| CVE-2026-82452 | 9.8 | — | — | — | — | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API rout | 7d ago |
| CVE-2026-82448 | 9.8 | — | — | — | — | Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthent | 7d ago |
| CVE-2026-14494 | 9.8 | — | — | — | — | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi | 7d ago |
| CVE-2026-80725 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregatio | 8d ago |
| CVE-2026-16259 | 9.8 | — | — | — | — | The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unaut | 8d ago |
| CVE-2026-10522 | 9.8 | — | — | — | — | The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its fron | 8d ago |
| CVE-2026-51663 | 9.8 | — | — | — | — | Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 8d ago |
| CVE-2026-19286 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enfo | 8d ago |
| CVE-2026-82329zero day | 9.8 | 7.7% | 3/3 | same day | jfrog / artifactory | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthentica | 8d ago |
| CVE-2026-82277 | 9.8 | — | — | — | — | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without aut | 8d ago |
| CVE-2026-82266 | 9.8 | — | — | — | — | Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treat | 8d ago |
| CVE-2026-55559 | 9.8 | — | — | — | — | Yamcs is a mission control framework. | 8d ago |
| CVE-2026-51645 | 9.8 | — | — | — | — | Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate | 8d ago |
| CVE-2026-51611 | 9.8 | — | — | — | — | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica | 8d ago |
| CVE-2026-81578zero day | 9.8 | 1.6% | 3/3 | 1d before | papercut / papercut mf | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. | 8d ago |
| CVE-2026-37751 | 9.8 | — | — | — | — | An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-mae | 8d ago |
| CVE-2026-37236 | 9.8 | — | — | — | — | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. | 8d ago |
| CVE-2026-80714 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to sync | 9d ago |
| CVE-2026-80694 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_ha | 9d ago |
| CVE-2026-80681 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortci | 9d ago |
| CVE-2026-80674 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and ha | 9d ago |
| CVE-2026-80673 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entr | 9d ago |
| CVE-2026-80668 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack | 9d ago |
| CVE-2026-80634 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underfl | 9d ago |
| CVE-2026-80630 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tre | 9d ago |
| CVE-2026-80617 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation siz | 9d ago |
| CVE-2026-80612 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT en | 9d ago |
| CVE-2026-80609 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_lis | 9d ago |
| CVE-2026-80600 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only af | 9d ago |
| CVE-2026-78032 | 9.8 | — | — | — | — | SOY CMS contains an issue with deserialization of untrusted data. | 9d ago |
| CVE-2026-76581zero day | 9.8 | 0.34% | 1/3 | 1d before | — | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl | 9d ago |
| CVE-2026-82082 | 9.8 | — | — | — | — | NUMail developed by Green-Computing has an OS Command Injection vulnerability. | 9d ago |
| CVE-2026-78239 | 9.8 | — | — | — | — | Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remo | 9d ago |
| CVE-2026-76943 | 9.8 | — | — | — | — | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker t | 9d ago |
| CVE-2026-76179 | 9.8 | — | — | — | — | An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. | 9d ago |
| CVE-2026-75337 | 9.8 | — | — | — | — | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. | 9d ago |
| CVE-2026-73125 | 9.8 | — | — | — | — | Ebyte device web management interface does not consistently enforce authentication before granting access to admin | 9d ago |
| CVE-2026-71187 | 9.8 | — | — | — | — | The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. | 9d ago |
| CVE-2026-69658 | 9.8 | — | — | — | — | MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level | 9d ago |
| CVE-2026-59313 | 9.8 | — | — | — | vmware / spring framework | Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-S | 9d ago |
| CVE-2026-37072 | 9.8 | — | — | — | — | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head- | 9d ago |
| CVE-2026-37071 | 9.8 | — | — | — | — | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Proje | 9d ago |
| CVE-2026-37007 | 9.8 | — | — | — | — | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution | 9d ago |
| CVE-2026-37006 | 9.8 | — | — | — | — | A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote at | 9d ago |
| CVE-2026-37004 | 9.8 | — | — | — | — | BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remo | 9d ago |
| CVE-2026-37003 | 9.8 | — | — | — | — | Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. | 9d ago |
| CVE-2026-35869 | 9.8 | — | — | — | — | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB- | 9d ago |
| CVE-2026-35868 | 9.8 | — | — | — | — | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB- | 9d ago |
| CVE-2026-30612 | 9.8 | — | — | — | — | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Andr | 9d ago |
| CVE-2026-19092 | 9.8 | — | — | — | — | The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables whil | 9d ago |
| CVE-2026-81707 | 9.8 | — | — | — | — | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers | 9d ago |
| CVE-2026-81702 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.js | 9d ago |
| CVE-2026-81701 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugi | 9d ago |
| CVE-2026-81700 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached | 9d ago |
| CVE-2026-75357 | 9.8 | — | — | — | — | An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js an | 9d ago |
| CVE-2026-26897 | 9.8 | — | — | — | — | An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to o | 9d ago |
| CVE-2026-74233zero day | 9.8 | 2.6% | 2/3 | same day | — | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink | 9d ago |
| CVE-2026-74232zero day | 9.8 | 0.47% | 2/3 | same day | — | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zb | 9d ago |
| CVE-2026-78292 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. | 9d ago |
| CVE-2026-78286 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | 9d ago |