| CVE-2026-67678 | 9.8 | — | — | — | — | File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code | 19d ago |
| CVE-2026-50775 | 9.8 | — | — | — | — | A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retriev | 19d ago |
| CVE-2026-50774 | 9.8 | — | — | — | — | An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. | 19d ago |
| CVE-2026-50772 | 9.8 | — | — | — | — | An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted pay | 19d ago |
| CVE-2026-50770 | 9.8 | — | — | — | — | An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted | 19d ago |
| CVE-2026-50769 | 9.8 | — | — | — | — | The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-b | 19d ago |
| CVE-2026-74901 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decry | 20d ago |
| CVE-2026-74900 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures | 20d ago |
| CVE-2026-74899 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that expose | 20d ago |
| CVE-2026-74896 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST an | 20d ago |
| CVE-2026-74895 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for | 20d ago |
| CVE-2026-74894 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that | 20d ago |
| CVE-2026-74891 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration fi | 20d ago |
| CVE-2026-74889 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functio | 20d ago |
| CVE-2026-74886 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard bl | 20d ago |
| CVE-2026-74880 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry ser | 20d ago |
| CVE-2026-74878 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not sh | 20d ago |
| CVE-2026-74876 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bund | 20d ago |
| CVE-2026-74875 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not inst | 20d ago |
| CVE-2026-74872 | 9.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash impl | 20d ago |
| CVE-2026-73061 | 9.8 | — | — | — | — | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template | 20d ago |
| CVE-2026-73056 | 9.8 | — | — | — | — | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerabi | 20d ago |
| CVE-2026-72887 | 9.8 | — | — | — | — | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OA | 20d ago |
| CVE-2026-19349 | 9.8 | — | — | — | — | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for | 20d ago |
| CVE-2024-13784 | 9.8 | — | — | — | — | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Inj | 21d ago |
| CVE-2026-18432 | 9.8 | — | — | — | — | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, | 21d ago |
| CVE-2026-16098 | 9.8 | — | — | — | — | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i | 21d ago |
| CVE-2026-19924 | 9.8 | — | — | — | — | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. | 21d ago |
| CVE-2026-73046 | 9.8 | — | — | — | — | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. | 21d ago |
| CVE-2026-19598zero day | 9.8 | 2.8% | 1/3 | same day | — | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authoriz | 21d ago |
| CVE-2026-15689 | 9.8 | — | — | — | — | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the requ | 21d ago |
| CVE-2026-74570 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc size calculations | 21d ago |
| CVE-2026-74569 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite | 21d ago |
| CVE-2026-74556 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data s | 21d ago |
| CVE-2026-74545 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: rtase: fix double free of multi-frag skb on DM | 21d ago |
| CVE-2026-74495 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: igbvf: Fix leak in TX DMA error cleanup If an | 21d ago |
| CVE-2026-74493 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-free during link | 21d ago |
| CVE-2026-74480 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a | 21d ago |
| CVE-2026-74478 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free in vector_mmsg_ | 21d ago |
| CVE-2026-74474 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmi | 21d ago |
| CVE-2026-74473 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() in route_sh | 21d ago |
| CVE-2026-73193 | 9.8 | — | — | — | — | DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in th | 21d ago |
| CVE-2026-16142 | 9.8 | — | — | — | — | The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. | 22d ago |
| CVE-2026-15826zero day | 9.8 | 3.9% | 1/3 | same day | — | The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in version | 22d ago |
| CVE-2026-74436 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation w | 22d ago |
| CVE-2026-74434 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB message onto th | 22d ago |
| CVE-2026-74433 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix UAF in rxgk_issue_challenge() Fix r | 22d ago |
| CVE-2026-74428 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix double unlock in rxrpc_recvmsg() Fi | 22d ago |
| CVE-2026-74427 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: afs: Fix netns teardown to cancel the prealloc | 22d ago |
| CVE-2026-74406 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_g | 22d ago |
| CVE-2026-74401 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg handle in send_queue ordered | 22d ago |
| CVE-2026-74398 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_failure when s | 22d ago |
| CVE-2026-74394 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow in immediate d | 22d ago |
| CVE-2026-74384 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix flex array size in struct | 22d ago |
| CVE-2026-74376 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: md/raid10: reset read_slot when reusing r10bio | 22d ago |
| CVE-2026-74361 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: nvme: fix FDP fdpcidx bounds check The fdpcidx | 22d ago |
| CVE-2026-74350 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink target during ino | 22d ago |
| CVE-2026-74345 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix endpoint/socket association hand | 22d ago |
| CVE-2026-74315 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: lockd: Avoid hashing uninitialized bytes in nl | 22d ago |
| CVE-2026-74269 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP head-grow The | 22d ago |