| CVE-2026-71233 | 8.7 | — | — | — | — | InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw | 67d ago |
| CVE-2026-70492 | 8.7 | — | — | — | — | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. | 67d ago |
| CVE-2026-67336 | 8.7 | — | — | — | — | better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins tha | 71d ago |
| CVE-2026-17735 | 8.7 | — | — | — | google / chrome | Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote att | 73d ago |
| CVE-2026-58157 | 8.7 | — | — | — | apache / traffic server | Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. | 74d ago |
| CVE-2026-15325 | 8.7 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smug | 74d ago |
| CVE-2026-15064 | 8.7 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0 | 74d ago |
| CVE-2026-66394 | 8.7 | — | — | — | — | SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that a | 76d ago |
| CVE-2026-47743 | 8.7 | — | — | — | — | Shopper is a Headless e-commerce Admin Panel. | 80d ago |
| CVE-2026-61078 | 8.7 | — | — | — | oracle / peoplesoft enterprise cc common application objects | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: | 81d ago |
| CVE-2026-60941 | 8.7 | — | — | — | oracle / service fulfillment manager | Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment | 81d ago |
| CVE-2026-60597 | 8.7 | — | — | — | oracle / peoplesoft enterprise fin cash management | Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Manag | 81d ago |
| CVE-2026-60553 | 8.7 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 81d ago |
| CVE-2026-60523 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-60470 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). | 81d ago |
| CVE-2026-60469 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). | 81d ago |
| CVE-2026-60448 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-60443 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 81d ago |
| CVE-2026-60437 | 8.7 | — | — | — | oracle / unified directory | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | 81d ago |
| CVE-2026-60427 | 8.7 | — | — | — | oracle / unified directory | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | 81d ago |
| CVE-2026-60214 | 8.7 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 81d ago |
| CVE-2026-47017 | 8.7 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler) | 81d ago |
| CVE-2026-15724 | 8.7 | — | — | — | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative | 82d ago |
| CVE-2026-45270 | 8.7 | — | — | — | — | CI4MS is a CodeIgniter 4-based content management system skeleton. | 83d ago |
| CVE-2026-64104 | 8.7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: virt: sev-guest: Explicitly leak pages in unkn | 84d ago |
| CVE-2026-16158 | 8.7 | — | — | — | fastify / fastify\/reply-from | Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by | 85d ago |
| CVE-2026-15631 | 8.7 | — | — | — | fastify / fastify\/http-proxy | Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket | 85d ago |
| CVE-2026-47869 | 8.7 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a remote code execution vulnerability. | 85d ago |
| CVE-2026-47867 | 8.7 | — | — | — | broadcom / vmware avi load balancer | VMware Avi Load Balancer contains a remote code execution vulnerability. | 85d ago |
| CVE-2026-54498 | 8.7 | — | — | — | viewcomponent / view component | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. | 85d ago |
| CVE-2026-44739 | 8.7 | — | — | — | — | Pimcore is an Open Source Data & Experience Management Platform. | 85d ago |
| CVE-2026-47994 | 8.7 | — | — | — | adobe / commerce | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-priv | 88d ago |
| CVE-2026-55466 | 8.7 | — | — | — | snipeitapp / snipe-it | Snipe-IT is an IT asset/license management system. | 92d ago |
| CVE-2026-6896 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, a | 94d ago |
| CVE-2026-55596 | 8.7 | — | — | — | — | Plate is a rich-text editor with AI and shadcn/ui. | 94d ago |
| CVE-2026-60104 | 8.7 | — | — | — | bitwarden / server | Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belong | 94d ago |
| CVE-2026-14891 | 8.7 | — | — | — | — | HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a | 94d ago |
| CVE-2026-55429 | 8.7 | — | — | — | coder / coder | Coder allows organizations to provision remote development environments via Terraform. | 95d ago |
| CVE-2026-12277 | 8.7 | — | — | — | — | The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user inp | 96d ago |
| CVE-2026-57983 | 8.7 | — | — | — | microsoft / edge chromium | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security fea | 99d ago |
| CVE-2026-28737 | 8.7 | — | — | — | — | Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in | 99d ago |
| CVE-2026-54406 | 8.7 | — | — | — | ui / unifi network application | A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability foun | 101d ago |
| CVE-2026-10643 | 8.7 | — | — | — | zephyrproject / zephyr | Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated th | 105d ago |
| CVE-2026-55069 | 8.7 | — | — | — | kestra / kestra | Kestra is an open-source, event-driven orchestration platform. | 106d ago |
| CVE-2026-53230 | 8.7 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix slab-out-of-bounds in mlx5_query | 108d ago |
| CVE-2026-10086 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, a | 108d ago |
| CVE-2026-52805 | 8.7 | — | — | — | — | Gogs is an open source self-hosted Git service. | 108d ago |
| CVE-2026-56223 | 8.7 | — | — | — | — | Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint th | 109d ago |
| CVE-2026-7574 | 8.7 | — | — | — | — | Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348. | 109d ago |
| CVE-2026-54011 | 8.7 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 110d ago |
| CVE-2026-48716 | 8.7 | — | — | — | — | nanobot is a personal AI assistant. | 114d ago |
| CVE-2026-46808 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 116d ago |
| CVE-2026-46804 | 8.7 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 116d ago |
| CVE-2026-35271 | 8.7 | — | — | — | oracle / peoplesoft enterprise pt peopletools | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). | 116d ago |
| CVE-2026-35258 | 8.7 | — | — | — | oracle / weblogic server | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). | 116d ago |
| CVE-2026-53608 | 8.7 | — | — | — | — | ApostropheCMS is an open-source Node.js content management system. | 120d ago |
| CVE-2026-47691 | 8.7 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |
| CVE-2026-6211 | 8.7 | — | — | — | — | Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. | 121d ago |
| CVE-2026-47135 | 8.7 | — | — | — | — | vm2 is an open source vm/sandbox for Node.js. | 121d ago |
| CVE-2026-45674 | 8.7 | — | — | — | netty / netty | Netty is a network application framework for development of protocol servers and clients. | 121d ago |