| CVE-2026-44494 | 8.7 | — | — | — | axios / axios | Axios is a promise based HTTP client for the browser and Node.js. | 122d ago |
| CVE-2026-10087 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, | 122d ago |
| CVE-2026-41031 | 8.7 | — | — | — | — | A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allo | 124d ago |
| CVE-2026-46392 | 8.7 | — | — | — | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. | 127d ago |
| CVE-2026-7313 | 8.7 | — | — | — | progress / sitefinity | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3. | 131d ago |
| CVE-2026-9024 | 8.7 | — | — | — | — | A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Eng | 132d ago |
| CVE-2026-49368 | 8.7 | — | — | — | jetbrains / youtrack | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | 134d ago |
| CVE-2026-48527 | 8.7 | — | — | — | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. | 135d ago |
| CVE-2026-45348 | 8.7 | — | — | — | — | pyLoad is a free and open-source download manager written in Python. | 135d ago |
| CVE-2026-44543 | 8.7 | — | — | — | suse / local path provisioner | Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. | 136d ago |
| CVE-2026-47762 | 8.7 | — | — | — | tiny / tinymce | TinyMCE is an open source rich text editor. | 136d ago |
| CVE-2026-47761 | 8.7 | — | — | — | tiny / tinymce | TinyMCE is an open source rich text editor. | 136d ago |
| CVE-2026-47760 | 8.7 | — | — | — | tiny / tinymce | TinyMCE is an open source rich text editor. | 136d ago |
| CVE-2026-47759 | 8.7 | — | — | — | tiny / tinymce | TinyMCE is an open source rich text editor. | 136d ago |
| CVE-2026-42197 | 8.7 | — | — | — | — | RELATE is a web-based courseware package. | 136d ago |
| CVE-2026-44669 | 8.7 | — | — | — | — | FACTION is a PenTesting Report Generation and Collaboration Framework. | 137d ago |
| CVE-2026-44667 | 8.7 | — | — | — | — | FACTION is a PenTesting Report Generation and Collaboration Framework. | 137d ago |
| CVE-2026-44729 | 8.7 | — | — | — | twenty / twenty | Twenty is an open source CRM. | 138d ago |
| CVE-2026-41147 | 8.7 | — | — | — | — | NukeViet CMS is a multi Content Management System. | 141d ago |
| CVE-2026-28445 | 8.7 | — | — | — | — | Typebot is a chatbot builder tool. | 142d ago |
| CVE-2026-40165 | 8.7 | — | — | — | — | authentik is an open-source identity provider. | 143d ago |
| CVE-2026-34241 | 8.7 | — | — | — | — | CtrlPanel is open-source billing software for hosting providers. | 144d ago |
| CVE-2026-27173 | 8.7 | — | — | — | apache / apache-airflow-providers-cncf-kubernetes | JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access t | 144d ago |
| CVE-2026-6346 | 8.7 | — | — | — | mattermost / mattermost server | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuratio | 146d ago |
| CVE-2026-45315 | 8.7 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 148d ago |
| CVE-2026-44552 | 8.7 | — | — | — | openwebui / open webui | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. | 148d ago |
| CVE-2026-7481 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, a | 150d ago |
| CVE-2026-7377 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, a | 150d ago |
| CVE-2026-6073 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, a | 150d ago |
| CVE-2026-33583 | 8.7 | — | — | — | — | Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys v | 150d ago |
| CVE-2026-0240 | 8.7 | — | — | — | paloaltonetworks / trust protection foundation | An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain | 150d ago |
| CVE-2026-44295 | 8.7 | — | — | — | protobufjs project / protobufjs-cli | protobufjs-cli is the command line add-on for protobuf.js. | 151d ago |
| CVE-2026-42930 | 8.7 | — | — | — | f5 / big-ip access policy manager | When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass | 151d ago |
| CVE-2026-42924 | 8.7 | — | — | — | f5 / big-ip access policy manager | An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration obje | 151d ago |
| CVE-2026-42406 | 8.7 | — | — | — | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas | 151d ago |
| CVE-2026-41953 | 8.7 | — | — | — | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resou | 151d ago |
| CVE-2026-40698 | 8.7 | — | — | — | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas | 151d ago |
| CVE-2026-40631 | 8.7 | — | — | — | f5 / big-ip access policy manager | An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects t | 151d ago |
| CVE-2026-40061 | 8.7 | — | — | — | f5 / big-ip domain name system | When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh | 151d ago |
| CVE-2026-34176 | 8.7 | — | — | — | f5 / big-ip access policy manager | When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed i | 151d ago |
| CVE-2026-32673 | 8.7 | — | — | — | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Admi | 151d ago |
| CVE-2026-32643 | 8.7 | — | — | — | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas | 151d ago |
| CVE-2026-34686 | 8.7 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-34653 | 8.7 | — | — | — | adobe / commerce | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected | 151d ago |
| CVE-2026-45392 | 8.7 | — | — | — | — | DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary J | 152d ago |
| CVE-2026-43912 | 8.7 | — | — | — | dani-garcia / vaultwarden | Vaultwarden is a Bitwarden-compatible server written in Rust. | 152d ago |
| CVE-2026-43888 | 8.7 | — | — | — | — | Outline is a service that allows for collaborative documentation. | 152d ago |
| CVE-2026-32277 | 8.7 | — | — | — | opensource-workshop / connect-cms | Connect-CMS is a content management system. | 201d ago |
| CVE-2026-4601 | 8.7 | — | — | — | kjur / jsrsasign | Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DS | 202d ago |
| CVE-2026-33226 | 8.7 | — | — | — | budibase / budibase | Budibase is a low code platform for creating internal tools, workflows, and admin panels. | 204d ago |
| CVE-2026-33172 | 8.7 | — | — | — | statamic / statamic | Statamic is a Laravel and Git powered content management system (CMS). | 204d ago |
| CVE-2026-33346 | 8.7 | — | — | — | open-emr / openemr | OpenEMR is a free and open source electronic health records and medical practice management application. | 205d ago |
| CVE-2026-32627 | 8.7 | — | — | — | yhirose / cpp-httplib | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. | 209d ago |
| CVE-2026-1090 | 8.7 | — | — | — | gitlab / gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, | 214d ago |
| CVE-2026-86119 | 8.6 | — | — | — | — | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, | 36d ago |
| CVE-2026-19305 | 8.6 | — | — | — | — | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server- | 37d ago |
| CVE-2026-85620 | 8.6 | — | — | — | — | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not appli | 37d ago |
| CVE-2026-85614 | 8.6 | — | — | — | — | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/sit | 37d ago |
| CVE-2026-63219zero day | 8.6 | 0.47% | 2/3 | 1d before | — | GeoNetwork is a catalog application to manage spatially referenced resources. | 37d ago |
| CVE-2026-20276 | 8.6 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software enginee | 39d ago |