| CVE-2026-45625 | 9.9 | — | — | — | — | Arcane is an interface for managing Docker containers, images, networks, and volumes. | 99d ago |
| CVE-2026-45663 | 9.9 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 99d ago |
| CVE-2026-44962 | 9.9 | — | — | — | — | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-su | 99d ago |
| CVE-2026-45312 | 9.9 | — | — | — | — | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. | 99d ago |
| CVE-2026-9559 | 9.9 | — | — | — | — | A path traversal vulnerability exists in the campaign import feature of Mautic 7. | 99d ago |
| CVE-2026-9558 | 9.9 | — | — | — | — | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. | 99d ago |
| CVE-2026-44881 | 9.9 | — | — | — | portainer / portainer | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be | 100d ago |
| CVE-2026-9645 | 9.9 | — | — | — | scadabr / scadabr | Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. | 100d ago |
| CVE-2026-46839 | 9.9 | — | — | — | oracle / rest data services | Vulnerability in Oracle REST Data Services (component: Core). | 100d ago |
| CVE-2026-46824 | 9.9 | — | — | — | oracle / universal work queue | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site | 100d ago |
| CVE-2026-46822 | 9.9 | — | — | — | oracle / iassets | Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). | 100d ago |
| CVE-2026-46775 | 9.9 | — | — | — | oracle / rest data services | Vulnerability in Oracle REST Data Services (component: Core). | 100d ago |
| CVE-2026-44477 | 9.9 | — | — | — | linuxfoundation / cloudnativepg | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. | 100d ago |
| CVE-2026-9813 | 9.9 | — | — | — | flowintel / flowintel | FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference | 100d ago |
| CVE-2026-45102 | 9.9 | — | — | — | — | OneUptime is an open-source monitoring and observability platform. | 101d ago |
| CVE-2026-46425 | 9.9 | — | — | — | — | Budibase is an open-source low-code platform. | 101d ago |
| CVE-2026-42757 | 9.9 | — | — | — | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: | 101d ago |
| CVE-2026-42756 | 9.9 | — | — | — | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWe | 101d ago |
| CVE-2026-42748 | 9.9 | — | — | — | — | Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a W | 101d ago |
| CVE-2026-44450 | 9.9 | — | — | — | — | Lumiverse is a full-featured AI chat application. | 102d ago |
| CVE-2026-46624 | 9.9 | — | — | — | twenty / twenty | Twenty is an open source CRM. | 102d ago |
| CVE-2026-7374 | 9.9 | — | — | — | — | A flaw was found in KubeVirt's virt-handler component. | 102d ago |
| CVE-2026-40411 | 9.9 | — | — | — | microsoft / azure virtual network gateway | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a ne | 106d ago |
| CVE-2026-44050 | 9.9 | — | — | — | — | A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remot | 108d ago |
| CVE-2026-33642 | 9.9 | — | — | — | kovidgoyal / kitty | Kitty is a cross-platform GPU based terminal. | 109d ago |
| CVE-2026-27130 | 9.9 | — | — | — | — | Dokploy is a free, self-hostable Platform as a Service (PaaS). | 110d ago |
| CVE-2026-44774 | 9.9 | — | — | — | traefik / traefik | Traefik is an HTTP reverse proxy and load balancer. | 113d ago |
| CVE-2026-44442 | 9.9 | — | — | — | frappe / erpnext | ERPNext is a free and open source Enterprise Resource Planning tool. | 115d ago |
| CVE-2026-43999 | 9.9 | — | — | — | vm2 project / vm2 | vm2 is an open source vm/sandbox for Node.js. | 115d ago |
| CVE-2026-41050 | 9.9 | — | — | — | — | Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with g | 116d ago |
| CVE-2026-43948 | 9.9 | — | — | — | — | wger is a free, open-source workout and fitness manager. | 116d ago |
| CVE-2026-42898 | 9.9 | — | — | — | microsoft / dynamics 365 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an author | 116d ago |
| CVE-2026-42823 | 9.9 | — | — | — | microsoft / azure logic apps | Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | 116d ago |
| CVE-2026-42864 | 9.9 | — | — | — | — | FireFighter is an incident management application. | 117d ago |
| CVE-2026-7813 | 9.9 | — | — | — | pgadmin / pgadmin 4 | Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background P | 117d ago |
| CVE-2026-33309 | 9.9 | — | — | — | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 165d ago |
| CVE-2026-22172 | 9.9 | — | — | — | openclaw / openclaw | OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path t | 169d ago |
| CVE-2026-32768 | 9.9 | — | — | — | ctfer-io / chall-manager | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. | 170d ago |
| CVE-2026-32938 | 9.9 | — | — | — | b3log / siyuan | SiYuan is a personal knowledge management system. | 170d ago |
| CVE-2026-26137 | 9.9 | — | — | — | microsoft / 365 copilot chat | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over | 170d ago |
| CVE-2026-32731 | 9.9 | — | — | — | apostrophecms / import-export | ApostropheCMS is an open-source content management framework. | 171d ago |
| CVE-2026-32621 | 9.9 | — | — | — | — | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. | 173d ago |
| CVE-2026-32306 | 9.9 | — | — | — | hackerbay / oneuptime | OneUptime is a solution for monitoring and managing online services. | 176d ago |
| CVE-2026-22192 | 9.9 | — | — | — | gvectors / wpdiscuz | Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticat | 176d ago |
| CVE-2026-21708 | 9.9 | — | — | — | veeam / veeam backup \& replication | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. | 177d ago |
| CVE-2026-21669 | 9.9 | — | — | — | veeam / veeam backup \& replication | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | 177d ago |
| CVE-2026-21667 | 9.9 | — | — | — | veeam / veeam backup \& replication | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | 177d ago |
| CVE-2026-21666 | 9.9 | — | — | — | veeam / veeam backup \& replication | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | 177d ago |
| CVE-2026-27591 | 9.9 | — | — | — | wintercms / winter | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. | 178d ago |
| CVE-2025-66956 | 9.9 | — | — | — | — | Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attac | 178d ago |
| CVE-2026-86189 | 9.8 | — | — | — | — | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attacker | 19h ago |
| CVE-2026-86184 | 9.8 | — | — | — | — | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that all | 20h ago |
| CVE-2026-10196 | 9.8 | — | — | — | — | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnera | 20h ago |
| CVE-2026-86124 | 9.8 | — | — | — | — | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all inte | 22h ago |
| CVE-2026-86121 | 9.8 | — | — | — | — | Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is uns | 22h ago |
| CVE-2024-11080 | 9.8 | — | — | — | — | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Inject | 23h ago |
| CVE-2026-83627 | 9.8 | — | — | — | — | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote | 1d ago |
| CVE-2026-13447 | 9.8 | — | — | — | — | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and | 1d ago |
| CVE-2026-75430 | 9.8 | — | — | — | — | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint with | 1d ago |
| CVE-2026-31020 | 9.8 | — | — | — | — | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt c | 1d ago |