| CVE-2026-12943 | 9.8 | — | — | — | ibm / hardware management console | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Po | 37d ago |
| CVE-2026-12118 | 9.8 | — | — | — | ibm / webmethods integration | IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitr | 37d ago |
| CVE-2026-12940 | 9.8 | — | — | — | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment vari | 37d ago |
| CVE-2026-52680 | 9.8 | — | — | — | apache / kyuubi | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a tem | 37d ago |
| CVE-2026-4978 | 9.8 | — | — | — | — | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision T | 37d ago |
| CVE-2026-28812 | 9.8 | — | — | — | apache / jspwiki | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escala | 37d ago |
| CVE-2026-28323 | 9.8 | — | — | — | solarwinds / web help desk | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. | 37d ago |
| CVE-2026-15435 | 9.8 | — | — | — | ibm / app connect enterprise | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacke | 38d ago |
| CVE-2026-59310exploited | 9.8 | 45.9% | 3/3 | +11d | vmware / vcenter server | VMware vCenter contains a directory traversal vulnerability in the Syslog server. | 38d ago |
| CVE-2026-59309exploited | 9.8 | 7.9% | 1/3 | +15d | vmware / vcenter server | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. | 38d ago |
| CVE-2026-17544 | 9.8 | — | — | — | php / php | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP ve | 38d ago |
| CVE-2026-17543 | 9.8 | — | — | — | php / php | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP vers | 38d ago |
| CVE-2026-7849 | 9.8 | — | — | — | — | Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command | 38d ago |
| CVE-2026-44108 | 9.8 | — | — | — | — | Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during sys | 38d ago |
| CVE-2026-44104 | 9.8 | — | — | — | — | The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum withou | 38d ago |
| CVE-2026-44101 | 9.8 | — | — | — | — | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigur | 38d ago |
| CVE-2026-44090 | 9.8 | — | — | — | — | Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protec | 38d ago |
| CVE-2026-58066 | 9.8 | — | — | — | rocket.chat / rocket.chat | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verifie | 38d ago |
| CVE-2026-16610 | 9.8 | — | — | — | — | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versi | 38d ago |
| CVE-2025-69943 | 9.8 | — | — | — | — | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters docto | 38d ago |
| CVE-2025-69942 | 9.8 | — | — | — | — | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. | 38d ago |
| CVE-2025-67404 | 9.8 | — | — | — | — | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the param | 38d ago |
| CVE-2025-67403 | 9.8 | — | — | — | — | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the pa | 38d ago |
| CVE-2025-65340 | 9.8 | — | — | — | — | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. | 38d ago |
| CVE-2026-41939 | 9.8 | — | — | — | — | Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final | 38d ago |
| CVE-2026-67191 | 9.8 | — | — | — | — | Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote | 38d ago |
| CVE-2026-60113 | 9.8 | — | — | — | nasa / ait dsn | AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication v | 38d ago |
| CVE-2026-60112 | 9.8 | — | — | — | nasa / ait gui | AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any un | 38d ago |
| CVE-2026-65888 | 9.8 | — | — | — | balbooa / gridbox | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allow | 39d ago |
| CVE-2026-65887 | 9.8 | — | — | — | balbooa / gridbox | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword | 39d ago |
| CVE-2026-65890 | 9.8 | — | — | — | balbooa / gridbox | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow u | 39d ago |
| CVE-2026-65884zero day | 9.8 | 0.28% | 1/3 | same day | balbooa / gridbox | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users p | 39d ago |
| CVE-2026-65883 | 9.8 | — | — | — | aimy-extensions / aimy captcha-less form guard | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 | 39d ago |
| CVE-2026-14900 | 9.8 | — | — | — | — | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, | 39d ago |
| CVE-2026-59243 | 9.8 | — | — | — | apache / apache-airflow-providers-fab | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an a | 39d ago |
| CVE-2025-10656 | 9.8 | — | — | — | — | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Miss | 39d ago |
| CVE-2026-18191 | 9.8 | — | — | — | — | VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attack | 39d ago |
| CVE-2026-13423 | 9.8 | — | — | — | — | The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its | 39d ago |
| CVE-2026-18072 | 9.8 | — | — | — | — | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerab | 39d ago |
| CVE-2026-54658 | 9.8 | — | — | — | — | Hypequery is a TypeScript semantic layer for ClickHouse. | 39d ago |
| CVE-2026-14512 | 9.8 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserializati | 39d ago |
| CVE-2026-14446 | 9.8 | — | — | — | ibm / websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the a | 39d ago |
| CVE-2026-66713 | 9.8 | — | — | — | apache / axis2\/java | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation | 40d ago |
| CVE-2026-16462 | 9.8 | — | — | — | — | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. | 40d ago |
| CVE-2026-15014 | 9.8 | — | — | — | — | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is v | 40d ago |
| CVE-2026-14545 | 9.8 | — | — | — | — | The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password | 40d ago |
| CVE-2021-32088 | 9.8 | — | — | — | quest / kace systems management appliance | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. | 40d ago |
| CVE-2021-32086 | 9.8 | — | — | — | quest / kace systems management appliance | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. | 40d ago |
| CVE-2021-32084 | 9.8 | — | — | — | quest / kace systems management appliance | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. | 40d ago |
| CVE-2026-64775 | 9.8 | — | — | — | apple / ipados | A memory initialization issue was addressed with improved memory handling. | 40d ago |
| CVE-2026-64774 | 9.8 | — | — | — | apple / ipados | An integer overflow was addressed with improved input validation. | 40d ago |
| CVE-2026-64772 | 9.8 | — | — | — | apple / ipados | An out-of-bounds write issue was addressed with improved input validation. | 40d ago |
| CVE-2026-64771 | 9.8 | — | — | — | apple / ipados | A buffer overflow was addressed with improved bounds checking. | 40d ago |
| CVE-2026-64770 | 9.8 | — | — | — | apple / ipados | An out-of-bounds write issue was addressed with improved bounds checking. | 40d ago |
| CVE-2026-64769 | 9.8 | — | — | — | apple / ipados | An out-of-bounds write issue was addressed with improved bounds checking. | 40d ago |
| CVE-2026-64767 | 9.8 | — | — | — | apple / macos | A buffer overflow was addressed with improved bounds checking. | 40d ago |
| CVE-2026-64762 | 9.8 | — | — | — | apple / macos | An out-of-bounds read was addressed with improved bounds checking. | 40d ago |
| CVE-2026-64751 | 9.8 | — | — | — | apple / ipados | A use after free issue was addressed with improved memory management. | 40d ago |
| CVE-2026-64746 | 9.8 | — | — | — | apple / ipados | An authorization issue was addressed with improved validation. | 40d ago |
| CVE-2026-64738 | 9.8 | — | — | — | apple / macos | A permissions issue was addressed with additional restrictions. | 40d ago |