| CVE-2026-32566exploited | 9.8 | 0.45% | 1/3 | +1d | — | Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | 9d ago |
| CVE-2026-47892 | 9.8 | — | — | — | vmware / spring framework | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header | 10d ago |
| CVE-2026-47891 | 9.8 | — | — | — | vmware / spring framework | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce | 10d ago |
| CVE-2026-47890 | 9.8 | — | — | — | vmware / spring framework | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with v | 10d ago |
| CVE-2026-47884 | 9.8 | — | — | — | — | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapp | 10d ago |
| CVE-2026-75338 | 9.8 | — | — | — | — | disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. | 10d ago |
| CVE-2026-75336 | 9.8 | — | — | — | — | Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/u | 10d ago |
| CVE-2026-75330 | 9.8 | — | — | — | — | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vu | 10d ago |
| CVE-2026-75329 | 9.8 | — | — | — | — | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication me | 10d ago |
| CVE-2026-75414 | 9.8 | — | — | — | — | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, w | 10d ago |
| CVE-2026-75411 | 9.8 | — | — | — | — | JeecgBoot v3.9.2 is vulnerable to Remote command execution. | 10d ago |
| CVE-2026-52103 | 9.8 | — | — | — | — | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat | 10d ago |
| CVE-2026-75334 | 9.8 | — | — | — | — | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. | 10d ago |
| CVE-2026-75327 | 9.8 | — | — | — | — | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has | 10d ago |
| CVE-2026-68000 | 9.8 | — | — | — | — | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. | 10d ago |
| CVE-2026-60004zero day | 9.8 | 86.8% | 3/3 | 7d before | gitea / gitea | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | 10d ago |
| CVE-2026-26448 | 9.8 | — | — | — | — | Stomper 5e2741e is vulnerable to Use-After-Free. | 10d ago |
| CVE-2025-70293 | 9.8 | — | — | — | — | An issue was discovered in Denx U-Boot before 2026.04. | 10d ago |
| CVE-2025-70290 | 9.8 | — | — | — | — | An issue was discovered in Denx U-Boot before 2026.04. | 10d ago |
| CVE-2026-75325 | 9.8 | — | — | — | — | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' | 10d ago |
| CVE-2025-61165 | 9.8 | — | — | — | — | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows | 10d ago |
| CVE-2025-61163 | 9.8 | — | — | — | — | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains | 10d ago |
| CVE-2023-42179 | 9.8 | — | — | — | — | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process | 10d ago |
| CVE-2026-81032 | 9.8 | — | — | — | — | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. | 10d ago |
| CVE-2026-80428 | 9.8 | — | — | — | — | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that al | 10d ago |
| CVE-2026-54569 | 9.8 | — | — | — | — | SENAITE.CORE is the core framework for the SENAITE laboratory information management system. | 10d ago |
| CVE-2026-80589 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a | 10d ago |
| CVE-2026-80587 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboption | 10d ago |
| CVE-2026-80586 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of un | 10d ago |
| CVE-2026-80561 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode | 10d ago |
| CVE-2026-80558 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from | 10d ago |
| CVE-2026-80557 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via | 10d ago |
| CVE-2026-80528 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->jo | 10d ago |
| CVE-2026-80519 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before pe | 10d ago |
| CVE-2026-74752 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use Wh | 10d ago |
| CVE-2026-74746 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple | 10d ago |
| CVE-2026-74744 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tai | 10d ago |
| CVE-2026-74743 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_ta | 10d ago |
| CVE-2026-74737 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id | 10d ago |
| CVE-2026-80203 | 9.8 | — | — | — | — | The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() fun | 10d ago |
| CVE-2026-77557 | 9.8 | — | — | — | — | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi | 10d ago |
| CVE-2026-77552 | 9.8 | — | — | — | — | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni | 10d ago |
| CVE-2026-18080 | 9.8 | — | — | — | — | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestric | 10d ago |
| CVE-2026-80349 | 9.8 | — | — | — | — | TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. | 10d ago |
| CVE-2026-59683 | 9.8 | — | — | — | — | The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extensi | 10d ago |
| CVE-2026-80235 | 9.8 | — | — | — | — | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. | 11d ago |
| CVE-2026-18431 | 9.8 | — | — | — | — | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 whe | 11d ago |
| CVE-2026-19632zero day | 9.8 | 0.79% | 1/3 | 1d before | — | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensit | 11d ago |
| CVE-2026-80138 | 9.8 | — | — | — | — | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing i | 11d ago |
| CVE-2026-16641 | 9.8 | — | — | — | — | Vulnerability in Drupal Commerce Elavon. | 11d ago |
| CVE-2026-16639 | 9.8 | — | — | — | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign- | 11d ago |
| CVE-2026-78619 | 9.8 | — | — | — | — | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challeng | 11d ago |
| CVE-2026-65905 | 9.8 | — | — | — | apache / tomcat | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. | 11d ago |
| CVE-2026-65637 | 9.8 | — | — | — | apache / tomcat | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. | 11d ago |
| CVE-2026-80104 | 9.8 | — | — | — | — | DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to th | 11d ago |
| CVE-2026-79152 | 9.8 | — | — | — | google / chrome | Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attack | 11d ago |
| CVE-2026-79090 | 9.8 | — | — | — | google / chrome | Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragin | 11d ago |
| CVE-2026-51368 | 9.8 | — | — | — | — | An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a | 11d ago |
| CVE-2026-45018 | 9.8 | — | — | — | — | Chainlit is a Python framework for building production-ready conversational AI applications. | 11d ago |
| CVE-2026-79787 | 9.8 | — | — | — | — | Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing | 11d ago |