| CVE-2026-72407 | 10 | critical | — | In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in genev | 21d ago |
| CVE-2026-73678 | 10 | critical | — | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability | 22d ago |
| CVE-2026-19188 | 10 | critical | — | A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. | 22d ago |
| CVE-2026-72811 | 10 | critical | — | SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model | 22d ago |
| CVE-2026-72851 | 10 | critical | — | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations wi | 23d ago |
| CVE-2026-61962 | 10 | critical | — | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | 23d ago |
| CVE-2026-27544 | 10 | critical | — | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | 23d ago |
| CVE-2026-59500 | 10 | critical | — | : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solu | 23d ago |
| CVE-2026-15413 | 10 | critical | — | The Link Factory WordPress plugin is a backdoor. | 23d ago |
| CVE-2024-27253 | 10 | critical | — | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to p | 24d ago |
| CVE-2026-73299 | 10 | critical | — | Prompty is a markdown file format (.prompty) for LLM prompts. | 24d ago |
| CVE-2026-45618 | 10 | critical | — | LiquidJS is a Shopify/GitHub Pages compatible template engine. | 25d ago |
| CVE-2026-71398 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar | 25d ago |
| CVE-2026-27302 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar | 25d ago |
| CVE-2026-48362 | 10 | critical | adobe / coldfusion | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inject | 25d ago |
| CVE-2026-17061 | 10 | critical | — | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Rel | 25d ago |
| CVE-2026-48056 | 10 | critical | — | Streambert is a cross-platform Electron Desktop App to stream and download video content. | 25d ago |
| CVE-2026-58115 | 10 | critical | — | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 runn | 25d ago |
| CVE-2026-58231 | 10 | critical | — | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit speciall | 25d ago |
| CVE-2026-72899 | 10 | critical | — | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that e | 26d ago |
| CVE-2026-72898exploited | 10 | critical | metabase / metabase | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endp | 26d ago |
| CVE-2026-65667 | 10 | critical | microsoft / teams | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-63508 | 10 | critical | microsoft / planetary computer | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker t | 30d ago |
| CVE-2026-56162 | 10 | critical | microsoft / azure sql database | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network | 30d ago |
| CVE-2026-14812 | 10 | critical | — | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administ | 30d ago |
| CVE-2026-11976 | 10 | critical | — | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. | 30d ago |
| CVE-2026-66665 | 10 | critical | — | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | 30d ago |
| CVE-2026-65553 | 10 | critical | — | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | 30d ago |
| CVE-2026-5430 | 10 | critical | wso2 / api control plane | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or su | 30d ago |
| CVE-2026-48168 | 10 | critical | — | PraisonAI is a multi-agent teams system. | 31d ago |
| CVE-2026-16940 | 10 | critical | — | The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allow | 31d ago |
| CVE-2026-48331 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i | 33d ago |
| CVE-2026-48330 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command | 33d ago |
| CVE-2026-48323 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engi | 33d ago |
| CVE-2026-69085 | 10 | critical | — | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the ca | 33d ago |
| CVE-2026-69084 | 10 | critical | — | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL sta | 33d ago |
| CVE-2026-69083 | 10 | critical | — | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint rea | 33d ago |
| CVE-2026-18452 | 10 | critical | — | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. | 36d ago |
| CVE-2026-66803 | 10 | critical | microsoft / azure cosmos db | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | 37d ago |
| CVE-2026-48449 | 10 | critical | adobe / campaign | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrar | 38d ago |
| CVE-2026-67429 | 10 | critical | — | Flyto2 Core is an execution kernel for automation and AI-agent workflows. | 38d ago |
| CVE-2026-16326 | 10 | critical | — | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which m | 38d ago |
| CVE-2026-54735 | 10 | critical | prebid / prebid server | Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. | 38d ago |
| CVE-2026-58162 | 10 | critical | apache / traffic server | The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. | 38d ago |
| CVE-2026-58150 | 10 | critical | apache / traffic server | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. | 38d ago |
| CVE-2026-57834 | 10 | critical | apache / traffic server | Apache Traffic Server allows request smuggling if chunked messages are malformed. | 38d ago |
| CVE-2026-33267 | 10 | critical | apache / traffic server | Improper Input Validation vulnerability in Apache Traffic Server. | 38d ago |
| CVE-2026-16498 | 10 | critical | — | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the stream | 39d ago |
| CVE-2026-11756 | 10 | critical | — | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Rel | 39d ago |
| CVE-2026-16812exploited | 10 | critical | arista / velocloud orchestrator | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access p | 40d ago |
| CVE-2026-66012 | 10 | critical | — | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gat | 42d ago |
| CVE-2026-58630 | 10 | critical | microsoft / azure app service for linux | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | 43d ago |
| CVE-2026-57106 | 10 | critical | microsoft / purview data governance | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a ne | 43d ago |
| CVE-2026-56163 | 10 | critical | microsoft / azure kubernetes service | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker | 43d ago |
| CVE-2026-62825 | 10 | critical | microsoft / azure key vault | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | 44d ago |
| CVE-2026-58275 | 10 | critical | microsoft / azure dns | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | 44d ago |
| CVE-2026-56191 | 10 | critical | microsoft / exchange online | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a n | 44d ago |
| CVE-2026-42933 | 10 | critical | — | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could | 44d ago |
| CVE-2025-71389 | 10 | critical | — | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a | 44d ago |
| CVE-2026-6516 | 10 | critical | — | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due t | 44d ago |