| CVE-2026-34038 | 9.9 | — | — | — | — | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. | 61d ago |
| CVE-2026-48614 | 9.9 | — | — | — | — | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary conf | 61d ago |
| CVE-2026-40141 | 9.9 | — | — | — | beyondtrust / privileged remote access | A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged R | 61d ago |
| CVE-2026-57100 | 9.9 | — | — | — | microsoft / entra provisioning service | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attac | 65d ago |
| CVE-2026-45499 | 9.9 | — | — | — | microsoft / azure openai | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a netw | 65d ago |
| CVE-2026-44935 | 9.9 | — | — | — | suse / rancher fleet | Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 befo | 65d ago |
| CVE-2026-55115 | 9.9 | — | — | — | ui / unifi protect | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) | 65d ago |
| CVE-2026-54402 | 9.9 | — | — | — | ui / unifi os server | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 65d ago |
| CVE-2026-50748 | 9.9 | — | — | — | ui / unifi access | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnera | 65d ago |
| CVE-2026-50747 | 9.9 | — | — | — | ui / unifi talk application | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Inject | 65d ago |
| CVE-2026-27419 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. | 65d ago |
| CVE-2026-50195 | 9.9 | — | — | — | linuxfoundation / containerd | containerd is an open-source container runtime. | 66d ago |
| CVE-2026-7873 | 9.9 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sens | 67d ago |
| CVE-2026-57331 | 9.9 | — | — | — | — | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. | 68d ago |
| CVE-2026-58053 | 9.9 | — | — | — | — | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the | 70d ago |
| CVE-2026-52785 | 9.9 | — | — | — | — | OpenProject is open-source, web-based project management software. | 71d ago |
| CVE-2026-52782 | 9.9 | — | — | — | — | OpenProject is open-source, web-based project management software. | 71d ago |
| CVE-2026-46386 | 9.9 | — | — | — | — | OpenProject is open-source, web-based project management software. | 71d ago |
| CVE-2026-56059 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. | 71d ago |
| CVE-2026-56058 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. | 71d ago |
| CVE-2026-56027 | 9.9 | — | — | — | — | Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. | 71d ago |
| CVE-2026-54823 | 9.9 | — | — | — | — | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. | 72d ago |
| CVE-2026-55454 | 9.9 | — | — | — | appsmith / appsmith | Appsmith is a platform to build admin panels, internal tools, and dashboards. | 73d ago |
| CVE-2026-54158 | 9.9 | — | — | — | — | SiYuan is an open-source personal knowledge management system. | 73d ago |
| CVE-2026-54067 | 9.9 | — | — | — | — | SiYuan is an open-source personal knowledge management system. | 73d ago |
| CVE-2026-50551 | 9.9 | — | — | — | — | SiYuan is an open-source personal knowledge management system. | 73d ago |
| CVE-2026-52806exploited | 9.9 | 7.9% | 2/4 | +4d | — | Gogs is an open source self-hosted Git service. | 73d ago |
| CVE-2026-54305 | 9.9 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-44791 | 9.9 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-44789 | 9.9 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-54310 | 9.9 | — | — | — | n8n / n8n | n8n is an open source workflow automation platform. | 74d ago |
| CVE-2026-56274 | 9.9 | — | — | — | flowiseai / flowise | Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due t | 74d ago |
| CVE-2026-5366 | 9.9 | — | — | — | prefect / prefect | Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in | 77d ago |
| CVE-2026-48584 | 9.9 | — | — | — | microsoft / azure synapse | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a | 78d ago |
| CVE-2026-56142 | 9.9 | — | — | — | jetbrains / hub | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 pr | 78d ago |
| CVE-2026-47647 | 9.9 | — | — | — | microsoft / dynamics 365 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a netwo | 79d ago |
| CVE-2026-49252 | 9.9 | — | — | — | — | deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale | 79d ago |
| CVE-2026-48781 | 9.9 | — | — | — | — | Postiz is an AI social media scheduling tool. | 80d ago |
| CVE-2026-40783 | 9.9 | — | — | — | — | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. | 80d ago |
| CVE-2026-40749 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. | 80d ago |
| CVE-2026-40748 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. | 80d ago |
| CVE-2026-40747 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. | 80d ago |
| CVE-2026-40746 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. | 80d ago |
| CVE-2026-39589 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. | 80d ago |
| CVE-2026-27041 | 9.9 | — | — | — | — | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. | 80d ago |
| CVE-2026-25446 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. | 80d ago |
| CVE-2026-22327 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. | 80d ago |
| CVE-2025-60218 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. | 80d ago |
| CVE-2024-52488 | 9.9 | — | — | — | — | Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions. | 80d ago |
| CVE-2026-46964 | 9.9 | — | — | — | oracle / universal work queue | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site | 80d ago |
| CVE-2026-46963 | 9.9 | — | — | — | oracle / universal work queue | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site | 80d ago |
| CVE-2026-46933 | 9.9 | — | — | — | oracle / applications manager | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operation | 80d ago |
| CVE-2026-46918 | 9.9 | — | — | — | oracle / process manufacturing product development | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (componen | 80d ago |
| CVE-2026-46908 | 9.9 | — | — | — | oracle / jd edwards enterpriseone accounts payable | Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts P | 80d ago |
| CVE-2026-46907 | 9.9 | — | — | — | oracle / jd edwards enterpriseone global order promising | Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Oracle JD Edwards (component: Order Promi | 80d ago |
| CVE-2026-46901 | 9.9 | — | — | — | oracle / enterprise command center framework | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Cor | 80d ago |
| CVE-2026-46900 | 9.9 | — | — | — | oracle / enterprise command center framework | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Cor | 80d ago |
| CVE-2026-46897 | 9.9 | — | — | — | oracle / enterprise command center framework | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Cor | 80d ago |
| CVE-2026-46895 | 9.9 | — | — | — | oracle / enterprise command center framework | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Cor | 80d ago |
| CVE-2026-46893 | 9.9 | — | — | — | oracle / jd edwards enterpriseone general ledger | Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundatio | 80d ago |