert_cloned_request
blk_insert_cloned_request() already recomputes nr_phys_segment | 9.8 | — | |
| CVE-2026-27960 | — OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploit | 9.8 | — | |
| CVE-2026-31040 | — A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution. | 9.8 | — | |
| CVE-2026-27143 | — Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading t | 9.8 | — | |
| CVE-2026-30314 | — Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile reg | 9.8 | — | |
| CVE-2026-30311 | — Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile reg | 9.8 | — | |
| CVE-2026-32917 | — OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The | 9.8 | — | |
| CVE-2025-50329 | — An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | 9.8 | — | |
| CVE-2026-61140 | — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability a | 9.8 | — | |
| CVE-2026-61100 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.8 | — | |
| CVE-2026-60566 | — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vu | 9.8 | — | |
| CVE-2026-60460 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.8 | — | |
| CVE-2026-60446 | — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily ex | 9.8 | — | |
| CVE-2026-60435 | — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable | 9.8 | — | |
| CVE-2026-60285 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60236 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60230 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60229 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60228 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60227 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60226 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60225 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60224 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60221 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60219 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | — | |
| CVE-2026-60216 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60215 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60212 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-60210 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulner | 9.8 | — | |
| CVE-2026-60209 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.8 | — | |
| CVE-2026-46994 | — Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploita | 9.8 | — | |
| CVE-2026-46924 | — Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to | 9.8 | — | |
| CVE-2026-46876 | — Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle | 9.8 | — | |
| CVE-2026-35290 | — Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to | 9.8 | — | |
| CVE-2026-42601 | — ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl | 9.8 | — | |
| CVE-2026-42257 | — Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is | 9.8 | — | |
| CVE-2026-42302 | — FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The start | 9.8 | — | |
| CVE-2026-34084 | — PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when th | 9.8 | — | |
| CVE-2026-38428 | — Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitizat | 9.8 | — | |
| CVE-2026-38431 | — ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on | 9.8 | — | |
| CVE-2026-38429 | — OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml. | 9.8 | — | |
| CVE-2026-39890 | — PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/functio | 9.8 | — | |
| CVE-2026-33229 | — XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script | 9.8 | — | |
| CVE-2026-33088 | — Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. | 9.8 | — | |
| CVE-2026-31789 | — Issue summary: Converting an excessively large OCTET STRING value to
a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.
Impact summary: A heap buffer overflow may lead to a cra | 9.8 | — | |
| CVE-2026-33439 | — Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deseriali | 9.8 | — | |
| CVE-2026-35471 | — goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3. | 9.8 | — | |
| CVE-2026-35393 | — goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3. | 9.8 | — | |
| CVE-2026-35392 | — goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3. | 9.8 | — | |
| CVE-2026-35184 | — EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is | 9.8 | — | |
| CVE-2026-35178 | — Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerab | 9.8 | — | |
| CVE-2026-35171 | — Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without | 9.8 | — | |
| CVE-2026-31405 | — In the Linux kernel, the following vulnerability has been resolved:
media: dvb-net: fix OOB access in ULE extension header tables
The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tab | 9.8 | — | |
| CVE-2019-25687 | — Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionalit | 9.8 | — | |
| CVE-2018-25254 | — NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to | 9.8 | — | |
| CVE-2026-34935 | — PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and forwarded through the call chain to anyio.open_pro | 9.8 | — | |
| CVE-2026-34934 | — PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with unescaped thread IDs fetched from the database. An a | 9.8 | — | |
| CVE-2026-27634 | — Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_cre | 9.8 | — | |
| CVE-2026-35053 | — OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId a | 9.8 | — | |
| CVE-2026-34877 | — An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the seri | 9.8 | — | |
| CVE-2026-33746 | — Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature of JWT token | 9.8 | — | |
| CVE-2026-34400 | — Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-sup | 9.8 | — | |
| CVE-2026-1579 | — The MAVLink communication protocol does not require cryptographic
authentication by default. When MAVLink 2.0 message signing is not
enabled, any message -- including SERIAL_CONTROL, which provides | 9.8 | — | |
| CVE-2026-30285 | — An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code executi | 9.8 | — | |
| CVE-2026-30286 | — An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code e | 9.8 | — | |
| CVE-2026-34243 | — wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_com | 9.8 | — | |
| CVE-2026-34220 | — MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted | 9.8 | — | |
| CVE-2026-30281 | — An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information | 9.8 | — | |
| CVE-2026-30276 | — An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or | 9.8 | — | |
| CVE-2026-16389 | — Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | — | |
| CVE-2026-48689 | — FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, | 9.8 | — | |
| CVE-2026-3660 | — IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the app | 9.8 | — | |
| CVE-2026-48904 | — An improper access check allows privelege escalation through the com_users group editing webservice endpoint. | 9.8 | — | |
| CVE-2026-48902 | — The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | 9.8 | — | |
| CVE-2026-48899 | — An improper access check allows privilege escalation through the com_users batch task. | 9.8 | — | |
| CVE-2026-48898 | — An improper access check allows privilege escalation through the com_users batch task. | 9.8 | — | |
| CVE-2026-48691 | — FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attri | 9.8 | — | |
| CVE-2026-40383 | — An improper validation of user-supplied input leads to a local file inclusion vulnerability. | 9.8 | — | |
| CVE-2026-35223 | — An improper access check allows unauthorized access to com_config webservice endpoints. | 9.8 | — | |
| CVE-2026-35222 | — Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | 9.8 | — | |
| CVE-2026-35221 | — Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | 9.8 | — | |
| CVE-2026-48686 | — FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() i | 9.8 | — | |
| CVE-2026-24207 | — NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of p | 9.8 | — | |
| CVE-2026-7261 | — In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted acro | 9.8 | — | |
| CVE-2026-5902 | — Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium | 9.8 | — | |
| CVE-2026-8495 | — Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.
This issue affects Date iCal: from 0.0.0 before 4.0.15. | 9.8 | — | |
| CVE-2026-8605 | — In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin. | 9.8 | — | |
| CVE-2026-8603 | — In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system. | 9.8 | — | |
| CVE-2026-8838 | — Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary c | 9.8 | — | |
| CVE-2017-10685 | — In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack. | 9.8 | — | |
| CVE-2017-10684 | — In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack. | 9.8 | — | |
| CVE-2026-11526 | — GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle.
GD::Image::_make_filehandle opens a filename argument with | 9.8 | — | |
| CVE-2026-49841 | — FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version | 9.8 | — | |
| CVE-2026-47643 | — External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | 9.8 | — | |
| CVE-2026-46325 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
The current implementation incorrectly handles memory regions ( | 9.8 | — | |
| CVE-2026-5067 | — A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the heade | 9.8 | — | |
| CVE-2026-52778 | — YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to san | 9.8 | — | |
| CVE-2026-44631 | — Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to | 9.8 | — | |
| CVE-2026-29167 | — Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to | 9.8 | — | |
| CVE-2026-45779 | — OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to | 9.8 | — | |
| CVE-2026-45777 | — OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web se | 9.8 | — | |
| CVE-2026-11420 | — Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on | 9.8 | — | |
| CVE-2026-8633 | — IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code executio | 9.8 | — | |
| CVE-2026-8376 | — Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c checked the size of the | 9.8 | — | |
| CVE-2026-16412 | — Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited | 9.8 | — | |
| CVE-2026-16411 | — Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. | 9.8 | — | |
| CVE-2026-16408 | — Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | — | |
| CVE-2026-16395 | — Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.8 | — | |
| CVE-2026-49448 | — authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2 | 9.8 | — | |
| CVE-2026-38967 | — CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. | 9.8 | — | |
| CVE-2026-42074 | — OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool | 9.8 | — | |
| CVE-2026-7198 | — CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in fu | 9.8 | — | |
| CVE-2018-25412 | — Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form | 9.8 | — | |
| CVE-2026-45697 | — Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as T | 9.8 | — | |
| CVE-2026-44649 | — SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, | 9.8 | — | |
| CVE-2026-41252 | — xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during t | 9.8 | — | |
| CVE-2026-35048 | — The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, th | 9.8 | — | |
| CVE-2026-25879 | — Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When | 9.8 | — | |
| CVE-2026-48687 | — FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (li | 9.8 | — | |
| CVE-2026-47429 | — Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path t | 9.8 | — | |
| CVE-2026-45288 | — Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated | 9.8 | — | |
| CVE-2016-20052 | — Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can u | 9.8 | — | |
| CVE-2026-9103 | — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived | 9.8 | — | |
| CVE-2026-44668 | — FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invok | 9.8 | — | |
| CVE-2026-63979 | — In the Linux kernel, the following vulnerability has been resolved:
net/handshake: hand off the pinned file reference to accept_doit
handshake_req_next() removes the request from the per-net
pending | 9.8 | — | |
| CVE-2026-63978 | — In the Linux kernel, the following vulnerability has been resolved:
net/handshake: Drain pending requests at net namespace exit
The arguments to list_splice_init() in handshake_net_exit() are
revers | 9.8 | — | |
| CVE-2026-63825 | — In the Linux kernel, the following vulnerability has been resolved:
gcov: use atomic counter updates to fix concurrent access crashes
GCC's GCOV instrumentation can merge global branch counters with | 9.8 | — | |
| CVE-2026-63808 | — In the Linux kernel, the following vulnerability has been resolved:
exfat: fix potential use-after-free in exfat_find_dir_entry()
In exfat_find_dir_entry(), the buffer_head obtained from
exfat_get_d | 9.8 | — | |
| CVE-2026-63800 | — In the Linux kernel, the following vulnerability has been resolved:
pNFS: Fix use-after-free in pnfs_update_layout()
When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(),
the code calls | 9.8 | — | |
| CVE-2026-53399 | — In the Linux kernel, the following vulnerability has been resolved:
nfsd: release layout stid on setlease failure
nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via
idr_alloc_cyclic() | 9.8 | — | |
| CVE-2026-53398 | — In the Linux kernel, the following vulnerability has been resolved:
NFSD: Fix SECINFO_NO_NAME decode error cleanup
nfsd4_decode_secinfo_no_name() currently initializes sin_exp after
decoding sin_sty | 9.8 | — | |
| CVE-2026-53384 | — In the Linux kernel, the following vulnerability has been resolved:
serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
dw8250_probe() registers the 8250 port via serial8250_regis | 9.8 | — | |
| CVE-2026-13446 | — IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external com | 9.8 | — | |
| CVE-2026-8505 | — IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses | 9.8 | — | |
| CVE-2026-46562 | — Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorith | 9.8 | — | |
| CVE-2026-53363 | — In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
iptfs_consume_frags() transfers paged fragments from one socket | 9.8 | — | |
| CVE-2026-53355 | — In the Linux kernel, the following vulnerability has been resolved:
net: rds: clear i_sends on setup unwind
The RDS IB connection teardown path is written so it can run during
partial startup and on | 9.8 | — | |
| CVE-2026-58479 | Sustainable Irrigation Platform (SIP) Command Injection (OS Command Injection via CLI Control Plugin HTTP Endpoint) | 9.8 | — | |
| CVE-2026-58123 | Hermes WebUI Unauthenticated Remote Code Execution via Terminal API (Missing Authentication for Critical Function) | 9.8 | — | |
| CVE-2026-58466 | AutoBangumi Hard-coded default credentials authentication bypass | 9.8 | — | |
| CVE-2026-58455 | Dockwatch Unauthenticated OS Command Injection RCE | 9.8 | — | |
| CVE-2026-58449 | txtai Unsafe Reflection / Arbitrary Code Execution via API endpoint (CWE-94) | 9.8 | — | |
| CVE-2026-58138 | Orkes Conductor Unauthenticated Remote Code Execution via unsandboxed GraalVM script evaluation | 9.8 | — | 3 PoC
|
| CVE-2026-58116 | LLaMA-Factory Remote Code Execution via unvalidated user-supplied model path with trust_remote_code=True | 9.8 | — | 1 PoC
|
| CVE-2026-56782 | Gorse Authentication Bypass (CWE-306) — Missing Authentication for Critical Function on /api/dump and /api/restore endpoints | 9.8 | — | 2 PoC
|
| CVE-2026-56786 | RTKLIB Out-of-bounds write (stack/heap buffer overflow) via crafted RTCM3 message | 9.8 | — | |
| CVE-2026-56121 | Feast (feast-dev/feast) Unsafe deserialization RCE via dill.loads() in gRPC registry server | 9.8 | — | 1 PoC
|
| CVE-2026-53805 | NVIDIA GEN3C Unauthenticated Python pickle deserialization RCE | 9.8 | — | 1 PoC
|
| CVE-2026-47103 | python-statemachine SCXML eval injection RCE (CWE-95/CWE-94) | 9.8 | — | 1 PoC
|
| CVE-2026-47117 | openmed Remote Code Execution via unsafe Hugging Face model loading (trust_remote_code=True) — CWE-94 Code Injection | 9.8 | — | |
| CVE-2026-34415 | Xerte Online Toolkits Incomplete input validation / unrestricted file upload leading to RCE (authentication bypass + path traversal + PHP extension bypass) | 9.8 | — | 1 PoC
|
| CVE-2026-39918 | Vvveb PHP Code Injection / Unauthenticated Remote Code Execution | 9.8 | — | |
| CVE-2026-40504 | Creolabs Gravity Heap Buffer Overflow RCE | 9.8 | — | |
| CVE-2026-35002 | agno eval() injection arbitrary code execution (CWE-95) | 9.8 | — | |
| CVE-2026-29515 | MiCode FileExplorer (SwiFTP FTP server) Authentication Bypass via Unconditional PASS Command Authorization | 9.8 | — | |
| CVE-2026-28517 | openDCIM OS Command Injection (CWE-78) | 9.8 | — | |
| CVE-2026-26339 | Hyland Alfresco Transformation Service Argument Injection Remote Code Execution (SSRF/RCE via CWE-918) | 9.8 | — | |
| CVE-2025-34468 | libcoap Stack-based buffer overflow in address resolution (CWE-121, CWE-787) | 9.8 | — | |
| CVE-2024-6127 | BC Security Empire C2 Framework Path traversal leading to unauthenticated remote code execution via malicious file upload | 9.8 | — | 2 PoC
|
| CVE-2024-23679 | Enonic XP (com.enonic.xp:lib-auth) Session Fixation (CWE-384) - lack of session invalidation on authentication | 9.8 | — | |
| CVE-2024-22051 | commonmarker Integer overflow leading to heap memory corruption (RCE / information leak) | 9.8 | — | 2 PoC
|
| CVE-2026-62392 | Apache Kylin OS Command Injection (CWE-78) | 9.8 | — | |
| CVE-2026-62390 | Apache Kylin SQL Injection (CWE-89) | 9.8 | — | |
| CVE-2026-9726 | Drupal AlternativeCommerce (Basket) Improperly Controlled Modification of Dynamically-Determined Object Attributes (Object Injection / Mass Assignment) | 9.8 | — | |
| CVE-2026-53088 | Linux Kernel bcmgenet off-by-one error in TX control block pointer management | 9.8 | — | |
| CVE-2026-53086 | Linux Kernel bcmgenet Race condition / timeout handler queue management | 9.8 | — | |
| CVE-2026-25555 | OpenBullet2 Authentication Bypass via Empty API Key Header | 9.8 | — | 1 PoC
|
| CVE-2026-31402 | Linux Kernel Heap buffer overflow (slab-out-of-bounds write) in NFSv4.0 LOCK replay cache | 9.8 | — | 1 PoC
|
| CVE-2026-23450 | Linux Kernel Use-After-Free (UAF) and NULL pointer dereference in SMC TCP SYN receive path | 9.8 | — | |
| CVE-2024-36265 | Apache Submarine Server Core Incorrect Authorization / Authentication Bypass via crafted REST requests | 9.8 | — | 1 PoC
|
| CVE-2026-57156 | FreeRDP Integer overflow leading to heap buffer overflow (CWE-190, CWE-122) | 9.8 | — | 1 PoC
|
| CVE-2026-56271 | Flowise Hardcoded default JWT secret authentication bypass | 9.8 | — | |
| CVE-2026-53010 | Linux Kernel ksmbd use-after-free | 9.8 | — | |
| CVE-2026-53002 | Linux Kernel Stack out-of-bounds write (CWE-787) via sprintf in netfilter conntrack SIP NAT helper | 9.8 | — | |
