| CVE-2026-44402 | 9.8 | — | — | — | — | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi | 1d ago |
| CVE-2026-18658 | 9.8 | — | — | — | — | IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerabl | 1d ago |
| CVE-2026-85696 | 9.8 | — | — | — | — | SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filename | 1d ago |
| CVE-2026-85688 | 9.8 | — | — | — | — | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer | 1d ago |
| CVE-2026-85672 | 9.8 | — | — | — | — | zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary fil | 1d ago |
| CVE-2026-85663 | 9.8 | — | — | — | — | Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr | 1d ago |
| CVE-2026-85661 | 9.8 | — | — | — | — | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing at | 1d ago |
| CVE-2026-82923 | 9.8 | — | — | — | — | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on | 1d ago |
| CVE-2026-70403 | 9.8 | — | — | — | — | XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). | 2d ago |
| CVE-2026-69657 | 9.8 | — | — | — | — | XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). | 2d ago |
| CVE-2026-62928 | 9.8 | — | — | — | — | XING CPTrans-ME-X contains an OS Command Injection (CWE-78). | 2d ago |
| CVE-2026-15354 | 9.8 | — | — | — | — | The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including | 2d ago |
| CVE-2026-85509 | 9.8 | — | — | — | — | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BM | 2d ago |
| CVE-2026-85508 | 9.8 | — | — | — | — | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in | 2d ago |
| CVE-2026-85507 | 9.8 | — | — | — | — | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi- | 2d ago |
| CVE-2026-85506 | 9.8 | — | — | — | — | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-o | 2d ago |
| CVE-2026-85504 | 9.8 | — | — | — | — | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfr | 2d ago |
| CVE-2026-11613 | 9.8 | — | — | — | — | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi | 2d ago |
| CVE-2026-85148 | 9.8 | — | — | — | — | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. | 2d ago |
| CVE-2026-85146 | 9.8 | — | — | — | — | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. | 2d ago |
| CVE-2026-85440 | 9.8 | — | — | — | — | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet hand | 2d ago |
| CVE-2026-85438 | 9.8 | — | — | — | — | MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, | 2d ago |
| CVE-2026-85437 | 9.8 | — | — | — | — | MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that tru | 2d ago |
| CVE-2026-85433 | 9.8 | — | — | — | — | MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher | 2d ago |
| CVE-2026-85428 | 9.8 | — | — | — | — | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server t | 2d ago |
| CVE-2026-85426 | 9.8 | — | — | — | — | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitiz | 2d ago |
| CVE-2026-85425 | 9.8 | — | — | — | — | MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that | 2d ago |
| CVE-2026-85424 | 9.8 | — | — | — | — | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to conne | 2d ago |
| CVE-2026-85391 | 9.8 | — | — | — | — | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated | 2d ago |
| CVE-2026-82526 | 9.8 | — | — | — | — | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute | 2d ago |
| CVE-2026-84834 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. | 2d ago |
| CVE-2026-84814 | 9.8 | — | — | — | — | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | 2d ago |
| CVE-2026-84753 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | 2d ago |
| CVE-2026-84238 | 9.8 | — | — | — | — | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | 2d ago |
| CVE-2026-85181 | 9.8 | — | — | — | — | CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing | 2d ago |
| CVE-2026-85109 | 9.8 | — | — | — | — | A vulnerability was determined in Tenda HG10 300001138. | 2d ago |
| CVE-2026-85154 | 9.8 | — | — | — | — | WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, | 2d ago |
| CVE-2026-19117 | 9.8 | — | — | — | — | Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target accou | 3d ago |
| CVE-2026-20279 | 9.8 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software enginee | 3d ago |
| CVE-2026-20274 | 9.8 | — | — | — | — | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software enginee | 3d ago |
| CVE-2026-20212 | 9.8 | — | — | — | — | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated | 3d ago |
| CVE-2026-53611 | 9.8 | — | — | — | — | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a | 3d ago |
| CVE-2025-9314 | 9.8 | — | — | — | — | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability | 3d ago |
| CVE-2026-84795 | 9.8 | — | — | — | — | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from de | 3d ago |
| CVE-2026-81294 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | 3d ago |
| CVE-2026-78657 | 9.8 | — | — | — | — | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insuf | 4d ago |
| CVE-2026-9055zero day | 9.8 | 0.29% | 1/3 | 1d before | — | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege | 4d ago |
| CVE-2026-84325 | 9.8 | — | — | — | google / chrome | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker levera | 4d ago |
| CVE-2026-84480 | 9.8 | — | — | — | — | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attacke | 4d ago |
| CVE-2026-84637 | 9.8 | — | — | — | mozilla / thunderbird | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Win | 4d ago |
| CVE-2026-84372 | 9.8 | — | — | — | — | Predis is a flexible and feature-complete Redis and Valkey client for PHP. | 4d ago |
| CVE-2023-54391zero day | 9.8 | 1.7% | 1/3 | same day | — | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access- | 4d ago |
| CVE-2026-73749 | 9.8 | — | — | — | hpe / arubaos-cx | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. | 4d ago |
| CVE-2026-52111 | 9.8 | — | — | — | — | An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configur | 4d ago |
| CVE-2026-19593 | 9.8 | — | — | — | — | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a use | 4d ago |
| CVE-2026-51934 | 9.8 | — | — | — | — | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. | 4d ago |
| CVE-2026-51770 | 9.8 | — | — | — | — | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe | 4d ago |
| CVE-2026-51769 | 9.8 | — | — | — | — | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauth | 4d ago |
| CVE-2026-51767 | 9.8 | — | — | — | — | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 4d ago |
| CVE-2026-78012 | 9.8 | — | — | — | — | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to | 4d ago |