| CVE-2026-71986 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function t | 28d ago |
| CVE-2026-71985 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol | 28d ago |
| CVE-2026-71984 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter func | 28d ago |
| CVE-2026-71983 | 9.8 | — | — | — | — | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interf | 28d ago |
| CVE-2026-71958 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overf | 28d ago |
| CVE-2026-71957 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overf | 28d ago |
| CVE-2026-71956 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command inje | 28d ago |
| CVE-2026-71955 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command inje | 28d ago |
| CVE-2026-71954 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71953 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71952 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71951 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71950 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71949 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71948 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71947 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71946 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71945 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-71944 | 9.8 | — | — | — | — | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a comma | 28d ago |
| CVE-2026-68082 | 9.8 | — | — | — | — | In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode | 29d ago |
| CVE-2026-14526 | 9.8 | — | — | — | — | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up t | 29d ago |
| CVE-2026-61808 | 9.8 | — | — | — | — | LightRAG provides simple and fast retrieval-augmented generation. | 29d ago |
| CVE-2026-19264 | 9.8 | — | — | — | — | Postiz is an open-source social media scheduling tool. | 29d ago |
| CVE-2022-4995zero day | 9.8 | 0.69% | 1/3 | 1028d before | — | Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unau | 29d ago |
| CVE-2026-71558 | 9.8 | — | — | — | apache / fory | Heap type confusion vulnerability in Apache Fory C++ deserialization. | 30d ago |
| CVE-2026-16258 | 9.8 | — | — | — | — | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allow | 30d ago |
| CVE-2026-14205 | 9.8 | — | — | — | — | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for | 30d ago |
| CVE-2026-14365 | 9.8 | — | — | — | — | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypa | 30d ago |
| CVE-2026-14364 | 9.8 | — | — | — | — | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover v | 30d ago |
| CVE-2026-62873 | 9.8 | — | — | — | microsoft / windows admin center | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to | 30d ago |
| CVE-2026-70558 | 9.8 | — | — | — | — | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File( | 30d ago |
| CVE-2026-67689 | 9.8 | — | — | — | — | SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` a | 30d ago |
| CVE-2026-67688 | 9.8 | — | — | — | — | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload m | 30d ago |
| CVE-2026-65400exploited | 9.8 | 9.9% | 3/3 | +1d | apple / macos | An authentication issue was addressed with improved state management. | 30d ago |
| CVE-2026-48087 | 9.8 | — | — | — | — | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. | 30d ago |
| CVE-2026-48085 | 9.8 | — | — | — | — | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. | 30d ago |
| CVE-2026-17032 | 9.8 | — | — | — | — | Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server | 30d ago |
| CVE-2026-15734 | 9.8 | — | — | — | — | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticat | 30d ago |
| CVE-2026-15733 | 9.8 | — | — | — | — | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. | 30d ago |
| CVE-2026-15732 | 9.8 | — | — | — | — | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. | 30d ago |
| CVE-2026-67261 | 9.8 | — | — | — | dell / virtual storage integrator | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command I | 30d ago |
| CVE-2026-66662 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | 30d ago |
| CVE-2026-65581 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | 30d ago |
| CVE-2026-65579 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. | 30d ago |
| CVE-2026-65578 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | 30d ago |
| CVE-2026-65577 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | 30d ago |
| CVE-2026-65576 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | 30d ago |
| CVE-2026-65575 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | 30d ago |
| CVE-2026-65574 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. | 30d ago |
| CVE-2026-65573 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | 30d ago |
| CVE-2026-65572 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | 30d ago |
| CVE-2026-65571 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | 30d ago |
| CVE-2026-65556 | 9.8 | — | — | — | — | Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | 30d ago |
| CVE-2026-65552 | 9.8 | — | — | — | — | Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | 30d ago |
| CVE-2026-65507 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | 30d ago |
| CVE-2026-53975 | 9.8 | — | — | — | — | OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to | 30d ago |
| CVE-2026-28139zero day | 9.8 | 0.38% | 1/3 | 2d before | — | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | 30d ago |
| CVE-2026-28005 | 9.8 | — | — | — | — | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | 30d ago |
| CVE-2026-5134 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software | 30d ago |
| CVE-2026-68079 | 9.8 | — | — | — | apache / cxf | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited numb | 31d ago |