| CVE-2026-60958 | 9.8 | — | — | — | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 18d ago |
| CVE-2026-60947 | 9.8 | — | — | — | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 18d ago |
| CVE-2026-60946 | 9.8 | — | — | — | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 18d ago |
| CVE-2026-60921 | 9.8 | — | — | — | oracle / webcenter enterprise capture | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bu | 18d ago |
| CVE-2026-60858 | 9.8 | — | — | — | oracle / hyperion calculation manager | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). | 18d ago |
| CVE-2026-60821 | 9.8 | — | — | — | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink | 18d ago |
| CVE-2026-60782 | 9.8 | — | — | — | oracle / payments | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). | 18d ago |
| CVE-2026-60727 | 9.8 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 18d ago |
| CVE-2026-60721 | 9.8 | — | — | — | oracle / identity manager | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). | 18d ago |
| CVE-2026-60698 | 9.8 | — | — | — | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | 18d ago |
| CVE-2026-60696 | 9.8 | — | — | — | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | 18d ago |
| CVE-2026-60672 | 9.8 | — | — | — | oracle / weblogic server | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). | 18d ago |
| CVE-2026-47627 | 9.8 | — | — | — | nvidia / triton inference server | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. | 18d ago |
| CVE-2026-52608 | 9.8 | — | — | — | — | An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject a | 18d ago |
| CVE-2021-43717 | 9.8 | — | — | — | — | An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. | 18d ago |
| CVE-2021-43716 | 9.8 | — | — | — | — | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. | 18d ago |
| CVE-2026-67271 | 9.8 | — | — | — | — | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. | 18d ago |
| CVE-2026-73373 | 9.8 | — | — | — | joomla / joomla\! | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default l | 18d ago |
| CVE-2026-45117 | 9.8 | — | — | — | — | MyBB is free and open source forum software. | 18d ago |
| CVE-2026-73996 | 9.8 | — | — | — | — | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | 18d ago |
| CVE-2026-73397 | 9.8 | — | — | — | — | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | 18d ago |
| CVE-2026-73380 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | 18d ago |
| CVE-2026-73376 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | 18d ago |
| CVE-2026-73366 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. | 18d ago |
| CVE-2026-73341 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | 18d ago |
| CVE-2026-59940 | 9.8 | — | — | — | — | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. | 18d ago |
| CVE-2026-32470 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | 18d ago |
| CVE-2026-74990 | 9.8 | — | — | — | mozilla / firefox | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74989 | 9.8 | — | — | — | mozilla / firefox | Internally found bugs present in Thunderbird 153. | 18d ago |
| CVE-2026-74988 | 9.8 | — | — | — | mozilla / firefox | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74987 | 9.8 | — | — | — | mozilla / firefox | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74985 | 9.8 | — | — | — | mozilla / firefox | Privilege escalation in the Enterprise Policies component. | 18d ago |
| CVE-2026-74979 | 9.8 | — | — | — | mozilla / firefox | Mitigation bypass in the Add-ons Manager component. | 18d ago |
| CVE-2026-74964 | 9.8 | — | — | — | mozilla / firefox | Integer overflow in the Graphics component. | 18d ago |
| CVE-2026-74944 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the DOM: Core & HTML component. | 18d ago |
| CVE-2026-74943 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the Graphics: ImageLib component. | 18d ago |
| CVE-2026-74940 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the Graphics: Text component. | 18d ago |
| CVE-2026-74936 | 9.8 | — | — | — | mozilla / firefox | Use-after-free in the JavaScript: WebAssembly component. | 18d ago |
| CVE-2026-75854 | 9.8 | — | — | — | — | ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin t | 18d ago |
| CVE-2026-75852 | 9.8 | — | — | — | — | ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol | 18d ago |
| CVE-2026-75627 | 9.8 | — | — | — | — | Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated att | 19d ago |
| CVE-2026-34884 | 9.8 | — | — | — | apache / skywalking mcp | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. | 19d ago |
| CVE-2026-15748 | 9.8 | — | — | — | — | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includ | 19d ago |
| CVE-2026-67919 | 9.8 | — | — | — | — | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFro | 19d ago |
| CVE-2026-42164 | 9.8 | — | — | — | — | Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in | 19d ago |
| CVE-2026-38165 | 9.8 | — | — | — | — | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport | 19d ago |
| CVE-2026-67960 | 9.8 | — | — | — | — | An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserContr | 19d ago |
| CVE-2026-67868 | 9.8 | — | — | — | — | A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during Cr | 19d ago |
| CVE-2026-67854 | 9.8 | — | — | — | — | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code | 19d ago |
| CVE-2026-42163 | 9.8 | — | — | — | — | Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Int | 19d ago |
| CVE-2026-75110 | 9.8 | — | — | — | — | MemOS is a memory operating system for LLMs and AI agents. | 19d ago |
| CVE-2026-67967 | 9.8 | — | — | — | — | Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. | 19d ago |
| CVE-2026-67966 | 9.8 | — | — | — | — | Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet | 19d ago |
| CVE-2026-67965 | 9.8 | — | — | — | — | An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login | 19d ago |
| CVE-2026-67926 | 9.8 | — | — | — | — | An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgB | 19d ago |
| CVE-2026-67917 | 9.8 | — | — | — | — | zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functiona | 19d ago |
| CVE-2026-47698 | 9.8 | — | — | — | — | vm2 is an open source vm/sandbox for Node.js. | 19d ago |
| CVE-2026-39255 | 9.8 | — | — | — | — | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary co | 19d ago |
| CVE-2026-39254 | 9.8 | — | — | — | — | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary co | 19d ago |
| CVE-2026-68004 | 9.8 | — | — | — | — | An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RT | 19d ago |