| CVE-2020-24881 | osTicket Server-Side Request Forgery (SSRF) | 9.8 | — | 2 PoC
|
| CVE-2026-44024 | fluentd Path Traversal via tag placeholder leading to arbitrary file write / RCE (CWE-22) | 9.8 | — | |
| CVE-2026-7840 | UltraVNC repeater Global buffer overflow (pre-auth RCE) in embedded HTTP administration server via unchecked sprintf into fixed-size global buffer | 9.8 | — | |
| CVE-2026-33264 | apache-airflow Insecure Deserialization RCE (CWE-502) via unrestricted import_string() in BaseSerialization.deserialize() | 9.8 | — | |
| CVE-2026-47898 | Apache Lucene.Net (Lucene.Net.Analysis.Common) XML External Entity (XXE) Injection | 9.8 | — | |
| CVE-2026-38968 | ntopng Predictable Session Identifier / Session Hijacking (CWE-341) | 9.8 | — | |
| CVE-2026-46289 | Linux Kernel Memory leak (CWE-401) in scatterlist kvec/user iterator extraction | 9.8 | — | |
| CVE-2026-43414 | Linux Kernel - scsi qla2xxx Double Free (CWE-415) | 9.8 | — | |
| CVE-2026-58521 | Wikimedia Foundation MediaWiki Cargo Extension SQL Injection (CWE-89) | 9.8 | — | |
| CVE-2026-30283 | PEAKSEL D.O.O. NIS Animal Sounds and Ringtones Arbitrary File Overwrite via Path Traversal (CWE-22) | 9.8 | — | 1 PoC
|
| CVE-2026-30278 | FLY is FUN Aviation Navigation Path Traversal Arbitrary File Overwrite (CWE-22) | 9.8 | — | |
| CVE-2025-56422 | LimeSurvey PHP deserialization RCE (CWE-502) | 9.8 | — | |
| CVE-2025-69929 | N3uron Web User Interface Client-side MD5 password hashing privilege escalation | 9.8 | — | |
| CVE-2025-56590 | Apryse HTML2PDF SDK OS Command Injection / Argument Injection RCE (CWE-78) | 9.8 | — | |
| CVE-2025-60534 | Blue Access Cobalt Authentication Bypass via Selective Proxy Request Manipulation | 9.8 | — | |
| CVE-2025-67418 | ClipBucket Hardcoded Default Credentials / Improper Access Control (CWE-798) | 9.8 | — | |
| CVE-2025-56157 | Dify Hard-coded / Default Credentials (CWE-798) | 9.8 | — | |
| CVE-2025-65854 | MineAdmin Insecure Permissions leading to Arbitrary Command Execution (Code Injection) | 9.8 | — | |
| CVE-2025-65882 | openmptcprouter OS Command Injection / Arbitrary File Write (CWE-78) | 9.8 | — | |
| CVE-2025-51683 | mJobtime Blind SQL Injection (unauthenticated) | 9.8 | — | |
| CVE-2025-51682 | mJobtime Client-Side Authorization Bypass (CWE-602) | 9.8 | — | |
| CVE-2025-63747 | QaTraq Default Credentials / Weak Password Policy (CWE-521) | 9.8 | — | 23 PoC
|
| CVE-2025-60307 | code-projects Computer Laboratory System 1.0 SQL Injection Authentication Bypass | 9.8 | — | 18 PoC
|
| CVE-2025-57119 | Online Library Management System Privilege Escalation via Authentication Bypass / Default Credentials | 9.8 | — | 1 PoC
|
| CVE-2025-45150 | LangChain-ChatGLM-Webui Insecure File Permissions / Arbitrary File Read and Download | 9.8 | — | 3 PoC
|
| CVE-2025-44148 | MailEnable Cross-Site Scripting (XSS) | 9.8 | — | 5 PoC
|
| CVE-2025-45949 | PHPGurukul User Registration & Login and User Management System Session Hijacking / Session Fixation (CWE-384) | 9.8 | — | |
| CVE-2025-45947 | phpgurukul Online Banquet Booking System Code Injection (CWE-94) - Arbitrary Code Execution via Change Password component | 9.8 | — | |
| CVE-2025-29287 | MCMS Arbitrary File Upload leading to Remote Code Execution | 9.8 | — | |
| CVE-2024-55160 | GFast SQL Injection via unsanitized OrderBy parameter | 9.8 | — | |
| CVE-2025-25790 | FoxCMS Arbitrary File Upload leading to Remote Code Execution | 9.8 | — | |
| CVE-2025-25789 | FoxCMS Remote Code Execution (RCE) via code injection | 9.8 | — | |
| CVE-2025-25784 | Jizhicms Arbitrary File Upload RCE via crafted Zip file | 9.8 | — | 1 PoC
|
| CVE-2025-25783 | Emlog Pro Arbitrary File Upload leading to Remote Code Execution | 9.8 | — | |
| CVE-2024-53480 | Phpgurukul Beauty Parlour Management System SQL Injection | 9.8 | — | |
| CVE-2024-51065 | Phpgurukul Beauty Parlour Management System SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2024-51064 | Phpgurukul Teachers Record Management System SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2024-46446 | Mecha CMS Directory Traversal / Arbitrary File Deletion / Authentication Bypass via Cookie and URI manipulation (CWE-22) | 9.8 | — | |
| CVE-2024-44902 | ThinkPHP (topthink/framework) PHP deserialization RCE (CWE-502) | 9.8 | — | 20 PoC
|
| CVE-2024-42850 | Silverpeas Weak Password Requirements / Password Complexity Bypass (CWE-521) | 9.8 | — | 1 PoC
|
| CVE-2024-38909 | studio-42/elfinder Incorrect Access Control - Unauthorized file copy with arbitrary extension leading to RCE / secret exposure | 9.8 | — | |
| CVE-2024-37858 | Lost and Found Information System SQL Injection privilege escalation (CWE-89, CWE-269) | 9.8 | — | |
| CVE-2024-39171 | PHPVibe Path Traversal / Directory Traversal leading to RCE via .htaccess and file upload bypass | 9.8 | — | 2 PoC
|
| CVE-2024-33120 | Roothub Arbitrary File Upload leading to Remote Code Execution (RCE) | 9.8 | — | 1 PoC
|
| CVE-2024-32161 | jizhiCMS Unrestricted File Upload (CWE-434) | 9.8 | — | |
| CVE-2024-28713 | Mblog Blog System Unrestricted File Upload leading to Arbitrary Code Execution (CWE-434) | 9.8 | — | |
| CVE-2024-24398 | Stimulsoft Dashboard.JS Directory Traversal / Path Traversal leading to Remote Code Execution | 9.8 | — | 3 PoC
|
| CVE-2024-22901 | Vinchin Backup & Recovery Default Credentials (MySQL) | 9.8 | — | 3 PoC
|
| CVE-2023-36177 | Snapcast JSON-RPC API Remote Code Execution (CWE-94 Code Injection) | 9.8 | — | 1 PoC
|
| CVE-2023-51925 | YonBIP (Yonyou BIP) Arbitrary File Upload leading to Remote Code Execution (RCE) | 9.8 | — | |
| CVE-2023-51924 | YonBIP Arbitrary File Upload leading to Remote Code Execution | 9.8 | — | |
| CVE-2023-51906 | yonyou YonBIP Remote Code Execution via crafted script to servlet endpoint | 9.8 | — | |
| CVE-2023-51928 | YonBIP (Yonyou BIP) Arbitrary File Upload leading to Remote Code Execution (RCE) | 9.8 | — | |
| CVE-2023-51927 | YonBIP SQL Injection | 9.8 | — | |
| CVE-2023-51892 | Weaver e-cology Remote Code Execution via crafted script injection | 9.8 | — | |
| CVE-2023-50643 | Evernote for macOS Electron RunAsNode Arbitrary Code Execution | 9.8 | — | 4 PoC
|
| CVE-2023-47458 | SpringBlade Missing Authorization / Broken Access Control (Privilege Escalation) | 9.8 | — | |
| CVE-2023-46958 | lmxcms Remote Code Execution via crafted script (Code Injection) | 9.8 | — | |
| CVE-2023-46010 | SeaCMS Arbitrary Code Execution via PHP component (CWE-94 Code Injection) | 9.8 | — | 1 PoC
|
| CVE-2023-45379 | posrotatorimg (Rotator Img) PrestaShop module by PosThemes SQL Injection (unauthenticated/guest) | 9.8 | — | |
| CVE-2023-43234 | DedeBIZ Remote Code Execution (RCE) via file management parameter injection | 9.8 | — | 1 PoC
|
| CVE-2023-41009 | adlered bolo-solo Unrestricted File Upload RCE (CWE-434) | 9.8 | — | 1 PoC
|
| CVE-2023-38894 | tree-kit Prototype Pollution | 9.8 | — | 1 PoC
|
| CVE-2023-30187 | ONLYOFFICE DocumentServer Out-of-bounds write (OOB memory access) leading to Remote Code Execution via crafted JavaScript file | 9.8 | — | 2 PoC
|
| CVE-2023-30186 | ONLYOFFICE DocumentServer Use After Free (UAF) Remote Code Execution via crafted JavaScript | 9.8 | — | 2 PoC
|
| CVE-2023-37847 | novel-plus SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2023-39004 | OPNsense Insecure file/directory permissions leading to sensitive information disclosure and privilege escalation (CWE-732) | 9.8 | — | 1 PoC
|
| CVE-2023-36095 | langchain Arbitrary Code Execution via python exec() in PALChain | 9.8 | — | |
| CVE-2023-38954 | ZKTeco BioAccess IVS SQL Injection | 9.8 | — | |
| CVE-2023-34960 | Chamilo LMS Command Injection via SOAP API (CWE-77) | 9.8 | — | 26 PoC
|
| CVE-2023-34842 | DedeCMS Remote Code Execution via crafted POST request (Code Injection) | 9.8 | — | |
| CVE-2023-37647 | SEMCMS SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2023-33668 | DigiExam Insufficient integrity verification of native modules (CWE-354) | 9.8 | — | 1 PoC
|
| CVE-2023-34752 | bloofox CMS SQL Injection | 9.8 | — | |
| CVE-2023-34944 | Chamilo LMS Arbitrary File Upload leading to Remote Code Execution (SVG upload) | 9.8 | — | 1 PoC
|
| CVE-2023-30185 | CRMEB Arbitrary File Upload (Unrestricted File Upload RCE) | 9.8 | — | 1 PoC
|
| CVE-2023-30242 | NS-ASG (Netentsec Application Security Gateway) SQL Injection (CWE-89) | 9.8 | — | |
| CVE-2022-46640 | Nanoleaf Desktop App Command Injection via crafted HTTP request | 9.8 | — | 1 PoC
|
| CVE-2023-27667 | Auto Dealer Management System SQL Injection | 9.8 | — | |
| CVE-2023-27779 | AM Presencia SQL Injection (CWE-89) in login form user parameter | 9.8 | — | 1 PoC
|
| CVE-2021-28235 | etcd (etcd-io) Authentication Bypass / Privilege Escalation via debug function (CWE-287) | 9.8 | — | |
| CVE-2023-25261 | Stimulsoft Designer/Viewer Remote Code Execution via local file system access (CWE-94 Code Injection) | 9.8 | — | 1 PoC
|
| CVE-2022-46501 | Accruent Maintenance Connection SQL Injection (CWE-89) | 9.8 | — | |
| CVE-2021-33224 | Umbraco Forms Unrestricted File Upload leading to Remote Code Execution (CWE-434) | 9.8 | — | |
| CVE-2023-24080 | Chamberlain myQ Lack of rate limiting on password reset endpoint enabling brute-force account takeover | 9.8 | — | 1 PoC
|
| CVE-2022-47003 | Mura CMS Authentication Bypass via Remember Me function | 9.8 | — | 1 PoC
|
| CVE-2022-47770 | Serenissima Informatica Fast Checkin Unauthenticated SQL Injection | 9.8 | — | |
| CVE-2022-47769 | Serenissima Informatica Fast Checkin Unrestricted File Upload / Arbitrary File Write leading to Web Shell RCE | 9.8 | — | |
| CVE-2020-22452 | phpMyAdmin SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-40434 | Softr HTML Injection (Stored XSS) | 9.8 | — | |
| CVE-2022-44945 | Rukovoditel SQL Injection | 9.8 | — | 2 PoC
|
| CVE-2022-44291 | webTareas SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-44290 | webTareas SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-45207 | jeecg-boot (jeecg-module-system) SQL Injection (CWE-89) | 9.8 | — | 2 PoC
|
| CVE-2022-45206 | jeecg-boot SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-36179 | FusionDirectory Improper Session Handling / Insufficient Session Expiration (CWE-613) | 9.8 | — | |
| CVE-2022-42122 | Liferay Portal / Liferay DXP - Friendly URL module SQL Injection (CWE-89) via Friendly URL title field | 9.8 | — | |
| CVE-2022-42120 | Liferay Portal / Liferay DXP Fragment Module SQL Injection via PortletPreferences namespace attribute | 9.8 | — | |
| CVE-2022-44089 | ESPCMS Remote Code Execution (RCE) via code injection | 9.8 | — | |
| CVE-2022-44088 | ESPCMS Remote Code Execution (RCE) via Code Injection | 9.8 | — | |
| CVE-2022-44087 | ESPCMS Remote Code Execution (RCE) via file upload / code injection | 9.8 | — | |
| CVE-2022-40030 | SourceCodester Simple Task Managing System SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-36202 | Doctor's Appointment System Insecure Direct Object Reference (IDOR) / Broken Access Control | 9.8 | — | 1 PoC
|
| CVE-2022-36262 | taocms PHP Code Injection via config.php modification | 9.8 | — | 1 PoC
|
| CVE-2022-33047 | OTFCC Heap buffer overflow after free (CWE-787) | 9.8 | — | 1 PoC
|
| CVE-2022-29704 | BrowsBox CMS SQL Injection | 9.8 | — | 30 PoC
|
| CVE-2022-30490 | Badminton Center Management System SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-28118 | SiteServer CMS (SSCMS) Arbitrary Code Execution via Malicious Plug-in | 9.8 | — | 4 PoC
|
| CVE-2022-27985 | CuppaCMS SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-27984 | CuppaCMS SQL Injection | 9.8 | — | 1 PoC
|
| CVE-2022-28093 | SCBS Online Sports Venue Reservation System Local File Inclusion (LFI) leading to Remote Code Execution | 9.8 | — | |
| CVE-2022-27262 | Skipper Arbitrary File Upload leading to Remote Code Execution (CWE-434) | 9.8 | — | 5 PoC
|
| CVE-2022-27260 | ButterCMS Arbitrary File Upload leading to Remote Code Execution (SVG upload) | 9.8 | — | |
| CVE-2021-37291 | KevinLAB Inc 4ST BEMS (Building Energy Management System) SQL Injection (CWE-89) | 9.8 | — | |
| CVE-2022-26646 | Online Banking System Protect Local File Inclusion (LFI) | 9.8 | — | |
| CVE-2022-26645 | Online Banking System Protect Unrestricted File Upload leading to Remote Code Execution (RCE) | 9.8 | — | |
| CVE-2022-25578 | taocms Code Injection via arbitrary .htaccess file edit | 9.8 | — | 2 PoC
|
| CVE-2021-45834 | OpenDocMan Unrestricted File Upload via MIME-type bypass (CWE-434) | 9.8 | — | |
| CVE-2021-44088 | Sourcecodester Attendance and Payroll System SQL Injection Authentication Bypass | 9.8 | — | |
| CVE-2021-44087 | Sourcecodester Attendance and Payroll System Unauthenticated File Upload Remote Code Execution (RCE) | 9.8 | — | |
| CVE-2022-25089 | Printix Secure Cloud Print Management Improper Privilege Management / Privileged API Abuse (CWE-269) | 9.8 | — | 27 PoC
|
| CVE-2022-22916 | O2OA Remote Code Execution (RCE) | 9.8 | — | 28 PoC
|
| CVE-2021-42637 | PrinterLogic Web Stack Server Side Request Forgery (SSRF) | 9.8 | — | 7 PoC
|
| CVE-2021-45807 | JPress Remote Code Execution via malicious addon upload | 9.8 | — | |
| CVE-2021-42216 | AnonAddy Broken or Risky Cryptographic Algorithm (CWE-326) | 9.8 | — | |
| CVE-2021-41716 | Maharashtra State Electricity Board Mahavitaran Android Application OTP Fixation Account Takeover (CWE-287 Authentication Bypass) | 9.8 | — | |
| CVE-2021-36582 | Kooboo CMS Unrestricted File Upload (Remote Shell Upload / RCE) | 9.8 | — | 2 PoC
|
| CVE-2021-36581 | Kooboo CMS Unrestricted File Upload (CWE-434) | 9.8 | — | 1 PoC
|
| CVE-2020-24914 | qcubed/qcubed PHP Object Injection / Deserialization RCE (CWE-502) | 9.8 | — | 1 PoC
|
| CVE-2020-24913 | qcubed/qcubed SQL Injection (CWE-89) | 9.8 | — | 4 PoC
|
| CVE-2020-24841 | PNPSCADA SQL Injection | 9.8 | — | |
| CVE-2017-15681 | Crafter CMS Crafter Studio Directory Traversal / Path Traversal leading to unauthenticated arbitrary file overwrite and RCE (CWE-22) | 9.8 | — | |
| CVE-2020-25466 | CRMEB Server-Side Request Forgery (SSRF) leading to Remote Code Execution | 9.8 | — | 1 PoC
|
| CVE-2018-5353 | Zoho ManageEngine ADSelfService Plus Authentication Spoofing via Custom GINA/CP Module leading to RCE / Privilege Escalation (CWE-290) | 9.8 | — | 2 PoC
|
| CVE-2020-24193 | Daily Tracker System SQL Injection Authentication Bypass | 9.8 | — | 1 PoC
|
| CVE-2026-7871 | IBM Langflow OSS Insecure Deserialization RCE via Redis (CWE-502) | 9.8 | — | |
| CVE-2026-7803 | IBM Langflow OSS Arbitrary Code Execution via improper validation of flow nodes | 9.8 | — | |
| CVE-2026-9158 | Eclipse 4diac FORTE Use-After-Free (CWE-416) | 9.8 | — | |
| CVE-2026-13776 | Google Chrome Dawn (WebGPU) Type Confusion sandbox escape | 9.8 | — | |
| CVE-2026-13775 | Google Chrome Use-After-Free GPU sandbox escape | 9.8 | — | |
| CVE-2026-13763 | AWS Application Load Balancer (ALB) with AWS WAF HTTP Request Smuggling / Inconsistent HTTP/2 Request Interpretation (WAF Bypass) - CWE-444 | 9.8 | — | |
| CVE-2026-13762 | Amazon CloudFront with AWS WAF HTTP/2 request smuggling / WAF body inspection bypass (CWE-444: Inconsistent Interpretation of HTTP Requests) | 9.8 | — | |
| CVE-2026-47065 | Apache (Java deserialization filter library — likely Apache Commons IO / SerialKiller / similar acceptMatchers-based filter) Java deserialization filter bypass via resolveProxyClass not overridden and static initializer trigger (CWE-502) | 9.8 | — | |
| CVE-2026-12293 | Firefox / Thunderbird (WebGPU) Use-after-free in WebGPU graphics component (CWE-416 / CWE-825) | 9.8 | — | |
| CVE-2026-33278 | NLnet Labs Unbound Use-After-Free (UAF) / Dangling Pointer via deep copy struct-assignment bug enabling DoS and possible RCE in DNSSEC validator | 9.8 | — | |
| CVE-2026-44484 | PyTorch Lightning Embedded Malicious Code / Credential Harvesting (Backdoor) | 9.8 | — | |
| CVE-2026-8401 | Mozilla Firefox / Thunderbird Sandbox escape via Profile Backup component (Protection Mechanism Failure / Insufficient Compartmentalization) | 9.8 | — | |
| CVE-2026-6722 | PHP SOAP extension Use-after-free (UAF) / dangling pointer via SOAP object deduplication leading to Remote Code Execution | 9.8 | — | |
| CVE-2025-14179 | PHP PDO Firebird driver SQL Injection via NUL byte handling in PDO Firebird driver (CWE-89) | 9.8 | — | |
| CVE-2026-35579 | CoreDNS TSIG authentication bypass (improper verification / CWE-287, CWE-303) | 9.8 | — | |
| CVE-2026-42027 | Apache OpenNLP Arbitrary Class Instantiation via static initializer execution during model manifest parsing (CWE-470 unsafe reflection, CWE-502 deserialization of untrusted data) | 9.8 | — | |
| CVE-2026-26956 | vm2 Sandbox Escape with Arbitrary Code Execution | 9.8 | — | 1 PoC
|
| CVE-2026-26332 | vm2 Sandbox escape via SuppressedError leading to arbitrary code execution | 9.8 | — | 1 PoC
|
| CVE-2026-24120 | vm2 Sandbox Escape / Arbitrary Code Execution (bypass of CVE-2023-37466 fix) | 9.8 | — | 1 PoC
|
| CVE-2026-24118 | vm2 Sandbox Breakout / Arbitrary Code Execution | 9.8 | — | 2 PoC
|
| CVE-2026-40860 | Apache Camel Java deserialization RCE via JMS ObjectMessage | 9.8 | — | 1 PoC
|
| CVE-2026-41179 | Rclone Unauthenticated Remote Code Execution via OS Command Injection in RC endpoint (CWE-78, CWE-306, CWE-94) | 9.8 | — | 2 PoC
|
| CVE-2026-41176 | Rclone Missing Authentication for Critical Function / Unauthenticated Global Configuration Mutation (CWE-306, CWE-15) | 9.8 | — | 1 PoC
|
| CVE-2026-6748 | Firefox / Thunderbird Web Codecs Uninitialized memory read/use (CWE-457, CWE-824) in Audio/Video Web Codecs component | 9.8 | — | |
| CVE-2026-21413 | LibRaw Heap-based buffer overflow | 9.8 | — | |
| CVE-2026-20911 | LibRaw heap-based buffer overflow | 9.8 | — | |
| CVE-2026-20889 | LibRaw Heap-based buffer overflow (integer overflow leading to buffer overflow) | 9.8 | — | |
| CVE-2026-5735 | Firefox / Thunderbird Memory safety bugs / memory corruption leading to arbitrary code execution (out-of-bounds read/write) | 9.8 | — | |
| CVE-2026-5734 | Mozilla Firefox / Thunderbird Memory safety bugs / buffer overflow / out-of-bounds write leading to arbitrary code execution | 9.8 | — | |
| CVE-2026-5731 | Mozilla Firefox / Firefox ESR / Thunderbird Memory safety bugs / buffer overflow / out-of-bounds write (CWE-119, CWE-787) leading to potential arbitrary code execution | 9.8 | — | |
| CVE-2026-0545 | mlflow Authentication bypass / Missing authentication for critical function (CWE-306) leading to unauthenticated RCE | 9.8 | — | |
| CVE-2025-15379 | MLflow Command Injection (CWE-77, CWE-78) via unsanitized shell command interpolation in model serving container initialization | 9.8 | — | |
| CVE-2026-4729 | Mozilla Firefox / Thunderbird Memory safety bugs / Buffer overflow / Dangling pointer (CWE-120, CWE-825) leading to potential arbitrary code execution | 9.8 | — | 2 PoC
