| CVE-2026-19912 | 9.8 | — | — | — | — | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caus | 11d ago |
| CVE-2026-79675 | 9.8 | — | — | — | nltk / nltk | NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() funct | 11d ago |
| CVE-2026-55546 | 9.8 | — | — | — | — | QWED-MCP is a deterministic verification gateway for MCP. | 11d ago |
| CVE-2022-51000 | 9.8 | — | — | — | nokogiri / nokogiri | Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, wh | 11d ago |
| CVE-2026-16286 | 9.8 | — | — | — | — | Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Ha | 11d ago |
| CVE-2026-63073 | 9.8 | — | — | — | — | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as | 11d ago |
| CVE-2026-79657 | 9.8 | — | — | — | nltk / nltk | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust | 11d ago |
| CVE-2026-49845 | 9.8 | — | — | — | apache / hive | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms | 11d ago |
| CVE-2026-63586 | 9.8 | — | — | — | — | The web-based management interface uses a modified uhttpd server with CGI shell scripts. | 12d ago |
| CVE-2026-13214 | 9.8 | — | — | — | — | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). | 12d ago |
| CVE-2026-78676 | 9.8 | — | — | — | gitpython project / gitpython | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupt | 12d ago |
| CVE-2026-56710 | 9.8 | — | — | — | — | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserLis | 12d ago |
| CVE-2026-56705 | 9.8 | — | — | — | — | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthentic | 12d ago |
| CVE-2026-78267 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | 12d ago |
| CVE-2026-78265 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | 12d ago |
| CVE-2026-78262 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | 12d ago |
| CVE-2026-32563 | 9.8 | — | — | — | — | Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | 12d ago |
| CVE-2026-52490 | 9.8 | — | — | — | — | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the | 12d ago |
| CVE-2026-71921 | 9.8 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi | 12d ago |
| CVE-2026-71914 | 9.8 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. | 12d ago |
| CVE-2026-78329 | 9.8 | — | — | — | apache / camel | Improper input validation vulnerability in Apache Camel Undertow component. | 12d ago |
| CVE-2026-77915 | 9.8 | — | — | — | — | rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attac | 12d ago |
| CVE-2026-71300 | 9.8 | — | — | — | apache / camel | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. | 12d ago |
| CVE-2026-76071 | 9.8 | — | — | — | — | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthent | 12d ago |
| CVE-2026-76070 | 9.8 | — | — | — | — | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthent | 12d ago |
| CVE-2026-66650 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions. | 12d ago |
| CVE-2026-66648 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. | 12d ago |
| CVE-2026-66587 | 9.8 | — | — | — | — | Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. | 12d ago |
| CVE-2026-32558zero day | 9.8 | 0.27% | 1/3 | same day | — | Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 ver | 12d ago |
| CVE-2026-28165 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Digits <= 9.2 versions. | 12d ago |
| CVE-2026-78211 | 9.8 | — | — | — | — | 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. | 13d ago |
| CVE-2026-78168 | 9.8 | — | — | — | — | A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. | 13d ago |
| CVE-2026-78183 | 9.8 | — | — | — | — | DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. | 13d ago |
| CVE-2026-8445 | 9.8 | — | — | — | — | justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle bracket | 13d ago |
| CVE-2026-7808 | 9.8 | — | — | — | — | justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e | 13d ago |
| CVE-2026-5388 | 9.8 | — | — | — | — | justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_ | 13d ago |
| CVE-2026-13598 | 9.8 | — | — | — | — | The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registratio | 14d ago |
| CVE-2026-74730 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE | 14d ago |
| CVE-2026-74727 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed fr | 14d ago |
| CVE-2026-74723 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without vali | 14d ago |
| CVE-2026-74688 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is b | 14d ago |
| CVE-2026-74669 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel | 14d ago |
| CVE-2026-74662 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming time | 14d ago |
| CVE-2026-74628 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by i | 14d ago |
| CVE-2026-74617 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dibs: initialise dibs->lock in dibs_dev_alloc( | 14d ago |
| CVE-2026-74616 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones that overrun skb_shared_inf | 14d ago |
| CVE-2026-74611 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optim | 14d ago |
| CVE-2026-74608 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_try_ad | 14d ago |
| CVE-2026-74597 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() i | 14d ago |
| CVE-2026-74591 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore inde | 14d ago |
| CVE-2026-74588 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the l | 14d ago |
| CVE-2026-74587 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chun | 14d ago |
| CVE-2026-74586 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer | 14d ago |
| CVE-2026-4703 | 9.8 | — | — | — | — | The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in a | 14d ago |
| CVE-2026-78003exploited | 9.8 | 0.87% | 1/3 | +6d | — | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traver | 15d ago |
| CVE-2026-77002 | 9.8 | — | — | — | — | The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the ide | 15d ago |
| CVE-2026-77001 | 9.8 | — | — | — | — | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any | 15d ago |
| CVE-2026-77000 | 9.8 | — | — | — | — | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually complete | 15d ago |
| CVE-2026-76904zero day | 9.8 | 1.8% | 1/3 | same day | — | GeoTools is an open source Java library that provides tools for geospatial data. | 15d ago |
| CVE-2026-74581 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result f | 15d ago |