| CVE-2026-72064 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX frags for CPU MAN | 22d ago |
| CVE-2026-72046 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruption with header- | 22d ago |
| CVE-2026-72041 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix parti | 22d ago |
| CVE-2026-72033 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry size 64-bit i | 22d ago |
| CVE-2026-72020 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq structs in ip_vs_co | 22d ago |
| CVE-2026-72014 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with an out-of-range | 22d ago |
| CVE-2026-68477 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong ipv6 transpor | 22d ago |
| CVE-2026-68476 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation | 22d ago |
| CVE-2026-15341 | 9.8 | — | — | — | — | The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeo | 22d ago |
| CVE-2026-15303 | 9.8 | — | — | — | — | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, | 22d ago |
| CVE-2026-17184 | 9.8 | — | — | — | ibm / db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external con | 22d ago |
| CVE-2026-17182 | 9.8 | — | — | — | ibm / db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter | 22d ago |
| CVE-2026-50027 | 9.8 | — | — | — | — | mcp-memory-service is a semantic memory layer for AI applications. | 22d ago |
| CVE-2026-73849 | 9.8 | — | — | — | — | Emlog is an open source website building system. | 22d ago |
| CVE-2026-48528 | 9.8 | — | — | — | — | Metacat is data repository software that helps researchers preserve, share, and discover data. | 22d ago |
| CVE-2026-12949 | 9.8 | — | — | — | — | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data A | 23d ago |
| CVE-2026-72839 | 9.8 | — | — | — | — | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with defa | 23d ago |
| CVE-2026-72776 | 9.8 | — | — | — | — | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any netwo | 23d ago |
| CVE-2026-17482 | 9.8 | — | — | — | ibm / documentation offline | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to impro | 23d ago |
| CVE-2026-19747 | 9.8 | — | — | — | — | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C | 23d ago |
| CVE-2026-73649 | 9.8 | — | — | — | — | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. | 23d ago |
| CVE-2026-67614 | 9.8 | — | — | — | — | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that | 23d ago |
| CVE-2026-56654 | 9.8 | — | — | — | — | Privilege Escalation via Access Token Scope Escalation in API | 23d ago |
| CVE-2026-73533zero day | 9.8 | 0.45% | 1/3 | 12d before | — | Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build s | 23d ago |
| CVE-2026-73532zero day | 9.8 | 0.46% | 1/3 | 12d before | — | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build se | 23d ago |
| CVE-2026-66691 | 9.8 | — | — | — | — | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | 23d ago |
| CVE-2026-66465 | 9.8 | — | — | — | — | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | 23d ago |
| CVE-2026-66453 | 9.8 | — | — | — | — | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | 23d ago |
| CVE-2026-66424 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | 23d ago |
| CVE-2026-61967 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | 23d ago |
| CVE-2026-28185 | 9.8 | — | — | — | — | Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | 23d ago |
| CVE-2026-28149 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | 23d ago |
| CVE-2026-28148 | 9.8 | — | — | — | — | Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | 23d ago |
| CVE-2026-28008 | 9.8 | — | — | — | — | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | 23d ago |
| CVE-2026-49827 | 9.8 | — | — | — | — | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. | 23d ago |
| CVE-2026-73487 | 9.8 | — | — | — | flowiseai / flowise | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allo | 24d ago |
| CVE-2026-14182 | 9.8 | — | — | — | — | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the emai | 24d ago |
| CVE-2026-49819 | 9.8 | — | — | — | — | UpSnap is a wake on lan web app. | 24d ago |
| CVE-2026-16770 | 9.8 | — | — | — | — | PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source do | 24d ago |
| CVE-2026-73519 | 9.8 | — | — | — | — | WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and publishe | 24d ago |
| CVE-2026-18749 | 9.8 | — | — | — | — | The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. | 24d ago |
| CVE-2026-19001 | 9.8 | — | — | — | — | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application suppl | 24d ago |
| CVE-2026-17083 | 9.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer o | 24d ago |
| CVE-2026-17218 | 9.8 | — | — | — | ibm / i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write | 24d ago |
| CVE-2026-16956 | 9.8 | — | — | — | ibm / db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper | 24d ago |
| CVE-2026-73240 | 9.8 | — | — | — | apache / allura | Specifically crafted inputs may lead to git argument injection in Apache Allura. | 24d ago |
| CVE-2025-59321 | 9.8 | — | — | — | — | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider th | 24d ago |
| CVE-2025-59326 | 9.8 | — | — | — | — | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary fi | 24d ago |
| CVE-2026-26035 | 9.8 | — | — | — | — | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWe | 24d ago |
| CVE-2025-41769 | 9.8 | — | — | — | — | The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configurat | 25d ago |
| CVE-2026-18391 | 9.8 | — | — | — | — | The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it o | 25d ago |
| CVE-2026-18366exploited | 9.8 | 0.39% | 1/3 | +19d | — | The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the ac | 25d ago |
| CVE-2026-16051 | 9.8 | — | — | — | — | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through | 25d ago |
| CVE-2026-15039exploited | 9.8 | 0.57% | 1/3 | +9d | — | The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload path | 25d ago |
| CVE-2026-68067 | 9.8 | — | — | — | — | The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live | 25d ago |
| CVE-2026-73034 | 9.8 | — | — | — | — | DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbit | 25d ago |
| CVE-2026-16230 | 9.8 | — | — | — | — | The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file pat | 25d ago |
| CVE-2026-73211 | 9.8 | — | — | — | — | PeerTube is an ActivityPub-federated video streaming platform. | 25d ago |
| CVE-2026-69102 | 9.8 | — | — | — | — | MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey. | 25d ago |
| CVE-2026-65791 | 9.8 | — | — | — | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a | 25d ago |