|
| CVE-2026-4721 | Mozilla Firefox / Thunderbird Memory safety bugs / buffer overflow / dangling pointer arbitrary code execution (CWE-120, CWE-825) | 9.8 | — | |
| CVE-2026-4720 | Mozilla Firefox / Firefox ESR / Thunderbird Memory safety bugs / Buffer overflow leading to arbitrary code execution (CWE-120) | 9.8 | — | |
| CVE-2026-4700 | Mozilla Firefox / Thunderbird Authentication bypass via HTTP request smuggling / mitigation bypass (CWE-288, CWE-444) | 9.8 | — | |
| CVE-2026-4698 | Mozilla Firefox / Thunderbird JavaScript Engine (SpiderMonkey JIT) JIT miscompilation type confusion (CWE-843) | 9.8 | — | |
| CVE-2026-4696 | Mozilla Firefox / Thunderbird Use-after-free in Layout: Text and Fonts | 9.8 | — | |
| CVE-2026-4691 | Firefox / Thunderbird Use-after-free in CSS Parsing and Computation | 9.8 | — | |
| CVE-2026-33195 | Rails Active Storage Path Traversal (Directory Traversal) arbitrary file read/write/delete | 9.8 | — | |
| CVE-2006-10003 | XML::Parser (Perl) Off-by-one heap buffer overflow | 9.8 | — | |
| CVE-2026-32304 | Locutus (locutusjs) Arbitrary Code Execution via unsanitized Function constructor injection (CWE-94, CWE-88) | 9.8 | — | 1 PoC
|
| CVE-2026-31806 | FreeRDP Heap buffer overflow via unvalidated bitmap dimensions in NSCodec surface bits processing | 9.8 | — | 1 PoC
|
| CVE-2026-28229 | Argo Workflows Improper Authorization / Missing Authentication for Critical Function (WorkflowTemplate endpoint unauthenticated information disclosure) | 9.8 | — | 1 PoC
|
| CVE-2026-28292 | simple-git (git-js) OS Command Injection / Case-sensitive bypass RCE (CWE-78, CWE-178, CWE-76) | 9.8 | — | 1 PoC
|
| CVE-2026-2293 | NestJS (@nestjs/platform-fastify) Authentication/Authorization Middleware Bypass via Fastify Path Normalization | 9.8 | — | |
| CVE-2026-2807 | Mozilla Firefox / Thunderbird Memory corruption / Out-of-bounds write (CWE-787) leading to arbitrary code execution | 9.8 | — | |
| CVE-2026-2799 | Firefox / Thunderbird Use-after-free in DOM Core & HTML | 9.8 | — | |
| CVE-2026-2797 | Firefox / Thunderbird JavaScript GC Use-after-free in JavaScript Garbage Collector (GC) | 9.8 | — | |
| CVE-2026-2796 | Mozilla Firefox / Thunderbird Type Confusion (CWE-843) via JIT miscompilation in JavaScript WebAssembly engine | 9.8 | — | 3 PoC
|
| CVE-2026-2795 | Firefox / Thunderbird JavaScript GC Use-after-free in JavaScript Garbage Collector (CWE-416) | 9.8 | — | 1 PoC
|
| CVE-2026-2793 | Mozilla Firefox / Thunderbird Memory safety bugs / out-of-bounds write (OOB write) leading to arbitrary code execution | 9.8 | — | |
| CVE-2026-2792 | Firefox / Thunderbird Memory corruption / out-of-bounds write (CWE-787) leading to arbitrary code execution | 9.8 | — | |
| CVE-2026-2777 | Mozilla Firefox / Thunderbird Messaging System Privilege Escalation (Improper Privilege Management) | 9.8 | — | 3 PoC
|
| CVE-2026-2775 | Mozilla Firefox / Thunderbird Authentication mitigation bypass via DOM HTML Parser (CWE-288) | 9.8 | — | |
| CVE-2026-2774 | Mozilla Firefox / Thunderbird Audio/Video component Integer overflow in Audio/Video processing (CWE-190) | 9.8 | — | |
| CVE-2026-2773 | Firefox / Thunderbird Web Audio Buffer boundary condition error (CWE-119) in Web Audio component | 9.8 | — | |
| CVE-2026-2772 | Firefox / Thunderbird Use-after-free in Audio/Video Playback | 9.8 | — | |
| CVE-2026-2771 | Mozilla Firefox / Thunderbird Out-of-bounds read / Undefined behavior in DOM Core & HTML component (CWE-125) | 9.8 | — | |
| CVE-2026-2770 | Mozilla Firefox / Thunderbird Use-after-free in DOM Bindings (WebIDL) RCE/memory corruption | 9.8 | — | |
| CVE-2026-2767 | Firefox / Thunderbird WebAssembly JavaScript Engine Use-after-free in WebAssembly JavaScript component (CWE-416) | 9.8 | — | |
| CVE-2026-2766 | Firefox / Thunderbird JavaScript Engine JIT Use-after-free in JIT compiler (JavaScript Engine) | 9.8 | — | |
| CVE-2026-2765 | Mozilla Firefox / Thunderbird JavaScript Engine Use-after-free in JavaScript Engine (CWE-416) | 9.8 | — | 2 PoC
|
| CVE-2026-2764 | Firefox / Thunderbird JavaScript Engine (SpiderMonkey JIT) JIT miscompilation use-after-free in JavaScript Engine JIT component | 9.8 | — | |
| CVE-2026-2763 | Mozilla Firefox / Thunderbird JavaScript Engine Use-after-free in JavaScript Engine (SpiderMonkey) | 9.8 | — | 3 PoC
|
| CVE-2026-2762 | Firefox / Thunderbird JavaScript Standard Library Integer overflow in JavaScript Standard Library | 9.8 | — | 2 PoC
|
| CVE-2026-2759 | Firefox / Thunderbird (Mozilla ImageLib) Incorrect boundary conditions (out-of-bounds read/write) in image decoding library | 9.8 | — | 1 PoC
|
| CVE-2026-2758 | Firefox / Thunderbird JavaScript GC Use-after-free in JavaScript Garbage Collector (GC) | 9.8 | — | |
| CVE-2026-2757 | Firefox / Thunderbird WebRTC Audio/Video Incorrect boundary conditions in WebRTC Audio/Video component | 9.8 | — | 3 PoC
|
| CVE-2025-69872 | python-diskcache (DiskCache) Pickle deserialization arbitrary code execution (CWE-94, CWE-502) | 9.8 | — | |
| CVE-2026-1615 | jsonpath (dchester/jsonpath) Arbitrary Code Injection via unsafe eval of JSON Path expressions (RCE / XSS) | 9.8 | — | |
| CVE-2026-23884 | FreeRDP Use-After-Free (UAF) in offscreen bitmap cache leading to DoS / potential RCE | 9.8 | — | |
| CVE-2026-23883 | FreeRDP Use-After-Free (UAF) in X11 cursor pointer handling leading to DoS / potential RCE | 9.8 | — | |
| CVE-2026-23534 | FreeRDP Heap buffer overflow (CWE-122) in ClearCodec bands decode path (client-side RCE/DoS) | 9.8 | — | 1 PoC
|
| CVE-2026-23533 | FreeRDP Heap buffer overflow (CWE-122) in RDPGFX ClearCodec decode path leading to DoS/RCE | 9.8 | — | 1 PoC
|
| CVE-2026-23532 | FreeRDP Heap buffer overflow (CWE-122) in GDI SurfaceToSurface RDP client-side | 9.8 | — | 1 PoC
|
| CVE-2026-23531 | FreeRDP Heap buffer overflow (out-of-bounds read/write) in ClearCodec via unvalidated destination rectangle | 9.8 | — | 1 PoC
|
| CVE-2026-23530 | FreeRDP Heap buffer overflow via missing bounds validation in planar bitmap decompression (RLE decode) | 9.8 | — | 1 PoC
|
| CVE-2026-22853 | FreeRDP Heap buffer overflow in NDR array parsing (CWE-787 out-of-bounds write) | 9.8 | — | 1 PoC
|
| CVE-2026-0879 | Mozilla Firefox / Thunderbird Sandbox escape via incorrect boundary conditions in Graphics component (CWE-119 buffer boundary error) | 9.8 | — | |
| CVE-2025-67268 | gpsd heap-based out-of-bounds write (CWE-122) via improper index validation (CWE-1285) | 9.8 | — | 1 PoC
|
| CVE-2026-26142 | Nuance PowerScribe Deserialization of untrusted data RCE | 9.8 | — | |
| CVE-2026-6951 | simple-git Argument Injection / Remote Code Execution (RCE) via --config option bypass | 9.8 | — | |
| CVE-2026-3256 | HTTP::Session (Perl) Insecure pseudo-random number generator (PRNG) used for session ID generation (CWE-338, CWE-340) | 9.8 | — | |
| CVE-2026-47323 | Apache Camel (camel-cxf, camel-knative-http) HTTP Message Header Injection via Missing Inbound Header Filtering leading to RCE / Arbitrary File Write | 9.8 | — | |
| CVE-2026-48930 | Node.js TLS hostname validation bypass via embedded NUL byte / c-string truncation in resolver bindings | 9.8 | — | |
| CVE-2026-41120 | Dell Wyse Management Suite (WMS) Acceptance of Extraneous Untrusted Data With Trusted Data (CWE-349) leading to Remote Code Execution | 9.8 | — | |
| CVE-2026-54906 | concurrent-ruby Improper lock release verification leading to missing synchronization / lock state corruption (CWE-414, CWE-667) | 9.8 | — | |
| CVE-2026-7664 | IBM Langflow OSS Improper Authorization / Authentication Bypass on MCP Transport Endpoint | 9.8 | — | |
| CVE-2017-8046 | spring-data-rest-core JSON deserialization RCE via malicious PATCH request | 9.8 | — | 43 PoC
|
| CVE-2026-40079 | Cacti OS Command Injection via unsanitized shell_exec in escape_command() | 9.8 | — | |
| CVE-2026-39955 | Cacti Pre-authentication SQL Injection | 9.8 | — | |
| CVE-2026-39948 | Cacti Unauthenticated SQL Injection (RLIKE clause injection via unfiltered request parameter) | 9.8 | — | |
| CVE-2026-39938 | Cacti Local File Inclusion (LFI) and OS Command Injection via graph_theme parameter and rrdtool IPC serialization | 9.8 | — | 1 PoC
|
| CVE-2026-39893 | Cacti Unauthenticated SQL Injection (SQLi) via RLIKE clause | 9.8 | — | |
| CVE-2026-49468 | LiteLLM Authentication Bypass by Spoofing (CWE-290) | 9.8 | — | |
| CVE-2026-35278 | PeopleSoft Enterprise PT PeopleTools Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / system takeover | 9.8 | — | |
| CVE-2026-46845 | Oracle WebCenter Portal Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover | 9.8 | — | |
| CVE-2026-34977 | AperiSolve OS Command Injection (CWE-78) via unsanitized password parameter passed to expect/bash -c RCE | 9.8 | — | |
| CVE-2026-30790 | rustdesk-client Cleartext transmission of password hash with insufficient computational effort (fast double SHA256, no slow KDF) over HTTP management channel, enabling offline brute-force after passive capture | 9.8 | — | |
| CVE-2026-30789 | RustDesk Client (rustdesk-client) Weak password hashing with insufficient computational effort and no brute-force restriction enabling offline password recovery (CWE-307, CWE-916) | 9.8 | — | |
| CVE-2026-30783 | RustDesk Client Privilege Abuse via client-side enforcement bypass (CWE-602, CWE-841) in API sync loop and config management | 9.8 | — | |
| CVE-2020-14968 | jsrsasign RSASSA-PSS signature manipulation / memory corruption (CWE-119) | 9.8 | — | 17 PoC
|
| CVE-2020-14967 | jsrsasign RSA PKCS1 v1.5 decryption ciphertext modification memory corruption | 9.8 | — | 17 PoC
|
| CVE-2026-46807 | Oracle Identity Manager (OIM) Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full system takeover via T3/IIOP | 9.8 | — | |
| CVE-2026-35310 | Oracle Coherence Improper Access Control (Unauthenticated RCE via HTTP) | 9.8 | — | |
| CVE-2026-35309 | Oracle Coherence Improper Access Control / Unauthenticated Remote Code Execution via HTTP (CWE-284) | 9.8 | — | |
| CVE-2026-35304 | Oracle Coherence Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / takeover via HTTPS | 9.8 | — | |
| CVE-2026-46919 | Oracle Siebel CRM Cloud Applications Improper Access Control / Authentication Bypass leading to unauthenticated RCE / Application Takeover (CWE-284, CWE-287, CWE-306) | 9.8 | — | |
| CVE-2026-46905 | JD Edwards EnterpriseOne Tools Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover via HTTP | 9.8 | — | |
| CVE-2026-46904 | JD Edwards EnterpriseOne Tools Improper Access Control / Missing Authentication for Critical Function (Unauthenticated RCE/Takeover via JDENET) | 9.8 | — | |
| CVE-2026-46890 | Oracle Siebel CRM - Siebel Apps Marketing Improper Access Control / Authentication Bypass / Missing Authentication for Critical Function (CWE-284, CWE-287, CWE-306) | 9.8 | — | |
| CVE-2026-46889 | Oracle Siebel CRM - Siebel Apps Marketing Improper Access Control (Unauthenticated Remote Takeover via HTTP) | 9.8 | — | |
| CVE-2026-46887 | Oracle Siebel CRM - Siebel Apps Marketing Improper Access Control / Unauthenticated Remote Takeover (CWE-284) | 9.8 | — | |
| CVE-2026-46884 | Oracle Siebel CRM - Siebel Apps Marketing Improper Access Control (Unauthenticated Remote Takeover) | 9.8 | — | |
| CVE-2026-46879 | JD Edwards EnterpriseOne Tools Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / system takeover | 9.8 | — | |
| CVE-2026-46878 | JD Edwards EnterpriseOne Tools Improper Access Control (Unauthenticated Network Takeover via JDENET) | 9.8 | — | |
| CVE-2026-46860 | MySQL Router Improper Access Control (CWE-284) leading to unauthenticated remote takeover via HTTP | 9.8 | — | |
| CVE-2026-46859 | Oracle Agile PLM Authentication Bypass (CWE-287) | 9.8 | — | |
| CVE-2026-46783 | Oracle WebCenter Content: Imaging Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover via HTTP | 9.8 | — | |
| CVE-2026-46774 | Oracle Unified Directory (OUD) Improper Access Control via RMI leading to unauthenticated remote takeover (CWE-284) | 9.8 | — | |
| CVE-2026-46773 | Oracle Unified Directory (OUD) Improper Access Control / Unauthenticated LDAP Remote Takeover (CWE-284) | 9.8 | — | |
| CVE-2026-46766 | Oracle WebCenter Content Improper Access Control / Unauthenticated Remote Takeover (CWE-284) | 9.8 | — | |
| CVE-2026-35319 | Oracle WebCenter Content Improper Access Control (Unauthenticated Remote Takeover) | 9.8 | — | |
| CVE-2026-35312 | Oracle Virtual Directory Improper Access Control / Unauthenticated LDAP Remote Takeover (CWE-284) | 9.8 | — | |
| CVE-2026-53838 | OpenClaw Time-of-check Time-of-use (TOCTOU) / State Mutation Race Condition (CWE-367) in node pairing reconnection logic | 9.8 | — | |
| CVE-2026-54133 | jmespath.php Code Injection via insufficient escaping of attacker-controlled JMESPath function names in generated PHP source (RCE) | 9.8 | — | |
| CVE-2026-44083 | QuMagie Authorization bypass through user-controlled key (IDOR / Broken Object Level Authorization) | 9.8 | — | |
| CVE-2026-9170 | IBM HTTP Server Improper Input Validation leading to Denial of Service and Remote Code Execution | 9.8 | — | |
| CVE-2026-48284 | Adobe ColdFusion Improper Input Validation Remote Code Execution | 9.6 | 28.0% | |
| CVE-2026-47928 | Adobe ColdFusion Improper Input Validation leading to Arbitrary Code Execution (RCE) | 9.6 | 8.25% | |
| CVE-2025-12543 | Undertow HTTP server Host header validation bypass enabling cache poisoning, SSRF, and session hijacking | 9.6 | 1.20% | 1 PoC
|
| CVE-2026-22208 | OpenS100 Unrestricted Lua interpreter RCE via unsandboxed luaL_openlibs() | 9.6 | 0.92% | 1 PoC
|
| CVE-2026-5917 | — libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands | 9.6 | 0.86% | |
| CVE-2026-55743 | — The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileg | 9.6 | 0.70% | |
| CVE-2026-39821 | golang.org/x/net/idna Improper Input Validation / Punycode label bypass leading to privilege escalation | 9.6 | 0.66% | |
| CVE-2026-2587 | Eclipse GlassFish Expression Language (EL) Injection / Server-Side Template Injection RCE (CWE-917) | 9.6 | 0.65% | 1 PoC
|
| CVE-2026-33211 | Tekton Pipelines Path Traversal (CWE-22) via git resolver pathInRepo parameter | 9.6 | 0.57% | |
| CVE-2026-5241 | huggingface/transformers Remote Code Execution via trust_remote_code override in LightGlue model loading (CWE-829: Inclusion of Functionality from Untrusted Control Sphere) | 9.6 | 0.55% | |
| CVE-2026-48359 | — Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. | 9.6 | 0.53% | |
| CVE-2026-71193 | — In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these | 9.6 | 0.53% | |
| CVE-2026-42880 | Argo CD Missing Authorization and Sensitive Data Exposure via Server-Side Apply dry-run (Secret plaintext leak) | 9.6 | 0.51% | 2 PoC
|
| CVE-2026-48317 | — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the | 9.6 | 0.48% | |
| CVE-2026-17681 | — Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially pe | 9.6 | 0.44% | |
| CVE-2026-70332 | — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 9.6 | 0.43% | |
| CVE-2026-17697 | — Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | 0.42% | |
| CVE-2026-17687 | — Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | 0.42% | |
| CVE-2026-17680 | — Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craft | 9.6 | 0.42% | |
| CVE-2026-19149 | — Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critica | 9.6 | 0.42% | |
| CVE-2026-17651 | — Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromi | 9.6 | 0.42% | |
| CVE-2026-48259 | — Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker c | 9.6 | 0.41% | |
| CVE-2026-72877 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src | 9.6 | 0.40% | |
| CVE-2025-67289 | Frappe Framework Arbitrary File Upload leading to Remote Code Execution (XSS/RCE via crafted XML) | 9.6 | 0.40% | |
| CVE-2026-12297 | Mozilla Firefox / Thunderbird Sandbox escape via incorrect boundary conditions in Networking component (CWE-119 buffer boundary error) | 9.6 | 0.39% | |
| CVE-2026-12296 | Mozilla Firefox / Thunderbird Sandbox escape in Process Sandboxing component | 9.6 | 0.39% | |
| CVE-2026-12295 | Firefox / Thunderbird Sandbox escape via DOM Navigation component (CWE-693: Protection Mechanism Failure) | 9.6 | 0.39% | 1 PoC
|
| CVE-2026-17717 | — Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | 0.39% | |
| CVE-2026-17710 | — Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cr | 9.6 | 0.39% | |
| CVE-2026-17708 | — Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | 0.39% | |
| CVE-2026-17704 | — Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | 0.39% | |
| CVE-2026-17695 | — Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever | 9.6 | 0.39% | |
| CVE-2026-17692 | — Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craft | 9.6 | 0.39% | |
| CVE-2026-17691 | — Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: | 9.6 | 0.39% | |
| CVE-2026-17688 | — Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | 0.39% | |
| CVE-2026-17684 | — Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a | 9.6 | 0.39% | |
| CVE-2026-17682 | — Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C | 9.6 | 0.39% | |
| CVE-2026-17676 | — Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via | 9.6 | 0.39% | |
| CVE-2026-17673 | — Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch | 9.6 | 0.39% | |
| CVE-2026-17672 | — Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esc | 9.6 | 0.39% | |
| CVE-2026-17671 | — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v | 9.6 | 0.39% | |
| CVE-2026-17670 | — Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | 0.39% | |
| CVE-2026-17669 | — Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium secur | 9.6 | 0.39% | |
| CVE-2026-42557 | JupyterLab Stored Cross-Site Scripting (XSS) via HTML cell output leading to arbitrary command execution | 9.6 | 0.39% | |
| CVE-2026-47705 | — TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating | 9.6 | 0.38% | |
| CVE-2026-12294 | Mozilla Firefox / Thunderbird Sandbox escape via DOM Workers | 9.6 | 0.36% | |
| CVE-2026-19170 | — Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Crit | 9.6 | 0.33% | |
| CVE-2026-55518 | — Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resour | 9.6 | 0.33% | |
| CVE-2026-66395 | — SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan: | 9.6 | 0.33% | |
| CVE-2026-60540 | — Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploi | 9.6 | 0.33% | |
| CVE-2026-60239 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.6 | 0.33% | |
| CVE-2026-8715 | — Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kube | 9.6 | 0.32% | |
| CVE-2026-62948 | — OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_writ | 9.6 | 0.31% | |
