| CVE-2026-77806zero day | 9.8 | 4.2% | 1/3 | same day | — | SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in | 15d ago |
| CVE-2026-77264 | 9.8 | — | — | — | — | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is | 16d ago |
| CVE-2026-77651 | 9.8 | — | — | — | — | The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the | 16d ago |
| CVE-2026-77650 | 9.8 | — | — | — | — | The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that use | 16d ago |
| CVE-2026-77649 | 9.8 | — | — | — | — | The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the | 16d ago |
| CVE-2026-77647zero day | 9.8 | 2.6% | 1/3 | same day | — | SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in | 16d ago |
| CVE-2026-72843 | 9.8 | — | — | — | — | The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/custome | 16d ago |
| CVE-2026-17160 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an in | 16d ago |
| CVE-2026-17157 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 16d ago |
| CVE-2026-17152 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf | 16d ago |
| CVE-2026-17145 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to impro | 16d ago |
| CVE-2026-17142 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i | 16d ago |
| CVE-2026-17141 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf | 16d ago |
| CVE-2026-17136 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a for | 16d ago |
| CVE-2026-17122 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 16d ago |
| CVE-2026-17118 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use | 16d ago |
| CVE-2026-17040 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf | 16d ago |
| CVE-2026-43798 | 9.8 | — | — | — | apple / swiftnio ssh | A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-co | 16d ago |
| CVE-2026-19586 | 9.8 | — | — | — | tp-link / er7212pc firmware | A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operat | 16d ago |
| CVE-2026-55642 | 9.8 | — | — | — | — | dbx is a cross-platform database client for databases. | 16d ago |
| CVE-2026-18265 | 9.8 | — | — | — | — | OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. | 16d ago |
| CVE-2026-63039 | 9.8 | — | — | — | apache / inlong | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLon | 16d ago |
| CVE-2026-63038 | 9.8 | — | — | — | apache / inlong | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLon | 16d ago |
| CVE-2026-63037 | 9.8 | — | — | — | apache / inlong | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLon | 16d ago |
| CVE-2026-15706 | 9.8 | — | — | — | — | Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. | 16d ago |
| CVE-2026-18482 | 9.8 | — | — | — | — | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server | 16d ago |
| CVE-2026-77071 | 9.8 | — | — | — | n8n / n8n | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's | 16d ago |
| CVE-2026-77070 | 9.8 | — | — | — | n8n / n8n | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delet | 16d ago |
| CVE-2026-74001 | 9.8 | — | — | — | — | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | 16d ago |
| CVE-2026-73993 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | 16d ago |
| CVE-2026-66682 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | 16d ago |
| CVE-2026-66672 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | 16d ago |
| CVE-2026-66583 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | 16d ago |
| CVE-2025-15689 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | 16d ago |
| CVE-2026-14950 | 9.8 | — | — | — | — | An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the sessi | 17d ago |
| CVE-2026-75860 | 9.8 | — | — | — | — | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of | 17d ago |
| CVE-2026-76850 | 9.8 | — | — | — | — | LMDeploy deserializes disaggregated-serving peer messages with pickle. | 17d ago |
| CVE-2026-53545 | 9.8 | — | — | — | — | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. | 17d ago |
| CVE-2026-63722 | 9.8 | — | — | — | — | ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers | 17d ago |
| CVE-2026-19508 | 9.8 | — | — | — | — | Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone | 17d ago |
| CVE-2026-19505 | 9.8 | — | — | — | — | Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` | 17d ago |
| CVE-2026-16919 | 9.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to impro | 17d ago |
| CVE-2026-16917 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an in | 17d ago |
| CVE-2026-16913 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16894 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16885 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16882 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i | 17d ago |
| CVE-2026-16872 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16864 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16862 | 9.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16845 | 9.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a hea | 17d ago |
| CVE-2026-16840 | 9.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an ou | 17d ago |
| CVE-2026-16834 | 9.8 | — | — | — | ibm / aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an | 17d ago |
| CVE-2026-18315 | 9.8 | — | — | — | — | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypa | 17d ago |
| CVE-2026-75143 | 9.8 | — | — | — | — | FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). | 17d ago |
| CVE-2026-72529zero day | 9.8 | 1.6% | 3/3 | 7d before | trueconf / trueconf server | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3. | 17d ago |
| CVE-2026-53451 | 9.8 | — | — | — | — | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry dec | 17d ago |
| CVE-2026-52889 | 9.8 | — | — | — | — | Formie is a Craft CMS plugin for creating forms. | 17d ago |
| CVE-2026-16656 | 9.8 | — | — | — | ibm / vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to imprope | 17d ago |
| CVE-2026-16019 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innov | 17d ago |