| CVE-2026-67425 | 8.6 | — | — | — | — | Flyto2 Core is an execution kernel for automation and AI-agent workflows. | 74d ago |
| CVE-2026-67201 | 8.6 | — | — | — | — | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that | 74d ago |
| CVE-2026-16328 | 8.6 | — | — | — | — | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, all | 74d ago |
| CVE-2026-56389 | 8.6 | — | — | — | gnu / bison | GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling o | 74d ago |
| CVE-2026-58182 | 8.6 | — | — | — | apache / traffic server | The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. | 74d ago |
| CVE-2026-11974 | 8.6 | — | — | — | — | The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using i | 74d ago |
| CVE-2026-54650 | 8.6 | — | — | — | — | openhole exposes localhost to the internet in one command. | 74d ago |
| CVE-2026-48396 | 8.6 | — | — | — | adobe / bridge | Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in th | 75d ago |
| CVE-2026-48395 | 8.6 | — | — | — | adobe / bridge | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the | 75d ago |
| CVE-2026-14869 | 8.6 | — | — | — | — | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamab | 75d ago |
| CVE-2026-48388 | 8.6 | — | — | — | adobe / photoshop installer | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have result | 75d ago |
| CVE-2026-54609 | 8.6 | — | — | — | — | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. | 75d ago |
| CVE-2026-54603 | 8.6 | — | — | — | — | OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). | 75d ago |
| CVE-2026-45293 | 8.6 | — | — | — | — | WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. | 75d ago |
| CVE-2026-43760 | 8.6 | — | — | — | apple / macos | An access issue was addressed with improved access restrictions. | 75d ago |
| CVE-2026-28973 | 8.6 | — | — | — | apple / ipados | An integer overflow was addressed with improved input validation. | 75d ago |
| CVE-2025-15662 | 8.6 | — | — | — | — | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user | 76d ago |
| CVE-2026-64400 | 8.6 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restri | 78d ago |
| CVE-2026-28698 | 8.6 | — | — | — | — | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized | 79d ago |
| CVE-2026-65702 | 8.6 | — | — | — | — | Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integra | 80d ago |
| CVE-2026-65908 | 8.6 | — | — | — | jetbrains / pycharm | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible | 80d ago |
| CVE-2026-64814 | 8.6 | — | — | — | jetbrains / intellij idea | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | 80d ago |
| CVE-2026-13321 | 8.6 | — | — | — | — | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer | 81d ago |
| CVE-2026-65318 | 8.6 | — | — | — | — | Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that all | 81d ago |
| CVE-2026-65317 | 8.6 | — | — | — | — | Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-orig | 81d ago |
| CVE-2026-60671 | 8.6 | — | — | — | oracle / business intelligence | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Pl | 81d ago |
| CVE-2026-60559 | 8.6 | — | — | — | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | 81d ago |
| CVE-2026-60556 | 8.6 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 81d ago |
| CVE-2026-60550 | 8.6 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 81d ago |
| CVE-2026-60536 | 8.6 | — | — | — | oracle / identity manager connector | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft | 81d ago |
| CVE-2026-60431 | 8.6 | — | — | — | oracle / http server | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). | 81d ago |
| CVE-2026-60359 | 8.6 | — | — | — | oracle / unified directory | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). | 81d ago |
| CVE-2026-60356 | 8.6 | — | — | — | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | 81d ago |
| CVE-2026-60327 | 8.6 | — | — | — | oracle / access manager | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). | 81d ago |
| CVE-2026-60293 | 8.6 | — | — | — | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services). | 81d ago |
| CVE-2026-60235 | 8.6 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 81d ago |
| CVE-2026-63764 | 8.6 | — | — | — | internlm / lmdeploy | LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in t | 81d ago |
| CVE-2026-53591 | 8.6 | — | — | — | — | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. | 83d ago |
| CVE-2026-63429 | 8.6 | — | — | — | — | HeyForm is an open-source form builder. | 83d ago |
| CVE-2026-64623 | 8.6 | — | — | — | — | Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter whe | 83d ago |
| CVE-2026-11349 | 8.6 | — | — | — | — | The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before | 83d ago |
| CVE-2026-53727 | 8.6 | — | — | — | premailer / css parser | css_parser is a Ruby CSS parser. | 85d ago |
| CVE-2026-44023 | 8.6 | — | — | — | docling / docling-core | Docling Core defines core data types and transformations for the document processing application Docling. | 86d ago |
| CVE-2026-63088 | 8.6 | — | — | — | — | stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated ne | 87d ago |
| CVE-2026-63086 | 8.6 | — | — | — | — | text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI- | 87d ago |
| CVE-2026-57206 | 8.6 | — | — | — | — | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded intera | 87d ago |
| CVE-2026-63306 | 8.6 | — | — | — | — | stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /e | 87d ago |
| CVE-2026-48795 | 8.6 | — | — | — | — | AdonisJS is a TypeScript-first web framework. | 87d ago |
| CVE-2026-61836 | 8.6 | — | — | — | monospace / directus | Directus is a real-time API and App dashboard for managing SQL database content. | 88d ago |
| CVE-2026-61436 | 8.6 | — | — | — | — | PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticate | 88d ago |
| CVE-2026-15583 | 8.6 | — | — | — | — | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's | 88d ago |
| CVE-2026-12512 | 8.6 | — | — | — | — | The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter bef | 88d ago |
| CVE-2026-48275 | 8.6 | — | — | — | adobe / illustrator | Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in | 88d ago |
| CVE-2026-48736 | 8.6 | — | — | — | sensiolabs / symfony | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 89d ago |
| CVE-2026-48350 | 8.6 | — | — | — | adobe / animate | Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabi | 89d ago |
| CVE-2026-48310 | 8.6 | — | — | — | adobe / experience manager | Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav | 89d ago |
| CVE-2026-48252 | 8.6 | — | — | — | adobe / experience manager | Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could re | 89d ago |
| CVE-2026-47988 | 8.6 | — | — | — | adobe / commerce | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature byp | 89d ago |
| CVE-2026-15720 | 8.6 | — | — | — | — | In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity h | 89d ago |
| CVE-2026-45077 | 8.6 | — | — | — | sensiolabs / symfony | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 89d ago |