| CVE-2026-53474 | migration-planner (kubev2v/migration-planner) SQL Injection via unsanitized spreadsheet cell input (CWE-89) | 9.6 | 0.31% | |
| CVE-2026-17711 | — Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch | 9.6 | 0.31% | |
| CVE-2026-17709 | — Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch | 9.6 | 0.31% | |
| CVE-2026-13901 | Google Chrome Insufficient policy enforcement sandbox escape via Serial API | 9.6 | 0.30% | |
| CVE-2026-13843 | Google Chrome for iOS Insufficient input validation sandbox escape | 9.6 | 0.30% | |
| CVE-2026-17758 | — Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 9.6 | 0.30% | |
| CVE-2026-53476 | assisted-migration-agent Path traversal via malicious gzipped tarball (Zip Slip / symlink follow) | 9.6 | 0.29% | |
| CVE-2026-15901 | — Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | 9.6 | 0.29% | |
| CVE-2026-17738 | — Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap | 9.6 | 0.28% | |
| CVE-2026-17768 | — Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esc | 9.6 | 0.28% | |
| CVE-2026-17804 | — Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | 0.28% | |
| CVE-2026-17801 | — Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Me | 9.6 | 0.28% | |
| CVE-2026-17727 | — Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: | 9.6 | 0.28% | |
| CVE-2026-17726 | — Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Hig | 9.6 | 0.28% | |
| CVE-2026-17721 | — Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | 0.28% | |
| CVE-2026-17718 | — Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | 0.28% | |
| CVE-2026-17675 | — Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | 9.6 | 0.28% | |
| CVE-2026-13909 | Google Chrome DevTools Insufficient policy enforcement sandbox escape | 9.6 | 0.28% | |
| CVE-2026-13846 | Google Chrome Use-After-Free USB sandbox escape | 9.6 | 0.28% | |
| CVE-2026-13792 | Google Chrome Use-After-Free sandbox escape | 9.6 | 0.28% | |
| CVE-2026-13789 | Google Chrome Use-After-Free GPU sandbox escape | 9.6 | 0.28% | |
| CVE-2026-68579 | — FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. ex | 9.6 | 0.27% | |
| CVE-2026-65007 | — The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-m | 9.6 | 0.27% | |
| CVE-2026-62549 | — Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low | 9.6 | 0.26% | |
| CVE-2026-15773 | Google Chrome Use-After-Free sandbox escape | 9.6 | 0.26% | |
| CVE-2026-31938 | jsPDF Stored/Reflected Cross-Site Scripting (XSS) via unsanitized HTML injection in PDF output options | 9.6 | 0.26% | |
| CVE-2026-19157 | — Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: | 9.6 | 0.26% | |
| CVE-2026-17803 | — Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox | 9.6 | 0.26% | |
| CVE-2026-15899 | — Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: | 9.6 | 0.26% | |
| CVE-2026-15900 | — Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critic | 9.6 | 0.26% | |
| CVE-2026-53513 | — Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-con | 9.6 | 0.25% | |
| CVE-2026-72737 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept | 9.6 | 0.25% | |
| CVE-2026-17276 | — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads. | 9.6 | 0.24% | |
| CVE-2026-17865 | — Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a c | 9.6 | 0.24% | |
| CVE-2026-14120 | Google Chrome DevTools Inappropriate implementation sandbox escape via compromised renderer process | 9.6 | 0.24% | |
| CVE-2026-55742 | — Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') | 9.6 | 0.23% | |
| CVE-2026-12605 | — In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin | 9.6 | 0.22% | |
| CVE-2026-17991 | — Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via | 9.6 | 0.22% | |
| CVE-2026-17947 | — Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | 9.6 | 0.22% | |
| CVE-2026-17940 | — Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially pe | 9.6 | 0.22% | |
| CVE-2026-17924 | — Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chrom | 9.6 | 0.22% | |
| CVE-2026-14109 | Google Chrome / Chromium Mojo Insufficient policy enforcement leading to sandbox escape | 9.6 | 0.22% | |
| CVE-2026-14106 | Google Chrome on Android Insufficient input validation sandbox escape | 9.6 | 0.22% | |
| CVE-2026-14101 | Google Chrome Sandbox escape via insufficient policy enforcement in renderer process | 9.6 | 0.22% | |
| CVE-2026-14044 | Google Chrome ANGLE Use-After-Free sandbox escape | 9.6 | 0.22% | |
| CVE-2026-14043 | Google Chrome Use-after-free sandbox escape in GetUserMedia | 9.6 | 0.22% | |
| CVE-2026-8670 | — Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay).
This issue affects Avantra: before 25.3.1. | 9.6 | 0.22% | |
| CVE-2026-17749 | — Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sand | 9.6 | 0.21% | |
| CVE-2026-47416 | — PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/memb | 9.6 | 0.21% | |
| CVE-2026-47413 | — PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspac | 9.6 | 0.21% | |
| CVE-2026-16424 | — Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML | 9.6 | 0.21% | |
| CVE-2026-17990 | — Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap | 9.6 | 0.21% | |
| CVE-2026-17987 | — Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox | 9.6 | 0.21% | |
| CVE-2026-28381 | Grafana Snowflake datasource plugin Improper Access Control - arbitrary file read/write via Snowflake GET/PUT commands | 9.6 | 0.21% | |
| CVE-2026-44985 | — Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, acceptin | 9.6 | 0.19% | |
| CVE-2026-18015 | — Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severi | 9.6 | 0.19% | |
| CVE-2026-18002 | — Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es | 9.6 | 0.19% | |
| CVE-2026-16419 | — Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security | 9.6 | 0.16% | |
| CVE-2026-68124 | — In the Linux kernel, the following vulnerability has been resolved:
mctp: serial: handle zero-length frames to prevent rx buffer overflow
The MCTP serial receive state machine reads a frame length b | 9.6 | — | |
| CVE-2026-73843 | — OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable a | 9.6 | — | |
| CVE-2026-56443 | — Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | 9.6 | — | |
| CVE-2026-72878 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by directly interpolating user-controlled database fiel | 9.6 | — | |
| CVE-2026-50540 | — Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable t | 9.6 | — | |
| CVE-2026-46409 | — OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<rando | 9.6 | — | |
| CVE-2026-62896 | — Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | 9.6 | — | |
| CVE-2026-56161 | — Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | 9.6 | — | |
| CVE-2026-60773 | — Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability | 9.6 | — | |
| CVE-2026-19175 | — Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | — | |
| CVE-2026-19171 | — Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High | 9.6 | — | |
| CVE-2026-19166 | — Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Hi | 9.6 | — | |
| CVE-2026-19164 | — Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium secur | 9.6 | — | |
| CVE-2026-71319 | — Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools | 9.6 | — | |
| CVE-2026-17656 | — Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 9.6 | — | |
| CVE-2026-17655 | — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit | 9.6 | — | |
| CVE-2026-17652 | — Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | — | |
| CVE-2026-17349 | — /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every co | 9.6 | — | |
| CVE-2026-17856 | — Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a | 9.6 | — | |
| CVE-2026-17855 | — Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | — | |
| CVE-2026-17848 | — Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) | 9.6 | — | |
| CVE-2026-17847 | — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit | 9.6 | — | |
| CVE-2026-17837 | — Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap | 9.6 | — | |
| CVE-2026-17834 | — Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esca | 9.6 | — | |
| CVE-2026-17832 | — Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | — | |
| CVE-2026-16624 | — Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including f | 9.6 | — | |
| CVE-2026-60564 | — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vu | 9.6 | — | |
| CVE-2026-55008 | — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 9.6 | — | |
| CVE-2026-39399 | — NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply a | 9.6 | — | |
| CVE-2026-28373 | — The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can | 9.6 | — | |
| CVE-2026-31818 | — Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection | 9.6 | — | |
| CVE-2026-26135 | — Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. | 9.6 | — | |
| CVE-2026-34931 | — hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in | 9.6 | — | |
| CVE-2026-34449 | — SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS po | 9.6 | — | |
| CVE-2026-7333 | — Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | — | |
| CVE-2026-5874 | — Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a craft | 9.6 | — | |
| CVE-2026-46703 | — Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users | 9.6 | — | |
| CVE-2026-11697 | — Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security | 9.6 | — | |
| CVE-2026-11671 | — Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | — | |
| CVE-2026-11659 | — Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | — | |
| CVE-2026-11654 | — Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: | 9.6 | — | |
| CVE-2026-11651 | — Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 9.6 | — | |
| CVE-2026-11638 | — Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 9.6 | — | |
| CVE-2026-11634 | — Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Cr | 9.6 | — | |
| CVE-2026-46441 | — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. T | 9.6 | — | |
| CVE-2026-42861 | — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. Th | 9.6 | — | |
| CVE-2026-45758 | — Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. A | 9.6 | — | |
| CVE-2026-11293 | — Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | 9.6 | — | |
| CVE-2026-11282 | — Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit | 9.6 | — | |
| CVE-2026-11250 | — Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from pro | 9.6 | — | |
| CVE-2026-11213 | — Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox e | 9.6 | — | |
| CVE-2026-11207 | — Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromiu | 9.6 | — | |
| CVE-2026-11198 | — Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium secur | 9.6 | — | |
| CVE-2026-11167 | — Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape vi | 9.6 | — | |
| CVE-2026-11165 | — Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 9.6 | — | |
| CVE-2026-11163 | — Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Me | 9.6 | — | |
| CVE-2026-11152 | — Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 9.6 | — | |
| CVE-2026-11146 | — Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esc | 9.6 | — | |
| CVE-2026-11131 | — Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted H | 9.6 | — | |
| CVE-2026-11120 | — Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a s | 9.6 | — | |
| CVE-2026-11119 | — Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a | 9.6 | — | |
| CVE-2026-11114 | — Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted H | 9.6 | — | |
| CVE-2026-11113 | — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v | 9.6 | — | |
| CVE-2026-11112 | — Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sa | 9.6 | — | |
| CVE-2026-11100 | — Use after free in File Input in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via | 9.6 | — | |
| CVE-2026-11095 | — Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape | 9.6 | — | |
| CVE-2026-11094 | — Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM | 9.6 | — | |
| CVE-2026-11088 | — Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C | 9.6 | — | |
| CVE-2026-11082 | — Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chro | 9.6 | — | |
| CVE-2026-11070 | — Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the network process to potentially perform a s | 9.6 | — | |
| CVE-2026-11066 | — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit | 9.6 | — | |
| CVE-2026-11065 | — Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr | 9.6 | — | |
| CVE-2026-11063 | — Insufficient validation of untrusted input in WebNN in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandb | 9.6 | — | |
| CVE-2026-11061 | — Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 9.6 | — | |
| CVE-2026-11056 | — Insufficient validation of untrusted input in SiteIsolation in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform | 9.6 | — | |
| CVE-2026-11052 | — Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML p | 9.6 | — | |
| CVE-2026-11047 | — Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a | 9.6 | — | |
| CVE-2026-11043 | — Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM | 9.6 | — | |
| CVE-2026-11037 | — Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) | 9.6 | — | |
| CVE-2026-11029 | — Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform | 9.6 | — | |
| CVE-2026-11021 | — Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox | 9.6 | — | |
| CVE-2026-11009 | — Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | 9.6 | — | |
| CVE-2026-11002 | — Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. ( | 9.6 | — | |
| CVE-2026-10990 | — Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chro | 9.6 | — | |
| CVE-2026-10983 | — Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security | 9.6 | — | |
| CVE-2026-10974 | — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit | 9.6 | — | |
| CVE-2026-10972 | — Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | — | |
| CVE-2026-10971 | — Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sa | 9.6 | — | |
| CVE-2026-10966 | — Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: | 9.6 | — | |
| CVE-2026-10931 | — Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | — | |
| CVE-2026-10892 | — Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Cr | 9.6 | — | |
| CVE-2026-10886 | — Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 9.6 | — | |
| CVE-2026-10881 | — Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Cr | 9.6 | — | |
| CVE-2026-32625 | — LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders agai | 9.6 | — | |
| CVE-2026-44211 | — Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of | 9.6 | — | |
| CVE-2026-45628 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (w | 9.6 | — | |
| CVE-2026-59891 | — sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checkin | 9.6 | — | |
| CVE-2026-9967 | — Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 9.6 | — | |
| CVE-2026-9886 | — Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 9.6 | — | |
| CVE-2026-9876 | — Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Crit | 9.6 | — | |
| CVE-2026-9875 | — Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: | 9.6 | — | |
| CVE-2026-9874 | — Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | 9.6 | — | |
| CVE-2026-9872 | — Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: C | 9.6 | — | |
| CVE-2026-9918 | — Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Hi | 9.6 | — | |
| CVE-2026-59151 | Prowler SAML authentication bypass / cross-tenant account takeover (improper authentication CWE-287) | 9.6 | — | 1 PoC
|
| CVE-2026-59792 | JetBrains IntelliJ IDEA Path Traversal leading to Code Execution (CWE-23) | 9.6 | — | |
| CVE-2026-15113 | Google Chrome Autofill (Android) Use-After-Free sandbox escape | 9.6 | — | |
| CVE-2026-13869 | Google Chrome Use-After-Free sandbox escape via Device component | 9.6 | — | |
| CVE-2024-44779 | vTiger CRM Reflected Cross-Site Scripting (XSS) | 9.6 | — | |
| CVE-2024-44778 | vTiger CRM Reflected Cross-Site Scripting (XSS) | 9.6 | — | 1 PoC
|
| CVE-2024-44777 | vTiger CRM Reflected Cross-Site Scripting (XSS) | 9.6 | — | 1 PoC
|
| CVE-2023-45992 | RUCKUS Cloudpath Persistent Cross-Site Scripting (Stored XSS) and Cross-Site Request Forgery (CSRF) leading to admin privilege escalation | 9.6 | — | 2 PoC
|
| CVE-2022-37830 | WebJET CMS Cross-Site Scripting (XSS) | 9.6 | — | |
| CVE-2023-38888 | Dolibarr ERP CRM Cross-Site Scripting (XSS) via REST API module | 9.6 | — | |
| CVE-2022-36180 | FusionDirectory Reflected Cross-Site Scripting (XSS) | 9.6 | — | |
| CVE-2026-14405 | Google Chrome V8 JavaScript Engine Uninitialized Use (CWE-457) leading to sandbox remote code execution | 9.6 | — | |
| CVE-2026-14397 | Google Chrome ANGLE (Almost Native Graphics Layer Engine) Out-of-bounds write sandbox escape | 9.6 | — | |
| CVE-2026-14392 | Google Chrome / Tint (WebGPU shader compiler) Out-of-bounds write sandbox escape | 9.6 | — | |
| CVE-2026-14382 | Google Chrome ANGLE Insufficient input validation sandbox escape | 9.6 | — | 1 PoC
|
| CVE-2026-53492 | containerd Improper Input Validation / Authorization Bypass via untrusted CDI annotation injection during container restoration (CWE-20, CWE-863) | 9.6 | — | |
| CVE-2026-14425 | Google Chrome ANGLE Use-after-free sandbox escape | 9.6 | — | |
| CVE-2026-14424 | Google Chrome / Dawn (WebGPU) Use-After-Free sandbox escape (CWE-416) | 9.6 | — | |
| CVE-2026-14423 | Google Chrome / Chromium Tint Type Confusion sandbox escape | 9.6 | — | |
| CVE-2026-14420 | Google Chrome - Dawn (WebGPU) Out-of-bounds read and write sandbox escape (CWE-125 / CWE-787) | 9.6 | — | |
| CVE-2026-14419 | Google Chrome / Skia Use-after-free sandbox escape | 9.6 | — | |
| CVE-2026-14417 | Google Chrome Dawn (WebGPU) Use-after-free sandbox escape | 9.6 | — | |
| CVE-2026-14416 | Google Chrome Dawn (WebGPU) Out of bounds read sandbox escape | 9.6 | — | |
| CVE-2026-14411 | Google Chrome ANGLE Insufficient input validation sandbox escape | 9.6 | — | |
| CVE-2026-14398 | Google Chrome ANGLE Use-After-Free sandbox escape | 9.6 | — | |
| CVE-2026-14390 | Google Chrome ANGLE Use-After-Free sandbox escape | 9.6 | — | |
| CVE-2026-14387 | Google Chrome / Skia Graphics Library Integer overflow leading to sandbox escape | 9.6 | — | |
| CVE-2026-10140 | IBM Langflow OSS Insecure Direct Object Reference / Improper Authorization (CWE-639) — cross-tenant API client cache poisoning | 9.6 | — | |
| CVE-2026-14152 | Google Chrome ANGLE Out-of-bounds read and write sandbox escape | 9.6 | — | |
| CVE-2026-14113 | Google Chrome Updater (Windows) Use-After-Free sandbox escape (renderer compromise) | 9.6 | — | |
| CVE-2026-14097 | Google Chrome Inappropriate implementation sandbox escape via WebAppInstalls | 9.6 | — | |
