| CVE-2024-35585 | 8.6 | — | — | — | — | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. | 39d ago |
| CVE-2026-84700 | 8.6 | — | — | — | — | PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus | 39d ago |
| CVE-2026-73706 | 8.6 | — | — | — | arubanetworks / fabric composer | A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obt | 39d ago |
| CVE-2026-81889 | 8.6 | — | — | — | — | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. | 40d ago |
| CVE-2026-82645 | 8.6 | — | — | — | — | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restrea | 42d ago |
| CVE-2026-82641 | 8.6 | — | — | — | — | Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces | 42d ago |
| CVE-2026-16061 | 8.6 | — | — | — | — | The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of | 43d ago |
| CVE-2026-55848 | 8.6 | — | — | — | — | mapfish-print is a component of MapFish for printing templated cartographic maps. | 43d ago |
| CVE-2026-82286 | 8.6 | — | — | — | — | gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing una | 43d ago |
| CVE-2026-80590 | 8.6 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments be | 44d ago |
| CVE-2026-81093 | 8.6 | — | — | — | — | The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. | 45d ago |
| CVE-2026-81091 | 8.6 | — | — | — | — | The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. | 45d ago |
| CVE-2026-81573 | 8.6 | — | — | — | — | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not en | 45d ago |
| CVE-2026-27330 | 8.6 | — | — | — | — | Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | 45d ago |
| CVE-2026-54511 | 8.6 | — | — | — | — | LogTape is an unobtrusive logging library. | 46d ago |
| CVE-2026-55539 | 8.6 | — | — | — | — | PraisonAI is a multi-agent teams system. | 47d ago |
| CVE-2022-50999 | 8.6 | — | — | — | nokogiri / nokogiri | Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling func | 47d ago |
| CVE-2026-55534 | 8.6 | — | — | — | — | PraisonAI is a multi-agent teams system. | 47d ago |
| CVE-2026-63587 | 8.6 | — | — | — | — | The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Passwo | 47d ago |
| CVE-2026-78284 | 8.6 | — | — | — | — | Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. | 47d ago |
| CVE-2026-32477 | 8.6 | — | — | — | — | Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 version | 48d ago |
| CVE-2026-28171 | 8.6 | — | — | — | — | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | 48d ago |
| CVE-2026-34741 | 8.6 | — | — | — | — | Combodo iTop is a web based IT service management tool. | 50d ago |
| CVE-2026-75932 | 8.6 | — | — | — | — | Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the a | 51d ago |
| CVE-2026-77775 | 8.6 | — | — | — | — | Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. | 51d ago |
| CVE-2026-72848 | 8.6 | — | — | — | — | SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_ | 51d ago |
| CVE-2026-69558 | 8.6 | — | — | — | microsoft / partner center | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to di | 51d ago |
| CVE-2026-69519 | 8.6 | — | — | — | microsoft / azure stack hci | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a | 51d ago |
| CVE-2026-66800 | 8.6 | — | — | — | microsoft / azure data factory | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information o | 51d ago |
| CVE-2026-75917 | 8.6 | — | — | — | — | SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generat | 53d ago |
| CVE-2026-75916 | 8.6 | — | — | — | — | SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint p | 53d ago |
| CVE-2026-16950 | 8.6 | — | — | — | — | The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before usin | 53d ago |
| CVE-2026-16616 | 8.6 | — | — | — | — | The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation re | 53d ago |
| CVE-2026-12983 | 8.6 | — | — | — | — | The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, | 53d ago |
| CVE-2026-52854 | 8.6 | — | — | — | — | Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. | 53d ago |
| CVE-2026-73939 | 8.6 | — | — | — | oracle / helidon | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). | 53d ago |
| CVE-2026-71131 | 8.6 | — | — | — | oracle / vm virtualbox | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). | 53d ago |
| CVE-2026-70996 | 8.6 | — | — | — | oracle / commerce experience manager | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce | 53d ago |
| CVE-2026-70721 | 8.6 | — | — | — | oracle / hyperion profitability and cost management | Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Depl | 53d ago |
| CVE-2026-62636 | 8.6 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 53d ago |
| CVE-2026-62628 | 8.6 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 53d ago |
| CVE-2026-62625 | 8.6 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 53d ago |
| CVE-2026-62620 | 8.6 | — | — | — | oracle / reports developer | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authent | 53d ago |
| CVE-2026-62599 | 8.6 | — | — | — | oracle / trading community | Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Inte | 53d ago |
| CVE-2026-62586 | 8.6 | — | — | — | oracle / siebel crm | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). | 53d ago |
| CVE-2026-62535 | 8.6 | — | — | — | oracle / hyperion infrastructure technology | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation | 53d ago |
| CVE-2026-61286 | 8.6 | — | — | — | oracle / enterprise manager base platform | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Even | 53d ago |
| CVE-2026-61230 | 8.6 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 53d ago |
| CVE-2026-61228 | 8.6 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 53d ago |
| CVE-2026-61045 | 8.6 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 53d ago |
| CVE-2026-61033 | 8.6 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 53d ago |
| CVE-2026-60699 | 8.6 | — | — | — | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | 53d ago |
| CVE-2026-75926 | 8.6 | — | — | — | — | Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through Post | 54d ago |
| CVE-2026-75856 | 8.6 | — | — | — | — | CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fail | 54d ago |
| CVE-2026-74902 | 8.6 | — | — | — | — | SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails t | 54d ago |
| CVE-2026-56677 | 8.6 | — | — | — | — | 9Router is an AI router & token saver. | 54d ago |
| CVE-2026-74791 | 8.6 | — | — | — | — | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowin | 56d ago |
| CVE-2026-72810 | 8.6 | — | — | — | — | SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that | 58d ago |
| CVE-2026-15205zero day | 8.6 | 0.45% | 1/3 | same day | — | The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier b | 58d ago |
| CVE-2026-17502 | 8.6 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds wr | 58d ago |