| CVE-2026-80465 | 8.7 | — | — | — | — | A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Me | 38d ago |
| CVE-2026-79679 | 8.7 | — | — | — | — | Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. | 38d ago |
| CVE-2026-84695 | 8.7 | — | — | — | — | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that | 39d ago |
| CVE-2026-82466 | 8.7 | — | — | — | — | Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logg | 42d ago |
| CVE-2026-47665 | 8.7 | — | — | — | — | Penpot is an open-source design and prototyping platform. | 45d ago |
| CVE-2026-77693 | 8.7 | — | — | — | — | The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a | 46d ago |
| CVE-2026-59335 | 8.7 | — | — | — | — | Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endp | 47d ago |
| CVE-2026-40877 | 8.7 | — | — | — | — | Combodo iTop is a web-based IT service management tool. | 47d ago |
| CVE-2026-78213 | 8.7 | — | — | — | — | Heptabase developed by Hepta Platforms, Inc. | 48d ago |
| CVE-2026-60084 | 8.7 | — | — | — | — | SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate e | 50d ago |
| CVE-2026-77811 | 8.7 | — | — | — | — | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenti | 50d ago |
| CVE-2026-13097 | 8.7 | — | — | — | redhat / enterprise linux | A privilege escalation flaw was found in FreeIPA. | 52d ago |
| CVE-2026-68899 | 8.7 | — | — | — | — | Wekan is open source kanban built with Meteor. | 52d ago |
| CVE-2026-49283 | 8.7 | — | — | — | — | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. | 53d ago |
| CVE-2026-71050 | 8.7 | — | — | — | oracle / product lifecycle analytics | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Is | 53d ago |
| CVE-2026-71000 | 8.7 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 53d ago |
| CVE-2026-70903 | 8.7 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 53d ago |
| CVE-2026-70900 | 8.7 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 53d ago |
| CVE-2026-70882 | 8.7 | — | — | — | oracle / hyperion data relationship management | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access an | 53d ago |
| CVE-2026-70778 | 8.7 | — | — | — | oracle / customer care | Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). | 53d ago |
| CVE-2026-62607 | 8.7 | — | — | — | oracle / customer care | Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). | 53d ago |
| CVE-2026-62589 | 8.7 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). | 53d ago |
| CVE-2026-61332 | 8.7 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). | 53d ago |
| CVE-2026-61219 | 8.7 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 53d ago |
| CVE-2026-61215 | 8.7 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 53d ago |
| CVE-2026-61193 | 8.7 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 53d ago |
| CVE-2026-60996 | 8.7 | — | — | — | oracle / identity manager connector | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Connectors | 53d ago |
| CVE-2026-60981 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 53d ago |
| CVE-2026-60980 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 53d ago |
| CVE-2026-60954 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 53d ago |
| CVE-2026-60935 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 53d ago |
| CVE-2026-60934 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 53d ago |
| CVE-2026-60903 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 53d ago |
| CVE-2026-60860 | 8.7 | — | — | — | oracle / service delivery platform | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). | 53d ago |
| CVE-2026-60707 | 8.7 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). | 53d ago |
| CVE-2026-54347 | 8.7 | — | — | — | — | Froxlor is open source server administration software. | 53d ago |
| CVE-2026-75924 | 8.7 | — | — | — | — | A flaw was found in managed-serviceaccount. | 53d ago |
| CVE-2026-55839 | 8.7 | — | — | — | — | Kestra is an open-source, event-driven orchestration platform. | 54d ago |
| CVE-2026-45116 | 8.7 | — | — | — | — | MyBB is free and open source forum software. | 54d ago |
| CVE-2026-45115 | 8.7 | — | — | — | — | MyBB is free and open source forum software. | 54d ago |
| CVE-2026-75855 | 8.7 | — | — | — | — | ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create datab | 54d ago |
| CVE-2026-75828 | 8.7 | — | — | — | — | Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired | 54d ago |
| CVE-2026-74798 | 8.7 | — | — | — | — | SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. | 55d ago |
| CVE-2026-49478 | 8.7 | — | — | — | — | Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. | 59d ago |
| CVE-2026-73332 | 8.7 | — | — | — | — | CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-p | 59d ago |
| CVE-2026-73329 | 8.7 | — | — | — | — | CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to | 59d ago |
| CVE-2026-15217 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, | 59d ago |
| CVE-2026-15216 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, | 59d ago |
| CVE-2026-12004 | 8.7 | — | — | — | ibm / security verify access | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify | 59d ago |
| CVE-2026-73031 | 8.7 | — | — | — | — | telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbit | 60d ago |
| CVE-2026-48413 | 8.7 | — | — | — | — | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-priv | 60d ago |
| CVE-2026-21273 | 8.7 | — | — | — | adobe / coldfusion | is affected by an Improper Input Validation vulnerability that could result in privilege escalation. | 60d ago |
| CVE-2026-18860 | 8.7 | — | — | — | — | Velociraptor allows multi-tenant deployments named "Orgs". | 61d ago |
| CVE-2026-18608 | 8.7 | — | — | — | — | A flaw was found in the Data Science Pipelines Operator (DSPO). | 61d ago |
| CVE-2026-72730 | 8.7 | — | — | — | — | Discourse is an open-source discussion platform. | 61d ago |
| CVE-2026-48026 | 8.7 | — | — | — | — | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. | 64d ago |
| CVE-2026-62836 | 8.7 | — | — | — | microsoft / azure sql managed instance | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauth | 65d ago |
| CVE-2026-3415 | 8.7 | — | — | — | — | The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of vali | 65d ago |
| CVE-2026-16315 | 8.7 | — | — | — | — | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend | 66d ago |
| CVE-2026-71236 | 8.7 | — | — | — | — | Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies | 67d ago |