| CVE-2026-41842 | 7.5 | — | — | — | vmware / spring framework | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resour | 124d ago |
| CVE-2026-41007 | 7.5 | — | — | — | vmware / spring hateoas | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied stri | 124d ago |
| CVE-2026-41006 | 7.5 | — | — | — | vmware / spring hateoas | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER me | 124d ago |
| CVE-2026-40984 | 7.5 | — | — | — | — | In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-ser | 124d ago |
| CVE-2026-40983 | 7.5 | — | — | — | — | In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-ser | 124d ago |
| CVE-2026-26236 | 7.5 | — | — | — | qnap / qumagie | A missing authorization vulnerability has been reported to affect QuMagie. | 124d ago |
| CVE-2026-11694 | 7.5 | — | — | — | google / chrome | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had comprom | 124d ago |
| CVE-2026-11690 | 7.5 | — | — | — | google / chrome | Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker wh | 124d ago |
| CVE-2026-11667 | 7.5 | — | — | — | google / chrome | Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromise | 124d ago |
| CVE-2026-11644 | 7.5 | — | — | — | google / chrome | Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user | 124d ago |
| CVE-2026-11641 | 7.5 | — | — | — | google / chrome | Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who conv | 124d ago |
| CVE-2026-11639 | 7.5 | — | — | — | google / chrome | Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute | 124d ago |
| CVE-2026-11636 | 7.5 | — | — | — | google / chrome | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convi | 124d ago |
| CVE-2026-11632 | 7.5 | — | — | — | google / chrome | Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user | 124d ago |
| CVE-2026-40519 | 7.5 | — | — | — | — | Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code | 124d ago |
| CVE-2026-46306 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frame | 124d ago |
| CVE-2026-46304 | 7.5 | — | — | — | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet | 124d ago |
| CVE-2026-49975 | 7.5 | — | — | — | apache / http server | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of serv | 124d ago |
| CVE-2026-49755 | 7.5 | — | — | — | wojtekmach / req | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-c | 124d ago |
| CVE-2026-42536 | 7.5 | — | — | — | apache / http server | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted con | 124d ago |
| CVE-2026-36786 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 pa | 124d ago |
| CVE-2026-34356 | 7.5 | — | — | — | apache / http server | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverse | 124d ago |
| CVE-2026-34355 | 7.5 | — | — | — | apache / http server | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted back | 124d ago |
| CVE-2026-22164 | 7.5 | — | — | — | — | Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap m | 124d ago |
| CVE-2026-49235 | 7.5 | — | — | — | nlnetlabs / routinator | When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crash | 125d ago |
| CVE-2026-49234 | 7.5 | — | — | — | nlnetlabs / routinator | When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint | 125d ago |
| CVE-2026-49233 | 7.5 | — | — | — | nlnetlabs / routinator | Routinator does not properly check the module component of rsync URIs, which are used to create the file system pa | 125d ago |
| CVE-2026-43974 | 7.5 | — | — | — | ninenines / gun | Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP se | 125d ago |
| CVE-2026-43973 | 7.5 | — | — | — | ninenines / gun | Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to ex | 125d ago |
| CVE-2026-36789 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in | 125d ago |
| CVE-2026-47430 | 7.5 | — | — | — | apache / cordova inappbrowser | ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` | 125d ago |
| CVE-2026-3238 | 7.5 | — | — | — | — | A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. | 125d ago |
| CVE-2023-54350 | 7.5 | — | — | — | — | WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that a | 125d ago |
| CVE-2026-49494 | 7.5 | — | — | — | — | Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expe | 126d ago |
| CVE-2026-10725 | 7.5 | — | — | — | crux / protocol\ | Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. | 127d ago |
| CVE-2026-9290 | 7.5 | — | — | — | — | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion | 127d ago |
| CVE-2026-36785 | 7.5 | — | — | — | — | Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page par | 127d ago |
| CVE-2026-46493 | 7.5 | — | — | — | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. | 127d ago |
| CVE-2026-45291 | 7.5 | — | — | — | — | Cloudburst Network provides network components used within Cloudburst projects. | 127d ago |
| CVE-2026-45290 | 7.5 | — | — | — | — | Cloudburst Network provides network components used within Cloudburst projects. | 127d ago |
| CVE-2026-36501 | 7.5 | — | — | — | — | An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial o | 127d ago |
| CVE-2026-50234 | 7.5 | — | — | — | — | Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read ar | 128d ago |
| CVE-2026-21035 | 7.5 | — | — | — | samsung / plus tv | Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive | 128d ago |
| CVE-2026-11296 | 7.5 | — | — | — | google / chrome | Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who | 128d ago |
| CVE-2026-11265 | 7.5 | — | — | — | google / chrome | Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak | 128d ago |
| CVE-2026-11255 | 7.5 | — | — | — | google / chrome | Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a | 128d ago |
| CVE-2026-11242 | 7.5 | — | — | — | google / chrome | Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote att | 128d ago |
| CVE-2026-11239 | 7.5 | — | — | — | google / chrome | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who h | 128d ago |
| CVE-2026-11154 | 7.5 | — | — | — | google / chrome | Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the r | 128d ago |
| CVE-2026-11151 | 7.5 | — | — | — | google / chrome | Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a r | 128d ago |
| CVE-2026-11149 | 7.5 | — | — | — | google / chrome | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote | 128d ago |
| CVE-2026-11058 | 7.5 | — | — | — | google / chrome | Integer overflow in CredentialProvider in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacke | 128d ago |
| CVE-2026-10969 | 7.5 | — | — | — | google / chrome | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote | 128d ago |
| CVE-2026-10946 | 7.5 | — | — | — | google / chrome | Heap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a us | 128d ago |
| CVE-2026-10906 | 7.5 | — | — | — | google / chrome | Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convince | 128d ago |
| CVE-2026-10901 | 7.5 | — | — | — | google / chrome | Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced | 128d ago |
| CVE-2026-10900 | 7.5 | — | — | — | google / chrome | Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced | 128d ago |
| CVE-2026-10899 | 7.5 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who convinced a | 128d ago |
| CVE-2025-8873 | 7.5 | — | — | — | — | On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane | 128d ago |
| CVE-2026-10796 | 7.5 | — | — | — | openjsf / node version manager | nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configu | 128d ago |