| CVE-2026-16815 | 8.6 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sen | 59d ago |
| CVE-2026-72777 | 8.6 | — | — | — | — | Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url end | 59d ago |
| CVE-2026-73608 | 8.6 | — | — | — | — | SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in | 59d ago |
| CVE-2026-59505 | 8.6 | — | — | — | — | : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solu | 59d ago |
| CVE-2026-59499 | 8.6 | — | — | — | — | : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to P | 59d ago |
| CVE-2026-72804 | 8.6 | — | — | — | — | SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allo | 60d ago |
| CVE-2026-72798 | 8.6 | — | — | — | — | SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing an | 60d ago |
| CVE-2026-72795 | 8.6 | — | — | — | — | SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed | 60d ago |
| CVE-2026-72794 | 8.6 | — | — | — | — | siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to un | 60d ago |
| CVE-2026-72793 | 8.6 | — | — | — | — | SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, all | 60d ago |
| CVE-2026-72789 | 8.6 | — | — | — | — | SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly | 60d ago |
| CVE-2026-18474 | 8.6 | — | — | — | — | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a S | 60d ago |
| CVE-2026-68433 | 8.6 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to fro | 60d ago |
| CVE-2026-73247 | 8.6 | — | — | — | — | Kestra is an open-source, event-driven orchestration platform. | 60d ago |
| CVE-2026-72742 | 8.6 | — | — | — | — | DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows a | 61d ago |
| CVE-2026-48441 | 8.6 | — | — | — | adobe / lightroom | Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 61d ago |
| CVE-2026-48397 | 8.6 | — | — | — | adobe / lightroom | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary | 61d ago |
| CVE-2026-24911 | 8.6 | — | — | — | intel / proset\/wireless wifi | Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may | 61d ago |
| CVE-2026-20776 | 8.6 | — | — | — | intel / proset\/wireless wifi | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow | 61d ago |
| CVE-2026-20727 | 8.6 | — | — | — | intel / proset\/wireless wifi | Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may all | 61d ago |
| CVE-2026-20349zero day | 8.6 | 1.0% | 3/3 | same day | cisco / adaptive security appliance software | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) S | 61d ago |
| CVE-2026-72536 | 8.6 | — | — | — | — | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers t | 61d ago |
| CVE-2026-72535 | 8.6 | — | — | — | — | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers t | 61d ago |
| CVE-2026-72581 | 8.6 | — | — | — | — | A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote at | 62d ago |
| CVE-2026-64940 | 8.6 | — | — | — | — | Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regul | 62d ago |
| CVE-2026-19049 | 8.6 | — | — | — | — | The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL qu | 62d ago |
| CVE-2026-17044 | 8.6 | — | — | — | — | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before usi | 63d ago |
| CVE-2026-48120 | 8.6 | — | — | — | — | Kakoune is a code editor. | 64d ago |
| CVE-2026-63637 | 8.6 | — | — | — | — | Dgraph is an open source distributed GraphQL database. | 65d ago |
| CVE-2026-53983 | 8.6 | — | — | — | — | Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the o | 65d ago |
| CVE-2026-19143 | 8.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed | 65d ago |
| CVE-2026-3430 | 8.6 | — | — | — | — | The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an | 66d ago |
| CVE-2026-18953 | 8.6 | — | — | — | amazon / aws transform mcp server | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transfo | 67d ago |
| CVE-2026-20301 | 8.6 | — | — | — | — | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protoc | 67d ago |
| CVE-2026-20273 | 8.6 | — | — | — | cisco / ios xe | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee | 67d ago |
| CVE-2026-20271 | 8.6 | — | — | — | cisco / ios xe | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee | 67d ago |
| CVE-2026-20270 | 8.6 | — | — | — | cisco / ios xe | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee | 67d ago |
| CVE-2026-20269 | 8.6 | — | — | — | cisco / ios xe | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee | 67d ago |
| CVE-2026-20268 | 8.6 | — | — | — | cisco / ios xe | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee | 67d ago |
| CVE-2026-20263 | 8.6 | — | — | — | — | A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an | 67d ago |
| CVE-2026-71270 | 8.6 | — | — | — | — | Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtm | 67d ago |
| CVE-2026-71259 | 8.6 | — | — | — | — | ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validat | 67d ago |
| CVE-2026-71255 | 8.6 | — | — | — | — | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identificati | 67d ago |
| CVE-2026-68587 | 8.6 | — | — | — | — | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, | 69d ago |
| CVE-2026-68586 | 8.6 | — | — | — | — | SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content end | 69d ago |
| CVE-2026-68584 | 8.6 | — | — | — | — | SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returni | 69d ago |
| CVE-2026-16572 | 8.6 | — | — | — | — | The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using i | 69d ago |
| CVE-2026-12817 | 8.6 | — | — | — | bouncycastle / bc-java | In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. | 69d ago |
| CVE-2026-12185 | 8.6 | — | — | — | bouncycastle / bc-java | In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. | 69d ago |
| CVE-2025-71399 | 8.6 | — | — | — | — | Better Auth relies on better-call, which uses the rou3 router library. | 70d ago |
| CVE-2026-12721 | 8.6 | — | — | — | — | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request befo | 72d ago |
| CVE-2026-67346 | 8.6 | — | — | — | — | Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_saf | 73d ago |
| CVE-2026-54367 | 8.6 | — | — | — | — | CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to r | 73d ago |
| CVE-2026-22620 | 8.6 | — | — | — | — | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow a | 73d ago |
| CVE-2026-44098 | 8.6 | — | — | — | — | This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypas | 73d ago |
| CVE-2026-44094 | 8.6 | — | — | — | — | An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure co | 73d ago |
| CVE-2026-13395 | 8.6 | — | — | — | — | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly ca | 73d ago |
| CVE-2026-48448 | 8.6 | — | — | — | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command | 73d ago |
| CVE-2026-17699 | 8.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a | 73d ago |
| CVE-2026-67427 | 8.6 | — | — | — | — | Flyto2 Core is an execution kernel for automation and AI-agent workflows. | 74d ago |