| CVE-2026-14095 | Google Chrome sandbox escape via insufficient policy enforcement in renderer process | 9.6 | — | |
| CVE-2026-14093 | Google Chrome Use-After-Free sandbox escape | 9.6 | — | |
| CVE-2026-14056 | Google Chrome Insufficient input validation sandbox escape via crafted video file | 9.6 | — | |
| CVE-2026-14055 | Google Chrome Insufficient input validation sandbox escape | 9.6 | — | |
| CVE-2026-14017 | Google Chrome Sandbox escape via inappropriate Navigation implementation (CWE-693 Protection Mechanism Failure) | 9.6 | — | |
| CVE-2026-13934 | Google Chrome Dawn (WebGPU) on Android Insufficient input validation sandbox escape | 9.6 | — | |
| CVE-2026-13920 | Google Chrome Insufficient input validation sandbox escape via Media component (renderer compromise) | 9.6 | — | |
| CVE-2026-13883 | Google Chrome ANGLE Type Confusion sandbox escape | 9.6 | — | |
| CVE-2026-13882 | Google Chrome Race condition (TOCTOU) in USB leading to sandbox escape | 9.6 | — | |
| CVE-2026-13880 | Google Chrome Use-after-free sandbox escape via USB | 9.6 | — | |
| CVE-2026-13878 | Google Chrome Use-After-Free sandbox escape via Bluetooth | 9.6 | — | |
| CVE-2026-13861 | Google Chrome Use-after-free sandbox escape | 9.6 | — | |
| CVE-2026-13859 | Google Chrome ANGLE Sandbox escape via inappropriate implementation in ANGLE graphics layer | 9.6 | — | |
| CVE-2026-13854 | Google Chrome / Chromium Ozone (Linux) Use-After-Free sandbox escape (renderer to OS) | 9.6 | — | |
| CVE-2026-13853 | Google Chrome Use-After-Free sandbox escape | 9.6 | — | |
| CVE-2026-13798 | Google Chrome / Chromium (Chromecast component) Heap buffer overflow sandbox escape (renderer process) | 9.6 | — | |
| CVE-2026-13797 | Google Chrome - Chromecast component Insufficient input validation sandbox escape (renderer process) | 9.6 | — | |
| CVE-2026-13796 | Google Chrome / Chromium Chromecast component Integer overflow sandbox escape via compromised renderer process | 9.6 | — | |
| CVE-2026-13785 | Google Chrome Use-After-Free sandbox escape via Bluetooth | 9.6 | — | |
| CVE-2026-13781 | Google Chrome / Skia Insufficient input validation sandbox escape via Skia renderer compromise | 9.6 | — | |
| CVE-2026-13780 | Google Chrome ANGLE Insufficient input validation sandbox escape | 9.6 | — | |
| CVE-2026-54352 | Budibase Path Traversal via Symlink in Zip Extraction (Zip Slip / Symlink Follow LFI) | 9.6 | — | |
| CVE-2026-33757 | OpenBao Session Fixation / Remote Phishing via JWT/OIDC Direct Callback Mode (CWE-384) | 9.6 | — | |
| CVE-2026-27148 | Storybook WebSocket Cross-Site WebSocket Hijacking (CSWSH) leading to XSS / RCE via unsanitized input injection | 9.6 | — | |
| CVE-2026-2611 | MLflow Improper Origin Validation / Cross-Origin Request Forgery (CORF) leading to arbitrary command execution via Claude Code sub-agent | 9.6 | — | 2 PoC
|
| CVE-2026-13028 | Google Chrome / Chromium WebGL (Android) Use-After-Free sandbox escape via WebGL | 9.6 | — | |
| CVE-2026-54307 | n8n Improper Authorization / Cross-User Credential Access (CWE-863) | 9.6 | — | |
| CVE-2026-46786 | Oracle WebCenter Content Cross-Site Request Forgery (CSRF) | 9.6 | — | |
| CVE-2026-46911 | JD Edwards EnterpriseOne Project Costing Improper Access Control (CWE-284) - Unauthorized data read/write via JDENET | 9.6 | — | |
| CVE-2026-46906 | JD Edwards EnterpriseOne Tools Improper Access Control (CWE-284) - Unauthorized data access and modification via HTTP | 9.6 | — | |
| CVE-2026-46861 | MySQL NDB Cluster Improper Access Control (CWE-284) - Unauthorized data read/write via HTTP in NDB Operator | 9.6 | — | |
| CVE-2026-46789 | Oracle WebCenter Content Missing Authentication for Critical Function (CWE-306) leading to full takeover via unauthenticated HTTP access with scope change | 9.6 | — | |
| CVE-2026-47281 | Visual Studio Code Improper Input Validation leading to Privilege Escalation (Missing Authentication / Hard-coded Credentials / Missing Authorization) | 9.6 | — | |
| CVE-2026-12027 | Google Chrome Headless Sandbox escape via inappropriate implementation in Headless renderer | 9.6 | — | |
| CVE-2026-66066 | — Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untruste | 9.5 | 1.70% | |
| CVE-2026-8467 | — Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation.
The psb-assign | 9.5 | 0.91% | |
| CVE-2026-46684 | — DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), wh | 9.5 | — | |
| CVE-2026-47670 | — DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS command | 9.4 | 1.71% | |
| CVE-2025-4517 | — Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data".
You are affected by this vulnerability if using the tarfile module to extract untrusted tar | 9.4 | 1.23% | |
| CVE-2026-23941 | — Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling.
This vulnerability is associated with program f | 9.4 | 0.53% | |
| CVE-2026-4404 | — Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. | 9.4 | 0.50% | |
| CVE-2026-67305 | — FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-pr | 9.4 | 0.49% | |
| CVE-2026-31448 | Linux Kernel ext4 Infinite loop (CWE-835) due to residual extent tree data on mkdir/mknod block mapping failure | 9.4 | 0.43% | |
| CVE-2026-61203 | — Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows una | 9.4 | 0.40% | |
| CVE-2026-50561 | — Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versi | 9.4 | 0.37% | |
| CVE-2026-14529 | — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP cont | 9.4 | 0.33% | |
| CVE-2026-39405 | — Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to | 9.4 | 0.30% | |
| CVE-2026-72879 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and reg | 9.4 | 0.28% | |
| CVE-2026-66398 | — phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write a | 9.4 | 0.24% | |
| CVE-2026-47407 | — PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and pro | 9.4 | 0.24% | |
| CVE-2026-64024 | — In the Linux kernel, the following vulnerability has been resolved:
tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
Blamed commit moved the TIME_WAIT-derived ISN from the skb control
| 9.4 | 0.17% | |
| CVE-2026-73483 | — Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-c | 9.4 | — | |
| CVE-2026-50516 | — Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 9.4 | — | |
| CVE-2025-15039 | — The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain auth | 9.4 | — | |
| CVE-2026-48088 | — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` acce | 9.4 | — | |
| CVE-2025-40099 | — In the Linux kernel, the following vulnerability has been resolved:
cifs: parse_dfs_referrals: prevent oob on malformed input
Malicious SMB server can send invalid reply to FSCTL_DFS_GET_REFERRALS
| 9.4 | — | |
| CVE-2025-39943 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer
If data_offset and data_length of smb_dir | 9.4 | — | |
| CVE-2025-39933 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: let recv_done verify data_offset, data_length and remaining_data_length
This is inspired by the related server fixes. | 9.4 | — | |
| CVE-2025-38552 | — In the Linux kernel, the following vulnerability has been resolved:
mptcp: plug races between subflow fail and subflow creation
We have races similar to the one addressed by the previous patch betwe | 9.4 | — | |
| CVE-2025-38146 | — In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: Fix the dead loop of MPLS parse
The unexpected MPLS packet may not end with the bottom label stack.
When there a | 9.4 | — | |
| CVE-2025-38120 | — In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_set_pipapo_avx2: fix initial map fill
If the first field doesn't cover the entire start map, then we must zero
out t | 9.4 | — | |
| CVE-2025-37959 | — In the Linux kernel, the following vulnerability has been resolved:
bpf: Scrub packet on bpf_redirect_peer
When bpf_redirect_peer is used to redirect packets to a device in
another network namespace | 9.4 | — | |
| CVE-2026-61186 | — Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability a | 9.4 | — | |
| CVE-2026-32916 | — OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administra | 9.4 | — | |
| CVE-2026-39397 | — @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's | 9.4 | — | |
| CVE-2026-33950 | — Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. | 9.4 | — | |
| CVE-2026-11624 | — The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had | 9.4 | — | |
| CVE-2026-16337 | — Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-a | 9.4 | — | |
| CVE-2025-71392 | — SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR | 9.4 | — | |
| CVE-2026-42569 | — phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been pa | 9.4 | — | |
| CVE-2026-63830 | — In the Linux kernel, the following vulnerability has been resolved:
net: skmsg: preserve sg.copy across SG transforms
The sk_msg sg.copy bitmap is part of the scatterlist entry ownership
state. A se | 9.4 | — | |
| CVE-2026-49973 | Hermes WebUI Improper Access Control / Missing Authentication for Critical Function (CWE-306) - Unauthenticated Initial Setup Hijack | 9.4 | — | |
| CVE-2026-41448 | AdGuard Home Authentication Bypass via Path Traversal (CWE-22) | 9.4 | — | |
| CVE-2025-34292 | Rox (BeWelcome) PHP object injection via deserialization of untrusted data (RCE / arbitrary file write) | 9.4 | — | |
| CVE-2025-52025 | Aptsys gemscms POS Platform SQL Injection (CWE-89) | 9.4 | — | |
| CVE-2025-52024 | Aptsys POS Platform Web Services Unauthenticated Access to Internal API Testing Tools (Missing Authentication / Forced Browsing) | 9.4 | — | |
| CVE-2026-50137 | Budibase Missing Authorization (CWE-862) — Unauthenticated pre-signed S3 PUT URL generation via exposed API endpoint | 9.4 | — | |
| CVE-2026-33454 | Apache Camel camel-mail Header injection via unserialized/unfiltered inbound MIME headers (CWE-502, CWE-1173) | 9.4 | — | |
| CVE-2026-1709 | keylime TLS client authentication bypass (CWE-322) | 9.4 | — | |
| CVE-2026-23734 | — XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Mai | 9.3 | 19.5% | |
| CVE-2026-62835 | — Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | 9.3 | 1.03% | |
| CVE-2026-73663 | — FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in a | 9.3 | 0.95% | |
| CVE-2026-26215 | manga-image-translator Unsafe deserialization (pickle) unauthenticated RCE | 9.3 | 0.92% | 2 PoC
|
| CVE-2025-31114 | — Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker | 9.3 | 0.88% | |
| CVE-2026-48321 | Adobe ColdFusion Incorrect Authorization / Privilege Escalation (CWE-863) | 9.3 | 0.77% | |
| CVE-2026-26220 | LightLLM Unauthenticated WebSocket pickle deserialization RCE | 9.3 | 0.66% | |
| CVE-2024-21364 | — Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | 9.3 | 0.62% | |
| CVE-2026-25069 | SunFounder Pironman Dashboard (pm_dashboard) Path Traversal / Arbitrary File Read and Delete (CWE-22) | 9.3 | 0.60% | |
| CVE-2026-33137 | — XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1. | 9.3 | 0.59% | |
| CVE-2026-70306 | — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 9.3 | 0.56% | |
| CVE-2026-41106 | Microsoft 365 Copilot Open Redirect (URL Redirection to Untrusted Site) leading to Privilege Escalation | 9.3 | 0.54% | |
| CVE-2026-44990 | — ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` pri | 9.3 | 0.51% | |
| CVE-2026-25896 | fast-xml-parser DOCTYPE entity name regex wildcard XSS (CWE-185, CWE-79) | 9.3 | 0.46% | |
| CVE-2026-14973 | — IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. | 9.3 | 0.45% | |
| CVE-2026-0650 | github.com/openflagr/flagr Authentication bypass via HTTP middleware path normalization whitelist logic | 9.3 | 0.44% | |
| CVE-2026-73080 | — SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3 | 9.3 | 0.38% | |
| CVE-2026-66421 | — OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting | 9.3 | 0.36% | |
| CVE-2026-47669 | — DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file pa | 9.3 | 0.34% | |
| CVE-2026-8763 | — In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIP | 9.3 | 0.33% | |
| CVE-2026-15091 | — IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. | 9.3 | 0.32% | |
| CVE-2026-12048 | pgAdmin 4 Stored Cross-Site Scripting (XSS) via unsanitized PostgreSQL server error messages and EXPLAIN plan output passed through html-react-parser | 9.3 | 0.31% | |
| CVE-2026-72904 | — Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe | 9.3 | 0.29% | |
| CVE-2026-59638 | — In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Ca | 9.3 | 0.28% | |
| CVE-2026-48046 | — Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised render | 9.3 | 0.27% | |
| CVE-2026-59650 | — In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12. | 9.3 | 0.26% | |
| CVE-2026-58155 | — Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 | 9.3 | 0.26% | |
| CVE-2026-49871 | Apache APISIX Cross-Site Request Forgery (CSRF) authentication identity swap | 9.3 | 0.23% | |
| CVE-2026-45043 | — RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create ser | 9.3 | 0.23% | |
| CVE-2026-73090 | — PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying tha | 9.3 | 0.22% | |
| CVE-2026-58062 | — In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle f | 9.3 | 0.20% | |
| CVE-2026-63939 | — In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Compute the correct max length of the in-GHCB scratch area
When setting the length of the GHCB scratch area, and the are | 9.3 | 0.20% | |
| CVE-2026-41920 | — Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to v | 9.3 | 0.19% | |
| CVE-2026-48700 | — An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt de | 9.3 | 0.18% | |
| CVE-2026-64034 | — In the Linux kernel, the following vulnerability has been resolved:
net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read | 9.3 | 0.18% | |
| CVE-2026-63940 | — In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Ignore Port I/O requests of length '0'
Explicitly ignore Port I/O requests of length '0' (or count '0'), so that
setting | 9.3 | 0.18% | |
| CVE-2026-63938 | — In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Check PSC request indices against the actual size of the buffer
When processing Page State Change (PSC) requests, valida | 9.3 | 0.18% | |
| CVE-2026-64080 | — In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Snapshot notifier callbacks under lock
Both notification handlers currently look up a notifier callback under
n | 9.3 | 0.18% | |
| CVE-2026-64018 | — In the Linux kernel, the following vulnerability has been resolved:
net: mana: validate rx_req_idx to prevent out-of-bounds array access
In mana_hwc_rx_event_handler(), rx_req_idx is derived from
sg | 9.3 | 0.17% | |
| CVE-2026-53475 | assisted-migration-agent Improper Certificate Validation / Hardcoded Insecure TLS (CWE-295) | 9.3 | 0.17% | |
| CVE-2026-48063 | — Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and | 9.3 | 0.16% | |
| CVE-2026-50252 | — In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balanc | 9.3 | 0.12% | |
| CVE-2026-60248 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.3 | 0.12% | |
| CVE-2024-20412 | — A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using | 9.3 | — | |
| CVE-2026-59118 | — Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | 9.3 | — | |
| CVE-2026-67531 | — FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), a | 9.3 | — | |
| CVE-2026-61207 | — Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is 9.2. Easily exploitable vul | 9.3 | — | |
| CVE-2026-61175 | — Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerabi | 9.3 | — | |
| CVE-2025-52936 | — Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2. | 9.3 | — | |
| CVE-2026-66418 | — OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted usernam | 9.3 | — | |
| CVE-2026-16416 | — Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Hig | 9.3 | — | |
| CVE-2025-38560 | — In the Linux kernel, the following vulnerability has been resolved:
x86/sev: Evict cache lines during SNP memory validation
An SNP cache coherency vulnerability requires a cache line eviction
mitiga | 9.3 | — | |
| CVE-2026-60632 | — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable | 9.3 | — | |
| CVE-2026-60631 | — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable | 9.3 | — | |
| CVE-2026-66013 | — OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known as | 9.3 | — | |
| CVE-2026-27304 | — ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitatio | 9.3 | — | |
| CVE-2026-25776 | — Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script. | 9.3 | — | |
| CVE-2026-1346 | — IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Acces | 9.3 | — | |
| CVE-2026-60220 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.3 | — | |
| CVE-2026-40331 | — Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, the unauthenticated JSON API accepts an altTa | 9.3 | — | |
| CVE-2026-40330 | — Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, a SQL injection vulnerability exists in the b | 9.3 | — | |
| CVE-2026-40329 | — Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's processing of the | 9.3 | — | |
| CVE-2026-34615 | — Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An | 9.3 | — | |
| CVE-2026-39382 | — dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside the reusable workflow dbt-labs/actions/blob/main/.git | 9.3 | — | |
| CVE-2026-28766 | — A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. | 9.3 | — | |
| CVE-2026-34932 | — hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0. | 9.3 | — | |
| CVE-2026-34361 | — HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" en | 9.3 | — | |
| CVE-2026-47202 | — Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given kn | 9.3 | — | |
| CVE-2026-5752 | — Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal. | 9.3 | — | |
| CVE-2026-41090 | — Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 9.3 | — | |
| CVE-2026-39878 | — Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in a | 9.3 | — | |
| CVE-2026-42849 | — authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compa | 9.3 | — | |
| CVE-2026-47708 | — MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata co | 9.3 | — | |
| CVE-2026-45668 | — Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled | 9.3 | — | |
| CVE-2026-48334 | — Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control o | 9.3 | — | |
| CVE-2026-63089 | — WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuar | 9.3 | — | |
| CVE-2026-55445 | — Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts checks /api/user/init but not | 9.3 | — | |
| CVE-2026-46515 | — Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup | 9.3 | — | |
| CVE-2026-59866 | — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both gene | 9.3 | — | |
