| CVE-2026-62893 | 9.8 | — | — | — | microsoft / windows 10 1607 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62878 | 9.8 | — | — | — | microsoft / windows 10 1607 | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62815 | 9.8 | — | — | — | microsoft / windows 11 23h2 | Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-59124 | 9.8 | — | — | — | microsoft / windows app | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attack | 25d ago |
| CVE-2026-12571 | 9.8 | — | — | — | — | An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. | 25d ago |
| CVE-2026-72920 | 9.8 | — | — | — | — | SeaweedFS is a distributed storage system. | 25d ago |
| CVE-2026-51584 | 9.8 | — | — | — | — | An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of | 25d ago |
| CVE-2026-46670 | 9.8 | — | — | — | — | YesWiki is a wiki system written in PHP. | 25d ago |
| CVE-2026-72599 | 9.8 | — | — | — | — | An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via | 26d ago |
| CVE-2026-72550 | 9.8 | — | — | — | — | An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers | 26d ago |
| CVE-2026-10579 | 9.8 | — | — | — | — | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions wit | 26d ago |
| CVE-2026-19425 | 9.8 | — | — | — | — | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. | 26d ago |
| CVE-2026-34265 | 9.8 | — | — | — | — | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protoco | 26d ago |
| CVE-2026-63106 | 9.8 | — | — | — | — | ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API whe | 26d ago |
| CVE-2026-68426 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto s | 26d ago |
| CVE-2026-68388 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated range | 26d ago |
| CVE-2026-68385 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: s390/checksum: Fix csum_partial() without vect | 26d ago |
| CVE-2026-68381 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: pin conn during async oplock break noti | 26d ago |
| CVE-2026-68302 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every p | 26d ago |
| CVE-2026-68300 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_ | 26d ago |
| CVE-2026-68170 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix stale skb->sk reference on subflow | 26d ago |
| CVE-2026-68161 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns te | 26d ago |
| CVE-2026-68160 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snapt | 26d ago |
| CVE-2026-68159 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} len | 26d ago |
| CVE-2026-68158 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode | 26d ago |
| CVE-2026-68156 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} a | 26d ago |
| CVE-2026-68154 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_dec | 26d ago |
| CVE-2026-68144 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb( | 26d ago |
| CVE-2026-68137 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free in x25_kill_by_nei | 26d ago |
| CVE-2026-68136 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-mark | 26d ago |
| CVE-2026-68127 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskb_may_pull in | 26d ago |
| CVE-2026-68123 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation unde | 26d ago |
| CVE-2026-68117 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path | 26d ago |
| CVE-2026-13206 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel | 26d ago |
| CVE-2026-72593 | 9.8 | — | — | — | — | A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker t | 27d ago |
| CVE-2026-72592 | 9.8 | — | — | — | — | An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacke | 27d ago |
| CVE-2026-72590 | 9.8 | — | — | — | — | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote at | 27d ago |
| CVE-2026-72589 | 9.8 | — | — | — | — | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote at | 27d ago |
| CVE-2026-72580 | 9.8 | — | — | — | — | An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to exe | 27d ago |
| CVE-2026-72577 | 9.8 | — | — | — | — | Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbi | 27d ago |
| CVE-2026-72567 | 9.8 | — | — | — | — | An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticat | 27d ago |
| CVE-2026-72565 | 9.8 | — | — | — | — | A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass p | 27d ago |
| CVE-2026-55799 | 9.8 | — | — | — | apache / ranger | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to | 27d ago |
| CVE-2026-44416 | 9.8 | — | — | — | apache / ranger | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2. | 27d ago |
| CVE-2026-42537 | 9.8 | — | — | — | apache / ranger | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version | 27d ago |
| CVE-2026-40920 | 9.8 | — | — | — | apache / ranger | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. | 27d ago |
| CVE-2026-32227 | 9.8 | — | — | — | apache / ranger | SQL Injection vulnerability vulnerability in Apache Ranger. | 27d ago |
| CVE-2026-28672 | 9.8 | — | — | — | apache / ranger | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger | 27d ago |
| CVE-2026-19089 | 9.8 | — | — | — | — | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when | 27d ago |
| CVE-2026-16299 | 9.8 | — | — | — | — | The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allo | 27d ago |
| CVE-2026-16298 | 9.8 | — | — | — | — | The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing un | 27d ago |
| CVE-2026-19348 | 9.8 | — | — | — | — | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. | 28d ago |
| CVE-2026-15038 | 9.8 | — | — | — | — | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the au | 28d ago |
| CVE-2026-71993 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn functi | 28d ago |
| CVE-2026-71992 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter func | 28d ago |
| CVE-2026-71991 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH func | 28d ago |
| CVE-2026-71990 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH func | 28d ago |
| CVE-2026-71989 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger fun | 28d ago |
| CVE-2026-71988 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw functio | 28d ago |
| CVE-2026-71987 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function t | 28d ago |