| CVE-2026-59865 | — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version value | 9.3 | — | |
| CVE-2026-59864 | — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from | 9.3 | — | |
| CVE-2026-48356 | Adobe Commerce (Magento) Unrestricted File Upload leading to Arbitrary Code Execution (CWE-434) | 9.3 | — | |
| CVE-2026-55879 | OpenReplay Stored Cross-Site Scripting (XSS) via unsanitized custom event names and page URLs rendered in authenticated dashboard | 9.3 | — | |
| CVE-2026-54527 | jupyterlab-git Stored Cross-Site Scripting (XSS) via unsanitized innerHTML injection | 9.3 | — | |
| CVE-2026-59702 | repomix Server-Side Request Forgery (SSRF) via unvalidated repository URLs in POST /api/pack endpoint | 9.3 | — | |
| CVE-2026-46316 | Linux Kernel Use-After-Free / Improper Reference Counting (CWE-911) in KVM arm64 vGIC-ITS translation cache | 9.3 | — | |
| CVE-2026-11712 | IBM WebSphere Application Server Cross-Site Scripting (XSS) | 9.3 | — | |
| CVE-2026-11708 | IBM WebSphere Application Server Cross-Site Scripting (XSS) | 9.3 | — | |
| CVE-2026-14038 | Google Chrome Insufficient input validation sandbox escape | 9.3 | — | |
| CVE-2026-48315 | Adobe ColdFusion Improper Input Validation leading to arbitrary code execution / script injection | 9.3 | — | |
| CVE-2026-48313 | Adobe ColdFusion Path Traversal arbitrary file read/write (CWE-22) | 9.3 | — | |
| CVE-2026-24834 | Kata Containers Improper file system permissions allowing guest VM filesystem modification leading to arbitrary code execution (CWE-732, CWE-281) | 9.3 | — | 1 PoC
|
| CVE-2026-46805 | Oracle WebCenter Content Improper Access Control (CWE-284) — unauthenticated HTTP access allowing unauthorized read/write to critical data with scope change | 9.3 | — | |
| CVE-2026-46795 | Oracle WebCenter Content Improper Access Control (CWE-284) - Unauthenticated HTTP network access leading to unauthorized data read/write (scope change) | 9.3 | — | |
| CVE-2026-46785 | Oracle WebCenter Content Cross-Site Request Forgery (CSRF) | 9.3 | — | |
| CVE-2026-48616 | Rocket.Chat Improper Access Control / Broken Authorization on Livechat File Downloads | 9.3 | — | |
| CVE-2026-7161 | GeoVision GV-IP Device Utility Insufficient encryption / credentials leak via UDP broadcast (CWE-656, security through obscurity) | 9.3 | — | |
| CVE-2026-45328 | ESP-IDF (Espressif IoT Development Framework) Improper Input Validation / Out-of-bounds Write in TEE secure-service wrappers (CWE-20, CWE-787) | 9.3 | — | |
| CVE-2026-34691 | Adobe Experience Manager Forms JEE Stored Cross-Site Scripting (XSS) | 9.3 | — | |
| CVE-2026-54466 | — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily la | 9.2 | 0.45% | |
| CVE-2026-66824 | — A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinj | 9.2 | 0.28% | |
| CVE-2026-47243 | — Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs | 9.2 | 0.18% | |
| CVE-2026-46713 | — Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that a | 9.2 | 0.17% | |
| CVE-2026-49445 | — Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-a | 9.2 | 0.17% | |
| CVE-2026-73414 | — Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(` and `)` when applications use the escape or escape | 9.2 | — | |
| CVE-2026-44895 | — GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: | 9.2 | — | |
| CVE-2026-52893 | — Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username m | 9.2 | — | |
| CVE-2026-55884 | github.com/tilt-dev/tilt Missing Authentication for Critical Function (unauthenticated HTTP handler access) | 9.2 | — | |
| CVE-2026-34714 | Vim Expression injection leading to OS command execution (CWE-78 / CWE-917) via %{expr} in tabpanel option missing P_MLE flag | 9.2 | — | |
| CVE-2026-62241 | — clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/sca | 9.1 | 6.55% | |
| CVE-2023-3867 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix out of bounds read in smb2_sess_setup
ksmbd does not consider the case of that smb2 session setup is
in compound reques | 9.1 | 5.13% | |
| CVE-2026-55040 | — Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | 9.1 | 2.96% | |
| CVE-2024-7387 | — A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder c | 9.1 | 2.30% | |
| CVE-2026-33186 | grpc-go (google.golang.org/grpc) HTTP/2 :path pseudo-header improper input validation leading to authorization bypass (CWE-285, CWE-551) | 9.1 | 1.56% | 1 PoC
|
| CVE-2021-33643 | libtar Out-of-bounds read via malloc(0) on crafted tar header | 9.1 | 1.45% | 1 PoC
|
| CVE-2026-48746 | vLLM HTTP Request Smuggling / Trust Boundary Violation Authentication Bypass (CWE-444, CWE-501) | 9.1 | 1.15% | |
| CVE-2026-33000 | — A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | 9.1 | 1.12% | |
| CVE-2026-14959 | — IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. | 9.1 | 1.04% | |
| CVE-2026-14890 | — SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attack | 9.1 | 0.91% | |
| CVE-2026-44007 | vm2 Sandbox escape via nested NodeVM unrestricted require() leading to arbitrary OS command execution | 9.1 | 0.90% | |
| CVE-2026-2586 | Eclipse GlassFish Administration Console Authenticated Remote Code Execution via Expression Language Injection (CWE-94, CWE-917) | 9.1 | 0.84% | 2 PoC
|
| CVE-2026-33210 | ruby/json Format String Injection leading to Denial of Service or Information Disclosure | 9.1 | 0.84% | |
| CVE-2024-22949 | JFreeChart NullPointerException (Out-of-bounds Read / CWE-125) | 9.1 | 0.77% | |
| CVE-2026-57158 | FreeRDP Out-of-bounds read (OOB read) in GFX pipeline planar RLE decompression | 9.1 | 0.69% | |
| CVE-2023-52441 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix out of bounds in init_smb2_rsp_hdr()
If client send smb2 negotiate request and then send smb1 negotiate
request, init_s | 9.1 | 0.68% | |
| CVE-2026-5720 | miniupnpd Integer underflow out-of-bounds read (CWE-125, CWE-191) in SOAPAction HTTP header parsing leading to denial of service or information disclosure | 9.1 | 0.67% | |
| CVE-2022-35293 | SAP Enable Now Insecure Session Management / Missing Authorization (CWE-862) | 9.1 | 0.63% | |
| CVE-2026-39830 | golang.org/x/crypto/ssh SSH global request response buffer fill / goroutine resource leak (DoS) | 9.1 | 0.62% | |
| CVE-2026-25858 | macrozheng mall OTP Disclosure / Unauthenticated Password Reset (Account Takeover) | 9.1 | 0.61% | |
| CVE-2026-39832 | golang.org/x/crypto/ssh/agent Insecure Deserialization / Improper Privilege Management - SSH agent constraint extension stripping | 9.1 | 0.60% | |
| CVE-2026-44172 | MariaDB Connector/C SQL Injection via improper character escaping (big5 charset bypass of mysql_real_escape_string) | 9.1 | 0.58% | |
| CVE-2026-42508 | Go (golang) crypto/ssh Improper Certificate Validation / Revoked SignatureKey not checked (CWE-295) | 9.1 | 0.57% | |
| CVE-2026-28302 | — SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrat | 9.1 | 0.56% | |
| CVE-2026-27962 | authlib JWK Header Injection / JWT Signature Verification Bypass | 9.1 | 0.55% | 1 PoC
|
| CVE-2026-28305 | — SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write acce | 9.1 | 0.55% | |
| CVE-2026-28304 | — SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments. | 9.1 | 0.55% | |
| CVE-2026-54003 | getkirby/cms IP spoofing via reverse proxy headers leading to unauthorized Panel installation and admin user creation | 9.1 | 0.55% | |
| CVE-2026-52958 | Linux Kernel Out-of-bounds memory access in OSD map decoding | 9.1 | 0.54% | |
| CVE-2026-73420 | — NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an ad | 9.1 | 0.53% | |
| CVE-2026-52999 | Linux Kernel out-of-bounds read in netfilter OS fingerprinting option matching | 9.1 | 0.52% | |
| CVE-2026-14958 | — IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. | 9.1 | 0.52% | |
| CVE-2026-48137 | NI grpc-device Untrusted pointer dereference RCE (CWE-822) via crafted protobuf message | 9.1 | 0.50% | |
| CVE-2025-65318 | Canary Mail Mark-of-the-Web (MotW) bypass via attachment save | 9.1 | 0.48% | 1 PoC
|
| CVE-2026-4599 | jsrsasign Incomplete Comparison with Missing Factors leading to DSA nonce bias and private key recovery | 9.1 | 0.48% | |
| CVE-2026-51536 | — In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream l | 9.1 | 0.47% | |
| CVE-2026-39834 | — When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packe | 9.1 | 0.47% | |
| CVE-2026-47040 | — Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability all | 9.1 | 0.45% | |
| CVE-2026-50627 | Apache CXF JWT Audience Claim Validation Bypass (Token Confusion/Routing Attack) | 9.1 | 0.45% | |
| CVE-2026-51537 | — EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid | 9.1 | 0.44% | |
| CVE-2022-4993 | — HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data | 9.1 | 0.44% | |
| CVE-2026-60208 | — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily | 9.1 | 0.44% | |
| CVE-2026-9074 | IBM API Connect Unauthenticated SQL Injection | 9.1 | 0.44% | |
| CVE-2026-61235 | — Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is 9.2. Eas | 9.1 | 0.43% | |
| CVE-2026-72850 | — Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenam | 9.1 | 0.42% | |
| CVE-2026-31682 | Linux Kernel Out-of-bounds memory access via non-linear SKB parsing in bridge neighbor discovery | 9.1 | 0.42% | |
| CVE-2026-39999 | Apache APISIX Authentication Bypass by Spoofing (CWE-290) via jwt-auth plugin misconfiguration | 9.1 | 0.41% | |
| CVE-2026-14740 | DBI (Perl) Out-of-bounds read (CWE-125) in SQL comment parsing | 9.1 | 0.41% | |
| CVE-2025-41118 | Pyroscope Sensitive configuration value exposure via API (CWE-732, CWE-201) | 9.1 | 0.41% | |
| CVE-2026-24013 | Apache IoTDB Authentication Bypass by Spoofing (CWE-290) via forged sessionId in Thrift RPC | 9.1 | 0.41% | |
| CVE-2024-38883 | Caterease Drop Encryption Level Attack / Algorithm Downgrade (CWE-757) | 9.1 | 0.41% | |
| CVE-2026-30458 | Daylight Studio FuelCMS Password reset token exfiltration via mail splitting attack | 9.1 | 0.40% | |
| CVE-2026-61184 | — Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Ea | 9.1 | 0.40% | |
| CVE-2026-51538 | — EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, | 9.1 | 0.39% | |
| CVE-2026-54058 | — Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row | 9.1 | 0.38% | |
| CVE-2026-51541 | — OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData fr | 9.1 | 0.38% | |
| CVE-2026-56278 | Flowise Hardcoded Default Secret / Session Forgery Authentication Bypass | 9.1 | 0.38% | |
| CVE-2026-60606 | — Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Easily e | 9.1 | 0.38% | |
| CVE-2026-60267 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.1 | 0.38% | |
| CVE-2026-61153 | — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. | 9.1 | 0.38% | |
| CVE-2026-42216 | OpenEXR Out-of-bounds read (OOB read) in prefix-compressed string reconstruction | 9.1 | 0.38% | 1 PoC
|
| CVE-2026-39831 | — The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch w | 9.1 | 0.37% | |
| CVE-2026-71213 | — Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration | 9.1 | 0.36% | |
| CVE-2026-16390 | — Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.1 | 0.35% | |
| CVE-2026-16380 | — Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.1 | 0.35% | |
| CVE-2026-16370 | — Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.1 | 0.35% | |
| CVE-2026-73501 | — kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthentic | 9.1 | 0.34% | |
| CVE-2026-64609 | — Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-co | 9.1 | 0.34% | |
| CVE-2026-28307 | — SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments. | 9.1 | 0.34% | |
| CVE-2026-28306 | — SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deploymen | 9.1 | 0.34% | |
| CVE-2026-46738 | — Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially explo | 9.1 | 0.34% | |
| CVE-2026-40712 | — Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially explo | 9.1 | 0.34% | |
| CVE-2023-32249 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: not allow guest user on multichannel
This patch return STATUS_NOT_SUPPORTED if binding session is guest. | 9.1 | 0.34% | |
| CVE-2026-45063 | symfony/security-http Authentication Bypass via Spoofing (CWE-290) — unanchored regex in X.509 client certificate DN parsing | 9.1 | 0.34% | |
| CVE-2026-61130 | — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability | 9.1 | 0.33% | |
| CVE-2026-47826 | BOSH CLI Path Traversal (CWE-22) - arbitrary file write and sensitive information exfiltration via blobs.yml path key | 9.1 | 0.33% | |
| CVE-2026-16364 | — Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.1 | 0.33% | |
| CVE-2026-16393 | — Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.1 | 0.32% | |
| CVE-2026-14198 | @fastify/middie Middleware Path Matching Bypass via Encoded Slash (Interpretation Conflict / CWE-436) | 9.1 | 0.31% | |
| CVE-2026-9142 | NI grpc-device Missing Authentication / Insecure Default Credentials (CWE-306) | 9.1 | 0.31% | |
| CVE-2026-53512 | — Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates | 9.1 | 0.30% | |
| CVE-2026-61244 | — Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is 9.1. Easily exploitable vuln | 9.1 | 0.29% | |
| CVE-2026-61238 | — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vuln | 9.1 | 0.29% | |
| CVE-2026-9390 | — XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup.
verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI valu | 9.1 | 0.28% | |
| CVE-2026-16359 | — Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.1 | 0.28% | |
| CVE-2026-13852 | Google Chrome Insufficient input validation DAC bypass | 9.1 | 0.27% | |
| CVE-2026-13851 | Google Chrome Insufficient input validation DAC bypass | 9.1 | 0.27% | |
| CVE-2026-60053 | — Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Administrative API keys remained usable after the owning administrator was demoted or | 9.1 | 0.27% | |
| CVE-2026-68980 | — Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Para | 9.1 | 0.26% | |
| CVE-2026-58319 | Apache Doris Missing Authentication for Critical Function (CWE-306) - Unauthenticated REST API Access | 9.1 | 0.26% | |
| CVE-2026-48170 | — `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. | 9.1 | 0.25% | |
| CVE-2026-44231 | — RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerabil | 9.1 | 0.25% | |
| CVE-2026-57830 | Helix Ultimate (Joomla extension) Unauthenticated Arbitrary File Deletion (Missing Authorization) | 9.1 | 0.24% | 1 PoC
|
| CVE-2026-45069 | symfony/security-http JWT OIDC claim verification bypass (missing mandatory claims enforcement) | 9.1 | 0.24% | |
| CVE-2026-13872 | Google Chrome on Android Insufficient input validation sandbox escape | 9.1 | 0.24% | |
| CVE-2026-48509 | MessagePack for C# (MessagePack-CSharp) Insecure default serializer options leading to denial-of-service via hash-collision attack (CWE-1188) | 9.1 | 0.24% | |
| CVE-2026-49230 | Apache APISIX Improper Validation of Integrity Check Value / Authentication Bypass | 9.1 | 0.23% | |
| CVE-2026-17666 | — Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chr | 9.1 | 0.21% | |
| CVE-2026-15616 | — Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. | 9.1 | 0.19% | |
| CVE-2026-16381 | — Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | 9.1 | 0.19% | |
| CVE-2026-17552 | — Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call.
When the rewrite base is a plain string, the REQUEST_URI is appe | 9.1 | 0.19% | |
| CVE-2026-46428 | — lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification | 9.1 | 0.19% | |
| CVE-2026-26219 | newbee-mall Unsalted MD5 password hashing enabling offline credential cracking | 9.1 | 0.19% | 1 PoC
|
| CVE-2026-13238 | drupal/commerce_realex Incorrect Authorization / Forceful Browsing (CWE-863) | 9.1 | 0.18% | |
| CVE-2026-63992 | — In the Linux kernel, the following vulnerability has been resolved:
tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
In some cases, iptunnel_pmtud_check_icmp() can be called wh | 9.1 | 0.18% | |
| CVE-2026-44087 | Apache APISIX Identity header spoofing / Insufficient Verification of Data Authenticity (CWE-345) | 9.1 | 0.17% | |
| CVE-2026-9487 | — XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.
_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the | 9.1 | 0.17% | |
| CVE-2026-59084 | Apache Tomcat Insufficient Technical Documentation (CWE-1059) - EncryptInterceptor misconfiguration | 9.1 | 0.16% | |
| CVE-2026-59083 | Apache Tomcat Improper Handling of URL Encoding (Hex Encoding) - Security Constraint Bypass via Rewrite Valve | 9.1 | 0.16% | |
| CVE-2026-15617 | — Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities. | 9.1 | 0.15% | |
| CVE-2026-15611 | — Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account. | 9.1 | 0.15% | |
| CVE-2026-13237 | Drupal AI Agents (drupal/ai_agents) Incorrect Authorization / Forceful Browsing (CWE-863) | 9.1 | 0.14% | |
| CVE-2026-13233 | Drupal OpenAI Provider (drupal/ai_provider_openai) Server-Side Request Forgery (SSRF) | 9.1 | 0.14% | 1 PoC
|
| CVE-2026-15612 | — Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. | 9.1 | 0.13% | |
| CVE-2026-7876 | IBM Aspera HSTS for CP4I Authentication Bypass | 9.1 | 0.04% | |
| CVE-2026-68083 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the
| 9.1 | — | |
| CVE-2026-58508 | — Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | 9.1 | — | |
| CVE-2026-58443 | — Public-only repository tokens can update private PR head branches | 9.1 | — | |
| CVE-2026-58433 | — Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | 9.1 | — | |
| CVE-2026-56750 | — Gitea Remember-Me Token Theft Not Invalidating Attacker Session | 9.1 | — | |
| CVE-2026-55982 | — OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | 9.1 | — | |
| CVE-2026-53791 | — rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with | 9.1 | — | |
| CVE-2026-34184 | — AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker co | 9.1 | — | |
| CVE-2026-16439 | — In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. | 9.1 | — | |
| CVE-2020-3187 | — A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to c | 9.1 | — | |
| CVE-2026-58102 | — Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts.
When building the extension hash (via extensions(), extensions_by_ | 9.1 | — | |
| CVE-2026-43197 | — In the Linux kernel, the following vulnerability has been resolved:
netconsole: avoid OOB reads, msg is not nul-terminated
msg passed to netconsole from the console subsystem is not guaranteed
to be | 9.1 | — | |
| CVE-2026-71560 | — Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. | 9.1 | — | |
| CVE-2026-10050 | — In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.
This was done because the initial specification for HTTP did not specify explicitl | 9.1 | — | |
| CVE-2024-6593 | — Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands.
An a | 9.1 | — | |
| CVE-2024-6592 | — An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on W | 9.1 | — | |
| CVE-2026-68823 | — Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | 9.1 | — | |
| CVE-2026-53984 | — Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauth | 9.1 | — | |
| CVE-2026-54489 | — Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentiall | 9.1 | — | |
| CVE-2026-34191 | — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable R | 9.1 | — | |
| CVE-2026-32327 | — A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users ar | 9.1 | — | |
| CVE-2026-56160 | — Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | 9.1 | — | |
| CVE-2026-65583 | — Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication | 9.1 | — | |
| CVE-2026-63687 | — Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly- | 9.1 | — | |
| CVE-2026-61466 | — In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it a | 9.1 | — | |
| CVE-2026-62546 | — Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerabi | 9.1 | — | |
| CVE-2026-16392 | — JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.1 | — | |
| CVE-2026-13379 | — The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnect | 9.1 | — | |
| CVE-2026-24457 | — An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorize | 9.1 | — | |
| CVE-2026-55953 | — The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The clie | 9.1 | — | |
| CVE-2026-61156 | — Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability | 9.1 | — | |
| CVE-2026-61155 | — Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability | 9.1 | — | |
| CVE-2026-60168 | — Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10. Easil | 9.1 | — | |
| CVE-2026-60438 | — Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability | 9.1 | — | |
| CVE-2026-64551 | — In the Linux kernel, the following vulnerability has been resolved:
sctp: validate STALE_COOKIE cause length before reading staleness
When an ERROR chunk with a STALE_COOKIE cause is received in the | 9.1 | — | |
| CVE-2025-71183 | — In the Linux kernel, the following vulnerability has been resolved:
btrfs: always detect conflicting inodes when logging inode refs
After rename exchanging (either with the rename exchange operation | 9.1 | — | |
| CVE-2025-71116 | — In the Linux kernel, the following vulnerability has been resolved:
libceph: make decode_pool() more resilient against corrupted osdmaps
If the osdmap is (maliciously) corrupted such that the encode | 9.1 | — | |
| CVE-2025-71095 | — In the Linux kernel, the following vulnerability has been resolved:
net: stmmac: fix the crash issue for zero copy XDP_TX action
There is a crash issue when running zero copy XDP_TX action, the cras | 9.1 | — | |
| CVE-2025-71093 | — In the Linux kernel, the following vulnerability has been resolved:
e1000: fix OOB in e1000_tbi_should_accept()
In e1000_tbi_should_accept() we read the last byte of the frame via
'data[length - 1]' | 9.1 | — | |
| CVE-2025-68809 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: vfs: fix race on m_flags in vfs_cache
ksmbd maintains delete-on-close and pending-delete state in
ksmbd_inode->m_flags. In | 9.1 | — | |
| CVE-2025-38728 | — In the Linux kernel, the following vulnerability has been resolved:
smb3: fix for slab out of bounds on mount to ksmbd
With KASAN enabled, it is possible to get a slab out of bounds
during mount to | 9.1 | — | |
| CVE-2025-38365 | — In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix a race between renames and directory logging
We have a race between a rename and directory inode logging that if it
hap | 9.1 | — | |
| CVE-2026-60649 | — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily expl | 9.1 | — | |
| CVE-2026-43071 | — In the Linux kernel, the following vulnerability has been resolved:
dcache: Limit the minimal number of bucket to two
There is an OOB read problem on dentry_hashtable when user sets
'dhash_entries=1 | 9.1 | — | |
| CVE-2026-64863 | — goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-d | 9.1 | — | |
| CVE-2026-62325 | — goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so runnin | 9.1 | — | |
| CVE-2026-58662 | — Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade | 9.1 | — | |
| CVE-2026-58023 | — Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue. | 9.1 | — | |
| CVE-2026-48144 | — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.2 | 9.1 | — | |
| CVE-2026-61171 | — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated a | 9.1 | — | |
| CVE-2026-61197 | — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vu | 9.1 | — | |
| CVE-2026-60567 | — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vu | 9.1 | — | |
| CVE-2026-60326 | — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita | 9.1 | — | |
| CVE-2026-64450 | — In the Linux kernel, the following vulnerability has been resolved:
tipc: fix out-of-bounds read in broadcast Gap ACK blocks
A broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its
d | 9.1 | — | |
| CVE-2026-64393 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: run set info with opener credentials
SMB2 SET_INFO handlers call path-based VFS helpers after checking the
access mask gran | 9.1 | — | |
| CVE-2026-64392 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: use opener credentials for delete-on-close
Delete-on-close can be completed by deferred or durable handle teardown,
where n | 9.1 | — | |
| CVE-2026-64320 | — In the Linux kernel, the following vulnerability has been resolved:
nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
nvmet_execute_disc_get_log_page() validates only the dword a | 9.1 | — | |
| CVE-2026-64319 | — In the Linux kernel, the following vulnerability has been resolved:
nvmet-auth: validate reply message payload bounds against transfer length
nvmet_auth_reply() accesses the variable-length rval[] a | 9.1 | — | |
| CVE-2026-64269 | — In the Linux kernel, the following vulnerability has been resolved:
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
When the server answers an RTRS READ, rdma_write_sg() builds | 9.1 | — | |
| CVE-2026-64257 | — In the Linux kernel, the following vulnerability has been resolved:
smb: client: reject overlapping data areas in SMB2 responses
Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption | 9.1 | — | |
| CVE-2023-46945 | — QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request | 9.1 | — | |
| CVE-2026-48021 | — In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain th | 9.1 | — | |
| CVE-2026-46989 | — Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitabl | 9.1 | — | |
| CVE-2026-28321 | — SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain | 9.1 | — | |
| CVE-2026-28317 | — SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in | 9.1 | — | |
| CVE-2026-28316 | — SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the ro | 9.1 | — | |
| CVE-2026-28314 | — SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. | 9.1 | — | |
| CVE-2026-28313 | — SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployme | 9.1 | — | |
| CVE-2026-28312 | — SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows depl | 9.1 | — | |
| CVE-2026-28310 | — SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows d | 9.1 | — | |
| CVE-2026-28309 | — SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. | 9.1 | — | |
| CVE-2026-28308 | — SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Window | 9.1 | — | |
| CVE-2026-42560 | — auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the s | 9.1 | — | |
| CVE-2026-44313 | — Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-Side Request Forgery (SSRF) vulnerability in the fe | 9.1 | — | |
| CVE-2026-42354 | — Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulner | 9.1 | — | |
| CVE-2026-35033 | — Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions quer | 9.1 | — | |
| CVE-2026-34457 | — OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy | 9.1 | — | |
| CVE-2026-40035 | — Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed dire | 9.1 | — | |
| CVE-2026-39847 | — Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path travers | 9.1 | — | |
| CVE-2026-39351 | — Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit. | 9.1 | — | |
| CVE-2026-35459 | — pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP va | 9.1 | — | |
| CVE-2026-35174 | — Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings pe | 9.1 | — | |
| CVE-2026-34953 | — PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request | 9.1 | — | |
| CVE-2026-34952 | — PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any netwo | 9.1 | — | |
| CVE-2026-25197 | — A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call. | 9.1 | — | |
| CVE-2026-32211 | — Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. | 9.1 | — | |
| CVE-2026-34758 | — OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/Wha | 9.1 | — | |
| CVE-2026-34745 | — Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/uploadChunked endpoint but was not applied to the una | 9.1 | — | |
| CVE-2026-34235 | — PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when pa | 9.1 | — | |
| CVE-2026-34221 | — MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge | 9.1 | — | |
| CVE-2026-34532 | — Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator acc | 9.1 | — | |
| CVE-2026-8602 | — In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sens | 9.1 | — | |
| CVE-2026-39833 | — The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication | 9.1 | — | |
| CVE-2026-49840 | — FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version | 9.1 | — | |
| CVE-2026-46440 | — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting an | 9.1 | — | |
| CVE-2026-42535 | — A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users | 9.1 | — | |
| CVE-2026-48579 | — Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | 9.1 | — | |
| CVE-2026-11153 | — Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | 9.1 | — | |
| CVE-2026-8450 | — HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().
send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd | 9.1 | — | |
| CVE-2026-33843 | — Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | 9.1 | — | |
| CVE-2026-16406 | — Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.1 | — | |
| CVE-2026-16394 | — Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | 9.1 | — | |
| CVE-2026-48040 | — The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses | 9.1 | — | |
| CVE-2026-50076 | — Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeCheck | 9.1 | — | |
| CVE-2026-46266 | — In the Linux kernel, the following vulnerability has been resolved:
inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
Yizhou Zhao reported that simply having one RAW socket on protocol
IPP | 9.1 | — | |
| CVE-2026-46244 | — In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_inner: Fix IPv6 inner_thoff desync
In nft_inner_parse_l2l3(), when processing inner IPv6 packets,
ipv6_find_hdr() c | 9.1 | — | |
| CVE-2026-47731 | — The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground | 9.1 | — | |
| CVE-2026-8644 | — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | 9.1 | — | |
| CVE-2026-22872 | — Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the | 9.1 | — | |
| CVE-2026-44650 | — SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, | 9.1 | — | |
| CVE-2026-42252 | — Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] } | 9.1 | — | |
| CVE-2026-46819 | — Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploit | 9.1 | — | |
| CVE-2026-42168 | — django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without | 9.1 | — | |
| CVE-2026-47372 | — Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts.
These versions use the built-in rand function, which is predictable and unsuitable for cryptography. | 9.1 | — | |
| CVE-2026-46621 | — Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through t | 9.1 | — | |
| CVE-2025-49796 | — A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input fi | 9.1 | — | |
| CVE-2025-49794 | — A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. T | 9.1 | — | |
| CVE-2026-44632 | — Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactor | 9.1 | — | |
| CVE-2026-45568 | — zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to url | 9.1 | — | |
| CVE-2026-48807 | — Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not i | 9.1 | — | |
| CVE-2026-48806 | — Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used a | 9.1 | — | |
| CVE-2026-48805 | — Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and a | 9.1 | — | |
| CVE-2026-48324 | Adobe ColdFusion SQL Injection leading to arbitrary code execution (CWE-89) | 9.1 | — | |
| CVE-2026-48319 | Adobe ColdFusion Path Traversal leading to Arbitrary Code Execution (CWE-22) | 9.1 | — | |
| CVE-2026-48358 | Adobe Commerce (Magento) Improper Encoding or Escaping of Output leading to arbitrary code execution (CWE-116) | 9.1 | — | |
| CVE-2026-58122 | Hermes WebUI Authentication bypass via X-Forwarded-For header spoofing (IP origin restriction circumvention) | 9.1 | — | |
| CVE-2026-58473 | cognee Improper Access Control / Missing Authentication for Critical Function (LLM provider configuration overwrite) | 9.1 | — | |
| CVE-2026-59099 | Apereo CAS AES-GCM IV/nonce reuse cryptographic vulnerability leading to plaintext recovery (CWE-323) | 9.1 | — | 1 PoC
|
| CVE-2026-58172 | Ocelot Security control bypass via WebSocket upgrade request omitting IP allowlist/blocklist middleware (CWE-288) | 9.1 | — | |
| CVE-2026-58166 | OpenBMB ChatDev Path Traversal arbitrary file write/delete via multipart filename | 9.1 | — | |
| CVE-2026-56111 | Marlin Firmware Out-of-bounds write via improper array index validation (CWE-129) | 9.1 | — | 1 PoC
|
| CVE-2026-54388 | Tinyproxy HTTP Request Smuggling via duplicate Content-Length headers (CWE-444) | 9.1 | — | |
| CVE-2026-54387 | Tinyproxy HTTP Request Smuggling via CL-TE (Content-Length / Transfer-Encoding) desynchronization | 9.1 | — | |
| CVE-2026-53776 | Perry JWT token expiration bypass (CWE-613: Insufficient Session Expiration) | 9.1 | — | |
| CVE-2026-45230 | DumbAssets Path Traversal Arbitrary File Deletion (CWE-22) | 9.1 | — | |
| CVE-2026-8634 | github.com/openclaw/crabbox Environment variable exposure / overly permissive allowlisting leading to credential leakage in remote command execution (CWE-94) | 9.1 | — | |
| CVE-2026-41473 | CyberPanel Authentication Bypass (CWE-306) - Unauthenticated API Access via AI Scanner Worker Endpoints | 9.1 | — | |
| CVE-2026-40525 | OpenViking Authentication bypass via empty/unset API key check failing open | 9.1 | — | |
| CVE-2026-39912 | V2Board / Xboard Authentication token exposure in HTTP response body (CWE-201) leading to account takeover | 9.1 | — | 1 PoC
|
| CVE-2026-29000 | pac4j-jwt JWT authentication bypass via JWE-wrapped PlainJWT (improper signature verification, CWE-347) | 9.1 | — | 22 PoC
|
| CVE-2025-34282 | ThingsBoard Server-Side Request Forgery (SSRF) via SVG Image Upload | 9.1 | — | 1 PoC
|
| CVE-2024-23687 | FOLIO mod-data-export-spring Hard-coded credentials authentication bypass | 9.1 | — | |
| CVE-2026-13221 | Perl (perl5) Integer overflow in regex trie compilation leading to silent incorrect match results (CWE-190) | 9.1 | — | |
| CVE-2026-23455 | Linux Kernel Out-of-bounds read (CWE-125) via integer underflow in netfilter H.323 connection tracking | 9.1 | — | |
| CVE-2026-40469 | gawk Integer overflow leading to heap metadata corruption | 9.1 | — | |
| CVE-2026-40468 | gawk Integer overflow leading to heap metadata overwrite / memory exhaustion | 9.1 | — | |
| CVE-2026-41041 | Apache Gravitino URL path injection via unencoded user-supplied identifiers | 9.1 | — | |
| CVE-2026-56260 | crawl4ai Path Traversal Arbitrary File Write | 9.1 | — | |
| CVE-2026-53043 | Linux Kernel (ocfs2/dlm) Out-of-bounds read via insufficient field validation in network message parsing | 9.1 | — | |
| CVE-2026-0274 | Cortex XSOAR / Cortex XSIAM - CommvaultSecurityIQ Integration Improper Validation of Credentials (Authentication Bypass) | 9.1 | — | |
| CVE-2026-46354 | github.com/coder/coder Improper Verification of Cryptographic Signature (PKCS#7 signature not verified, CWE-347) | 9.1 | — | |
| CVE-2026-38971 | ardupilot out-of-bounds read (CWE-125) | 9.1 | — | 1 PoC
|
| CVE-2024-40583 | Pentaminds CuroVMS Exposed Credentials (CWE-522: Insufficiently Protected Credentials) | 9.1 | — | |
| CVE-2026-31017 | ERPNext / Frappe Framework Server-Side Request Forgery (SSRF) via HTML-to-PDF rendering | 9.1 | — | |
| CVE-2025-65319 | Blue Mail Mark-of-the-Web (MotW) bypass - missing zone identifier tag on downloaded files | 9.1 | — | 1 PoC
|
| CVE-2025-65669 | classroomio Missing Authorization (Unauthorized Course Deletion) | 9.1 | — | 1 PoC
|
| CVE-2025-56231 | Tonec Internet Download Manager (IDM) Missing SSL Certificate Validation (CWE-295) | 9.1 | — | |
| CVE-2025-56557 | Tuya Smart Life App Unprivileged Matter Device Control (Excessive Privilege / CWE-250) | 9.1 | — | 1 PoC
|
| CVE-2025-45953 | PHPGurukul Hostel Management System Session Hijacking (CWE-384) | 9.1 | — | |
| CVE-2025-25785 | JizhiCMS Server-Side Request Forgery (SSRF) | 9.1 | — | |
| CVE-2024-54879 | SeaCMS Incorrect Access Control / Logic Flaw - Unauthorized Unlimited Member Recharge | 9.1 | — | 1 PoC
|
| CVE-2024-51063 | Phpgurukul Teachers Record Management System SQL Injection | 9.1 | — | 2 PoC
|
| CVE-2024-51060 | Projectworlds Online Admission System v1 SQL Injection | 9.1 | — | 4 PoC
|
| CVE-2024-25294 | REBUILD Server-Side Request Forgery (SSRF) | 9.1 | — | 1 PoC
|
| CVE-2023-27812 | bloofox Arbitrary File Deletion (Path Traversal / CWE-22) | 9.1 | — | 1 PoC
|
| CVE-2023-27162 | openapi-generator (org.openapitools:openapi-generator-project) Server-Side Request Forgery (SSRF) | 9.1 | — | 1 PoC
|
| CVE-2023-24188 | ureport2-core (UReport2) Path Traversal / Directory Traversal leading to Arbitrary File Deletion (CWE-22) | 9.1 | — | |
| CVE-2022-40842 | NdkAdvancedCustomizationFields Server-Side Request Forgery (SSRF) | 9.1 | — | 1 PoC
|
| CVE-2022-31321 | Bolt CMS Improper Input Validation - Directory Enumeration / Denial of Service (DoS) | 9.1 | — | |
| CVE-2021-41945 | Encode OSS httpx (PyPI:httpx) Improper Input Validation (CWE-20) in URL parsing | 9.1 | — | |
| CVE-2022-23383 | YzmCMS Broken Access Control / Authentication Bypass (CWE-287) | 9.1 | — | |
| CVE-2021-42640 | PrinterLogic Web Stack Insecure Direct Object Reference (IDOR) - Unauthenticated Printer Driver Reassignment | 9.1 | — | |
| CVE-2020-25912 | Symphony CMS XML External Entity (XXE) injection | 9.1 | — | |
| CVE-2021-28860 | mixme (node-mixme) Prototype Pollution (CWE-1321) | 9.1 | — | |
| CVE-2026-7874 | IBM Langflow OSS Weak and reversible key derivation mechanism leading to credential disclosure (CWE-338) | 9.1 | — | |
| CVE-2026-7663 | IBM Langflow OSS Improper Authorization / Broken Access Control (unauthenticated access to protected MCP resources) | 9.1 | — | |
| CVE-2026-55276 | Apache Tomcat Always-Incorrect Control Flow Implementation (CWE-670) - special roles and empty authorisation constraints omitted from effective web.xml logging | 9.1 | — | |
| CVE-2026-53434 | Apache Tomcat Detection of Error Condition Without Action (CWE-390) in CRL handling for FFM-based connector | 9.1 | — | |
| CVE-2026-7839 | UltraVNC Repeater Hardcoded Default Credentials (CWE-798) | 9.1 | — | |
| CVE-2026-11720 | googleapis/mcp-toolbox Path Traversal via URL parameter substitution (CWE-22) | 9.1 | — | |
| CVE-2025-62821 | Microsoft HEIF Image Extensions Out-of-bounds read (OOB read) via undersized buffer allocation in image copy path | 9.1 | — | 1 PoC
|
| CVE-2025-4404 | FreeIPA Privilege escalation via krbCanonicalName uniqueness bypass (host to domain) | 9.1 | — | 4 PoC
|
| CVE-2026-42496 | Archive::Tar (Perl) Symlink path traversal / arbitrary file read-write via tar extraction (CWE-59, CWE-22) | 9.1 | — | 2 PoC
|
| CVE-2026-8948 | Mozilla Firefox / Thunderbird Same-origin policy bypass with Cross-Site Scripting (XSS) via DOM Networking component | 9.1 | — | |
| CVE-2026-6104 | PHP mbstring extension Out-of-bounds read via NUL byte in encoding name (CWE-125) | 9.1 | — | |
| CVE-2026-40982 | Spring Cloud Config Path Traversal (Directory Traversal) via crafted URL | 9.1 | — | |
| CVE-2026-5081 | Apache::Session::Generate::ModUniqueId Insecure session ID generation via predictable UNIQUE_ID environment variable (CWE-340/CWE-341) | 9.1 | — | |
| CVE-2026-40682 | Apache OpenNLP XML External Entity (XXE) injection via unsanitized SAX parsing | 9.1 | — | |
| CVE-2026-40976 | Spring Boot Missing Authorization / Authentication Bypass allowing unauthorized access to all endpoints | 9.1 | — | |
| CVE-2026-40575 | oauth2-proxy Authentication Bypass via HTTP Header Spoofing (CWE-290) | 9.1 | — | |
| CVE-2026-33557 | Apache Kafka JWT authentication bypass via missing signature/issuer/audience validation (SASL OAuthBearer) | 9.1 | — | |
| CVE-2026-34582 | Botan C++ cryptography library TLS 1.3 client authentication bypass via premature ApplicationData processing | 9.1 | — | |
| CVE-2026-35030 | LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CWE-287, CWE-222) | 9.1 | — | 1 PoC
|
| CVE-2025-15031 | MLflow Path Traversal arbitrary file write via tar archive extraction (Zip/Tar Slip) | 9.1 | — | |
| CVE-2026-4177 | YAML::Syck Heap buffer overflow in YAML emitter / base64 decoder out-of-bounds read / strtok type_id corruption / memory leak (CWE-122, CWE-120) | 9.1 | — | |
| CVE-2025-55130 | Node.js Permission Model bypass via relative symlink path traversal (arbitrary file read/write) | 9.1 | — | 1 PoC
|
| CVE-2026-22859 | FreeRDP Out-of-bounds read via unchecked server-supplied array index (CWE-125, CWE-129) | 9.1 | — | 1 PoC
|
| CVE-2026-22858 | FreeRDP global-buffer-overflow via Base64 decoding out-of-bounds read/write (CWE-125, CWE-787, CWE-758) | 9.1 | — | 1 PoC
|
| CVE-2026-22855 | FreeRDP Heap out-of-bounds read (OOB read) in smartcard NDR buffer parsing | 9.1 | — | 1 PoC
|
| CVE-2026-40372 | ASP.NET Core Improper verification of cryptographic signature leading to privilege escalation | 9.1 | — | |
| CVE-2026-27876 | Grafana Chained SQL Injection and Code Injection leading to Remote Code Execution (RCE) | 9.1 | — | 1 PoC
|
| CVE-2026-20912 | Gitea Improper Authorization / Broken Object Level Authorization - Cross-Repository Attachment Linking | 9.1 | — | |
| CVE-2026-20897 | Gitea Improper Authorization / Broken Object Level Authorization (BOLA) - LFS Lock Deletion without Repository Ownership Validation | 9.1 | — | |
| CVE-2026-20750 | Gitea Improper Access Control - Organization Project Ownership Validation Bypass | 9.1 | — | |
| CVE-2025-61686 | React Router / Remix (@react-router/node, @remix-run/node, @remix-run/deno) Path Traversal (CWE-22) in createFileSessionStorage | 9.1 | — | 3 PoC
|
| CVE-2026-55455 | Appsmith Server-Side Request Forgery (SSRF) via HTTP host filter bypass | 9.1 | — | |
| CVE-2026-12628 | IBM Storage Protect Client / IBM Storage Protect Snapshot For Windows Hardcoded Credential Authentication Bypass (CWE-798) | 9.1 | — | |
| CVE-2026-46892 | JD Edwards EnterpriseOne Human Resources Management Improper Access Control / Missing Authentication for Critical Function (CWE-284, CWE-306) | 9.1 | — | |
| CVE-2021-30246 | jsrsasign Improper Signature Verification (RSA PKCS#1 v1.5) | 9.1 | — | 7 PoC
|
| CVE-2026-46777 | Oracle WebCenter Content Improper Access Control / Unauthenticated Remote Data Manipulation and Disclosure | 9.1 | — | |
| CVE-2026-46946 | Oracle iSupport (Oracle E-Business Suite) Improper Access Control / Authorization Bypass leading to full product takeover (CWE-284) | 9.1 | — | |
| CVE-2026-46930 | Oracle In-Memory Cost Management for Discrete Industries (Oracle E-Business Suite) Improper Access Control (unauthenticated remote unauthorized data access and modification) | 9.1 | — | |
| CVE-2026-46858 | Oracle Enterprise Manager APM - Application Performance Management Improper Access Control (Unauthenticated Remote Data Manipulation and Denial of Service) | 9.1 | — | |
| CVE-2026-46784 | Oracle WebCenter Content: Imaging Improper Access Control (CWE-284) - Unauthenticated Remote Data Compromise via HTTP | 9.1 | — | |
| CVE-2026-34182 | OpenSSL Insufficient input validation on AuthEnvelopedData cipher and tag length fields leading to authentication bypass and decryption oracle (CWE-354) | 9.1 | — | |
| CVE-2026-48188 | OTRS / ((OTRS)) Community Edition Improper Input Validation - Unauthenticated SQL Injection leading to Authentication Bypass | 9.1 | — | 1 PoC
|
| CVE-2026-26241 | QNAP File Station 5 Stack-based buffer overflow (CWE-121) remote memory corruption / process crash | 9.1 | — | 10 PoC
|
| CVE-2026-26240 | QNAP File Station 5 Stack-based buffer overflow (CWE-121) leading to memory corruption or process crash via remote exploitation | 9.1 | — | |
| CVE-2026-4408 | Samba OS Command Injection via unsanitized shell meta-character substitution (CWE-78) leading to Remote Code Execution | 9.0 | 2.50% | |
| CVE-2024-21403 | — Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 9.0 | 1.34% | |
| CVE-2024-21376 | — Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | 9.0 | 1.17% | |
| CVE-2025-4318 | — The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to creat | 9.0 | 1.03% | |
| CVE-2022-42989 | ERP Sankhya Cross-Site Scripting (XSS) | 9.0 | 1.01% | |
| CVE-2024-38220 | — Azure Stack Hub Elevation of Privilege Vulnerability | 9.0 | 0.97% | |
| CVE-2022-37720 | Orchard CMS Stored Cross-Site Scripting (XSS) leading to privilege escalation / account takeover | 9.0 | 0.96% | |
| CVE-2026-40477 | Thymeleaf Server-Side Template Injection (SSTI) via expression execution security bypass | 9.0 | 0.85% | |
| CVE-2026-40478 | Thymeleaf Server-Side Template Injection (SSTI) / Expression Language Injection security bypass | 9.0 | 0.77% | 1 PoC
|
| CVE-2026-58289 | Microsoft Edge (Chromium-based) Type Confusion Remote Code Execution | 9.0 | 0.53% | |
| CVE-2025-66024 | — The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via t | 9.0 | 0.35% | |
| CVE-2026-61223 | — Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exp | 9.0 | 0.35% | |
| CVE-2026-61201 | — Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnera | 9.0 | 0.35% | |
| CVE-2026-73302 | — Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verifi | 9.0 | 0.31% | |
| CVE-2026-54636 | Dokku OS Command Injection (CWE-78) via app.json cron plugin shell metacharacter escape | 9.0 | 0.27% | |
| CVE-2026-61204 | — Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable v | 9.0 | 0.16% | |
| CVE-2026-60249 | — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploi | 9.0 | 0.16% | |
| CVE-2026-64106 | — In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
Userspace can restore an ITS Device Table Entry whose | 9.0 | 0.15% | |
| CVE-2026-73601 | — Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands | 9.0 | — | |
| CVE-2026-73487 | — Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers | 9.0 | — | |
| CVE-2026-73485 | — Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator bloc | 9.0 | — | |
| CVE-2025-20363 | — A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, | 9.0 | — | |
| CVE-2026-18245 | — Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI | 9.0 | — | |
| CVE-2026-71851 | — crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry p | 9.0 | — | |
| CVE-2026-17351 | — The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statemen | 9.0 | — | |
| CVE-2026-61174 | — Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerabi | 9.0 | — | |
| CVE-2026-44221 | — ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any ot | 9.0 | — | |
| CVE-2026-60424 | — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vuln | 9.0 | — | |
| CVE-2026-42571 | — Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escala | 9.0 | — | |
| CVE-2026-39860 | — Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically | 9.0 | — | |
| CVE-2026-28798 | — ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused | 9.0 | — | |
| CVE-2026-35216 | — Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that conta | 9.0 | — | |
| CVE-2026-34448 | — SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gall | 9.0 | — | |
| CVE-2026-45721 | — Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent | 9.0 | — | |
| CVE-2026-11393 | — Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS Agent | 9.0 | — | |
| CVE-2026-35198 | — HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaS | 9.0 | — | |
| CVE-2026-10868 | — A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the applicat | 9.0 | — | |
| CVE-2026-9319 | — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. | 9.0 | — | |
| CVE-2026-9311 | — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. | 9.0 | — | |
| CVE-2026-45630 | — Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users t | 9.0 | — | |
| CVE-2026-9891 | — Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Ex | 9.0 | — | |
| CVE-2026-9881 | — Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a craf | 9.0 | — | |
| CVE-2026-46833 | — Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with | 9.0 | — | |
| CVE-2026-39846 | — SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is tha | 9.0 | — | |
| CVE-2025-34157 | Coolify Stored Cross-Site Scripting (XSS) in project creation workflow | 9.0 | — | 3 PoC
|
| CVE-2026-30282 | Cast to TV Screen Mirroring by UXGROUP LLC Arbitrary File Overwrite via Path Traversal (CWE-22 / CWE-73) leading to arbitrary code execution or information exposure | 9.0 | — | 1 PoC
|
| CVE-2022-31358 | Proxmox Virtual Environment (pve-http-server) Reflected Cross-Site Scripting (XSS) via non-existent API endpoint path | 9.0 | — | |
| CVE-2022-37721 | pyrocms/pyrocms Stored Cross-Site Scripting (XSS) leading to privilege escalation / admin account takeover | 9.0 | — | |
| CVE-2022-35131 | Joplin Cross-Site Scripting (XSS) leading to Remote Code Execution via crafted Node titles | 9.0 | — | 5 PoC
|
| CVE-2026-12046 | pgAdmin 4 Missing authentication on critical function with pickle deserialization RCE sink (CWE-306 + CWE-502) | 9.0 | — | |
| CVE-2026-12045 | pgAdmin 4 Prompt injection leading to read-only transaction bypass and arbitrary SQL execution (CWE-77, CWE-89) | 9.0 | — | |
| CVE-2026-2651 | MLflow Missing Authorization / Improper Authorization on Multipart Upload Endpoints (CWE-862, CWE-1220) | 9.0 | — | |
| CVE-2026-45408 | Dokku OS Command Injection via unquoted heredoc in bash pre-receive hook (CWE-78) | 9.0 | — | |
| CVE-2026-45406 | Dokku Eval Injection via unsanitized filename interpolation in single-quoted shell string (CWE-95) | 9.0 | — | |
| CVE-2026-45405 | Dokku Symlink traversal / path traversal during archive extraction (Zip Slip variant) | 9.0 | — | |
| CVE-2026-35320 | Oracle WebCenter Content Improper Access Control (unauthenticated network RCE / takeover) | 9.0 | — | |
| CVE-2026-4480 | Samba OS Command Injection via unescaped shell metacharacters in print job description (CWE-78) | 9.0 | — | 5 PoC
|
| CVE-2026-43284 | Linux Kernel In-place decryption on shared skb frags (write-what-where / buffer misuse via shared pipe pages) | 8.8 | 93.2% | 33 PoC
|
| CVE-2023-36899 | — ASP.NET Elevation of Privilege Vulnerability | 8.8 | 77.1% | |
| CVE-2025-15467 | OpenSSL Stack buffer overflow via oversized IV in CMS AEAD parameter parsing (CWE-787, CWE-120) | 8.8 | 47.6% | 6 PoC
|
| CVE-2026-64561 | — In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
Check for a "stale" page fault, i.e. for an invalid a | 8.8 | — | |
| CVE-2025-37899 | — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in session logoff
The sess->user object can currently be in use by another thread, for
example if anothe | 8.8 | — | |
| CVE-2026-43503 | — In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: propagate shared-frag marker through frag-transfer helpers
Two frag-transfer helpers (__pskb_copy_fclone() and skb_sh | 8.8 | — | |
| CVE-2026-53359 | Linux Kernel KVM x86 Shadow Paging Shadow paging use-after-free via unexpected MMU page role mismatch | 8.8 | — | 8 PoC
|
| CVE-2026-23479 | Redis (redis-server) Use-After-Free (UAF) Remote Code Execution via unblock client flow | 8.8 | — | 4 PoC
|
| CVE-2026-23918 | Apache HTTP Server Double Free RCE via HTTP/2 protocol | 8.8 | — | 15 PoC
|
| CVE-2026-41651 | PackageKit Time-of-Check Time-of-Use (TOCTOU) race condition local privilege escalation | 8.8 | — | 12 PoC
|
| CVE-2026-44578 | Next.js Server-Side Request Forgery (SSRF) via WebSocket upgrade request proxying | 8.6 | 38.9% | 8 PoC
|
| CVE-2024-21626 | runc File descriptor leak leading to container escape / host filesystem namespace access | 8.6 | 18.1% | 62 PoC
|
| CVE-2026-42945 | NGINX Plus and NGINX Open Source Heap buffer overflow via PCRE capture in rewrite module (potential RCE) | 8.1 | 66.0% | 44 PoC
|
| CVE-2026-9256 | NGINX Plus / NGINX Open Source Heap buffer overflow via PCRE regex capture groups in rewrite module (RCE) | 8.1 | 10.1% | 5 PoC
|
| CVE-2026-42533 | — A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map outp | 8.1 | 3.60% | |
| CVE-2026-42588 | — Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the | 8.1 | — | |
| CVE-2026-55200 | libssh2 out-of-bounds write heap corruption RCE | 8.1 | — | 4 PoC
|
| CVE-2026-42530 | NGINX Open Source Use-after-Free (UAF) in HTTP/3 QUIC QPACK encoder stream handling leading to worker process restart or RCE | 8.1 | — | 3 PoC
|
| CVE-2026-50656 | — Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". | 7.8 | 10.7% | |
| CVE-2026-46242 | — In the Linux kernel, the following vulnerability has been resolved:
eventpoll: fix ep_remove struct eventpoll / struct file UAF
ep_remove() (via ep_remove_file()) cleared file->f_ep under
file->f_lo | 7.8 | 3.23% | |
| CVE-2026-43499 | — In the Linux kernel, the following vulnerability has been resolved:
rtmutex: Use waiter::task instead of current in remove_waiter()
remove_waiter() is used by the slowlock paths, but it is also used | 7.8 | 0.47% | |
| CVE-2026-23111 | Linux kernel netfilter nf_tables Use-After-Free (CWE-416) via inverted genmask check in catchall map element activation leading to local privilege escalation | 7.8 | 0.34% | 7 PoC
|
| CVE-2026-46331 | Linux Kernel Integer overflow and out-of-bounds write (CWE-190, CWE-787) in net/sched pedit partial COW leading to page cache corruption | 7.8 | 0.32% | 11 PoC
|
| CVE-2026-43494 | — In the Linux kernel, the following vulnerability has been resolved:
net/rds: reset op_nents when zerocopy page pin fails
When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(),
the pinned | 7.8 | 0.27% | |
| CVE-2026-64531 | — In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: reject oversized nested action attrs
Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field | 7.8 | — | |
| CVE-2026-14266 | — 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User int | 7.8 | — | |
| CVE-2025-38001 | — In the Linux kernel, the following vulnerability has been resolved:
net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
Savino says:
"We are writing to report that this recen | 7.8 | — | |
| CVE-2026-64600 | — In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,
a d | 7.8 | — | |
| CVE-2026-46300 | Linux Kernel Out-of-bounds write / arbitrary write via lost shared-frag marker during SKB coalescing (CWE-787, CWE-123) | 7.8 | — | 12 PoC
|
| CVE-2025-6018 | pam-config / Linux PAM (Pluggable Authentication Modules) Local Privilege Escalation (LPE) via incorrect Polkit allow_active authorization (CWE-863 Incorrect Authorization) | 7.8 | — | 25 PoC
|
| CVE-2026-22200 | Enhancesoft osTicket PHP filter chain arbitrary file read via mPDF PDF export (CWE-74 injection) | 7.5 | 73.1% | 2 PoC
|
| CVE-2018-25032 | zlib / nokogiri (RubyGems) Out-of-bounds Write / Memory Corruption during deflate compression (CWE-787) | 7.5 | 52.1% | 14 PoC
|
| CVE-2026-49975 | Apache HTTP Server (mod_http) Memory Allocation with Excessive Size Value leading to Denial of Service (CWE-789, CWE-409) | 7.5 | 28.0% | 12 PoC
|
| CVE-2025-4138 | — Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.
You are affected by this vulnerability if | 7.5 | 1.15% | |
| CVE-2025-60787 | motioneye OS Command Injection via unsanitized configuration parameter write (CWE-20, CWE-78, CWE-116) | 7.2 | — | 9 PoC
|
| CVE-2026-46333 | Linux Kernel Improper Privilege Management (CWE-269) via ptrace dumpability logic bypass | 7.1 | 1.38% | 5 PoC
|
| CVE-2026-46243 | Linux Kernel Improper Input Validation / Dangling Pointer (Use-After-Free) via userspace-supplied cifs.spnego key descriptions | 7.1 | 0.38% | 4 PoC
|
| CVE-2025-6019 | libblockdev Local Privilege Escalation via SUID-root XFS image resize through udisks (CWE-250) | 7.0 | — | 34 PoC
|
| CVE-2026-48710 | Starlette HTTP Host header validation bypass / HTTP Request Smuggling (CWE-444, CWE-1289) | 6.5 | 1.84% | 3 PoC
|
| CVE-2023-40931 | Nagios XI SQL Injection (CWE-89) | 6.5 | — | 5 PoC
|
| CVE-2023-27163 | request-baskets Server-Side Request Forgery (SSRF) | 6.5 | — | 45 PoC
|
| CVE-2023-41425 | Wonder CMS Cross-Site Scripting (XSS) leading to Remote Code Execution via malicious module upload | 6.1 | — | 24 PoC
|
| CVE-2025-26466 | OpenSSH Pre-authentication denial of service via uncontrolled memory allocation (ping/pong packet queue exhaustion) | 5.9 | — | 11 PoC
|
| CVE-2025-32462 | sudo Incorrect authorization / host-based sudoers bypass (CWE-863) | 2.8 | 3.24% | 30 PoC
|